BREAK IN TRANSCRIPT
Mr. PALLONE. Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 360) to require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes, as amended.
The Clerk read the title of the bill.
The text of the bill is as follows: H.R. 360
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled, SECTION 1. SHORT TITLE.
This Act may be cited as the ``Cyber Sense Act of 2020''. SEC. 2. CYBER SENSE.
(a) In General.--The Secretary of Energy, in coordination with relevant Federal agencies, shall establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, as defined in section 215(a) of the Federal Power Act (16 U.S.C. 824o(a)).
(b) Program Requirements.--In carrying out subsection (a), the Secretary of Energy shall--
(1) establish a testing process under the Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, including products relating to industrial control systems and operational technologies, such as supervisory control and data acquisition systems;
(2) for products and technologies tested under the Cyber Sense program, establish and maintain cybersecurity vulnerability reporting processes and a related database;
(3) provide technical assistance to electric utilities, product manufacturers, and other electricity sector stakeholders to develop solutions to mitigate identified cybersecurity vulnerabilities in products and technologies tested under the Cyber Sense program;
(4) biennially review products and technologies tested under the Cyber Sense program for cybersecurity vulnerabilities and provide analysis with respect to how such products and technologies respond to and mitigate cyber threats;
(5) develop guidance, that is informed by analysis and testing results under the Cyber Sense program, for electric utilities for procurement of products and technologies;
(6) provide reasonable notice to the public, and solicit comments from the public, prior to establishing or revising the testing process under the Cyber Sense program;
(7) oversee testing of products and technologies under the Cyber Sense program; and
(8) consider incentives to encourage the use of analysis and results of testing under the Cyber Sense program in the design of products and technologies for use in the bulk-power system.
(c) Disclosure of Information.--Any cybersecurity vulnerability reported pursuant to a process established under subsection (b)(2), the disclosure of which the Secretary of Energy reasonably foresees would cause harm to critical electric infrastructure (as defined in section 215A of the Federal Power Act), shall be deemed to be critical electric infrastructure information for purposes of section 215A(d) of the Federal Power Act.
(d) Federal Government Liability.--Nothing in this section shall be construed to authorize the commencement of an action against the United States Government with respect to the testing of a product or technology under the Cyber Sense program.
BREAK IN TRANSCRIPT
Mr. PALLONE. 360.
Mr. Speaker, I rise in support of H.R. 360, the Cyber Sense Act of 2020.
Grid security is a national security issue and one that is clearly and properly delegated under law to the Secretary of Energy to manage together with the industry. We must give the electric sector the tools and technologies necessary to protect our grid from malicious harm.
Fortunately, there has not yet been a broad cyberattack that has taken down large parts of the grid in the United States, but we must not let our guard down.
H.R. 360 gives the Department of Energy important and new authorities to facilitate more secure technologies and equipment in our Nation's grid. It also now requires the Secretary to coordinate with the Department of Homeland Security and other relevant Federal agencies in order to ensure smooth and seamless implementation across the Federal Government.
This bill requires the Department of Energy to set up a voluntary Cyber Sense program to identify cyber-secure products that could be used in the bulk-power system.
This program would also provide technical assistance to electric utilities and product manufacturers to assist them in developing solutions to mitigate cyber vulnerabilities in the grid.
I thank my colleagues, Representative McNerney and Representative Latta, for their hard work on this critical issue. Their partnership and bipartisan leadership on cybersecurity matters continues to benefit us all.
BREAK IN TRANSCRIPT
Mr. PALLONE. Mr. Speaker, I have no additional Members that wish to speak.
Mr. Speaker, I enter into the Record a letter to the Speaker and the minority leader from the American Public Power Association, Edison Electric Institute, and the National Rural Electric Cooperative Association in support of this legislation. September 28, 2020. Hon. Nancy Pelosi, House of Representatives, Washington, DC. Hon. Kevin McCarthy, House of Representatives, Washington, DC.
Dear Speaker Pelosi and Minority Leader McCarthy: We are writing in support of full House consideration of three electric grid security bills passed by the House Energy and Commerce Committee: H.R. 359, the Enhancing Grid Security through Public-Private Partnerships Act; H.R. 360, the Cyber Sense Act of 2020; and H.R. 362, the Energy Emergency Leadership Act.
APPA is the national service organization for not-for- profit, community-owned utilities that power 2,000 towns and cities nationwide. Public power utilities account for over 15 percent of all electric sales to over 49 million customers in every state but Hawaii. EEI is the association that represents all U.S. investor-owned electric companies. EEI members provide electricity for about 220 million Americans, and operate in all 50 states and the District of Columbia. NRECA is the national service organization representing the interests of cooperative electric utilities and the consumers they serve. More than 900 not-for-profit rural electric utilities provide electricity to over 42 million people in 48 states.
Protecting and maintaining electric sector security and reliability is a top priority for our associations and our members. To keep up with evolving threats, the industry welcomes close coordination with government partners. The bills scheduled for consideration by the House this week are aimed at strengthening our shared responsibility to protect the nation's critical infrastructure. We are particularly supportive of H.R. 359 and H.R. 362. H.R. 359 directs DOE to establish a program to facilitate and encourage public- private partnerships to promote and advance the physical and cybersecurity of the electric power sector. H.R. 362 would amend the DOE Organization Act to include energy emergency and energy security among the functions that the Secretary assigns to an Assistant Secretary, with the intent to clarify and codify the functions of DOE's Office of Cybersecurity, Energy Security, and Emergency Response (CESER).
Thank you for your consideration. We appreciate your leadership and efforts to help improve the security of our nation's electric grid. Sincerely, American Public Power Association. Edison Electric Institute. National Rural Electric Cooperative Association.
BREAK IN TRANSCRIPT
Mr. PALLONE. Mr. Speaker, I ask my colleagues to support this important bill, and I yield back the balance of my time.
BREAK IN TRANSCRIPT