H.R. 5733House115th Congress (2017-2019)Passed House

DHS Industrial Control Systems Capabilities Enhancement Act of 2018

Sponsored by Don BaconRep. Don Bacon (R-NE)
Introduced May 9, 2018

AI-Generated Summary

Updated April 15, 2026 at 9:53 PM UTC

The DHS Industrial Control Systems Capabilities Enhancement Act of 2018 amends the Homeland Security Act to require the National Cybersecurity and Communications Integration Center (NCCIC) to develop and maintain capabilities for identifying and addressing cyber threats to industrial control systems (ICS) that run critical infrastructure. The law adds new duties for the Center, such as leading federal coordination on ICS security, providing technical help to industry, and sharing vulnerability information, and it mandates regular briefings to Congress on these activities.

Key Provisions

  • Adds a new responsibility for the NCCIC to focus on both information technology and operational technology, including industrial control systems.
  • Requires the Center to lead federal efforts, in coordination with sector agencies, to identify and mitigate cybersecurity threats to industrial control systems and supervisory control and data acquisition (SCADA) systems.
  • Mandates the Center maintain cross‑sector incident‑response capabilities for cyber incidents affecting industrial control systems.
  • Obligates the Center to provide technical assistance to end‑users, manufacturers, and other stakeholders to help identify and fix vulnerabilities in industrial control system products and technologies.
  • Directs the Center to collect, coordinate, and share vulnerability information with the industrial control systems community, working with researchers, users, and manufacturers.
  • Requires the Center to report to the House and Senate Homeland Security committees every six months for four years, starting 180 days after enactment, on its industrial control systems capabilities and activities.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

12 earlier actions
SenateIntro Referral Latest Action

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

June 26, 2018

View full timeline
HouseIntro Referral

Introduced in House

May 9, 2018

HouseIntro Referral

Referred to the House Committee on Homeland Security.

May 9, 2018

HouseCommittee

Committee Consideration and Mark-up Session Held.

June 6, 2018

HouseCommittee

Ordered to be Reported (Amended) by Unanimous Consent.

June 6, 2018

HouseCommittee

Reported (Amended) by the Committee on Homeland Security. H. Rept. 115-777.

June 22, 2018

HouseCalendars

Placed on the Union Calendar, Calendar No. 603.

June 22, 2018

HouseFloor

Mr. Bacon moved to suspend the rules and pass the bill, as amended.

June 25, 2018 • 7:48 PM

HouseFloor

Considered under suspension of the rules. (consideration: CR H5630-5632)

June 25, 2018 • 7:48 PM

HouseFloor

DEBATE - The House proceeded with forty minutes of debate on H.R. 5733.

June 25, 2018 • 7:48 PM

HouseFloor

Passed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote.(text: CR H5630-5631)

June 25, 2018 • 7:59 PM

HouseFloor

On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H5630-5631)

June 25, 2018 • 7:59 PM

HouseFloor

Motion to reconsider laid on the table Agreed to without objection.

June 25, 2018 • 7:59 PM

SenateIntro Referral

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

June 26, 2018

Floor Debate

2 members

What members said about H.R. 5733 on the floor

1 Republican1 Democrat
James R. Langevin
Rep. James R. LangevinD-RI-2 · Jun 25, 2018

Mr. Speaker, I yield myself such time as I may consume. Mr. Speaker, I rise in support of H.R. 5733, the DHS Industrial Control Systems Capabilities Enhancement Act. H.R. 5733 would codify the…

Don Bacon
Rep. Don BaconR-NE-2 · Jun 25, 2018

Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 5733) to amend the Homeland Security Act of 2002 to provide for the responsibility of the National Cybersecurity and Communications…

Bill Text

4 versions available

Reading Mode
Latest
Referred in SenateIssued June 26, 2018

IIB

115th CONGRESS

2d Session

H. R. 5733

IN THE SENATE OF THE UNITED STATES

June 26, 2018

Received; read twice and referred to the Committee on Homeland Security and Governmental Affairs

AN ACT

To amend the Homeland Security Act of 2002 to provide for the responsibility of the National Cybersecurity and Communications Integration Center to maintain capabilities to identify threats to industrial control systems, and for other purposes.

1.

Short title

This Act may be cited as the DHS Industrial Control Systems Capabilities Enhancement Act of 2018.

2.

Capabilities of National Cybersecurity and Communications Integration Center to identify threats to industrial control systems

(a)

In general

Section 227 of the Homeland Security Act of 2002 (6 U.S.C. 148) is amended—

(1)

in subsection (e)(1)—

(A)

in subparagraph (G), by striking and after the semicolon;

(B)

in subparagraph (H), by inserting and after the semicolon; and

(C)

by adding at the end the following new subparagraph:

(I)

activities of the Center address the security of both information technology and operational technology, including industrial control systems;

;

(2)

by redesignating subsections (f) through (m) as subsections (g) through (n), respectively; and

(3)

by inserting after subsection (d) the following new subsection:

(f)

Industrial control systems

The Center shall maintain capabilities to identify and address threats and vulnerabilities to products and technologies intended for use in the automated control of critical infrastructure processes. In carrying out this subsection, the Center shall—

(1)

lead, in coordination with relevant sector specific agencies, Federal Government efforts to identify and mitigate cybersecurity threats to industrial control systems, including supervisory control and data acquisition systems;

(2)

maintain cross-sector incident response capabilities to respond to industrial control system cybersecurity incidents;

(3)

provide cybersecurity technical assistance to industry end-users, product manufacturers, and other industrial control system stakeholders to identify and mitigate vulnerabilities;

(4)

collect, coordinate, and provide vulnerability information to the industrial control systems community by, as appropriate, working closely with security researchers, industry end-users, product manufacturers, and other industrial control systems stakeholders; and

(5)

conduct such other efforts and assistance as the Secretary determines appropriate.

.

(b)

Report to Congress

Not later than 180 days after the date of the enactment of this Act, and every 6 months thereafter during the subsequent 4-year period, the National Cybersecurity and Communications Integration Center shall provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a briefing on the industrial control systems capabilities of the Center under subsection (f) of section 227 of the Homeland Security Act of 2002 (6 U.S.C. 148), as added by subsection (a).

Passed the House of Representatives June 25, 2018.

Karen L. Haas,

Clerk.