II
115th CONGRESS
2d Session
S. 2392
IN THE SENATE OF THE UNITED STATES
February 7, 2018
Mr. Daines introduced the following bill; which was read twice and referred to the Committee on Homeland Security and Governmental Affairs
A BILL
To amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to designate cybersecurity technologies that qualify for protection under systems of risk and litigation management.
Short title
This Act may be cited as the Cyber Support for Anti-Terrorism by Fostering Effective Technologies Act of 2018
or the Cyber SAFETY Act of 2018
.
Inclusion of qualifying cyber incidents
Subtitle G of title VIII of the Homeland Security Act of 2002 (6 U.S.C. 441 et seq.) is amended—
in section 862(b) (6 U.S.C. 441(b))—
in the heading, by striking Designation of qualified anti-terrorism technologies
and inserting Designation of anti-Terrorism and cybersecurity technologies
;
in the matter preceding paragraph (1), by inserting or cybersecurity
after anti-terrorism
;
in paragraphs (3), (4), and (5), by inserting or cybersecurity
after anti-terrorism
each place that term appears; and
in paragraph (7)—
by inserting “or cybersecurity” after “Anti-terrorism”; and
by inserting or qualifying cyber incidents
after acts of terrorism
;
in section 863 (6 U.S.C. 442)—
by inserting or cybersecurity
after anti-terrorism
each place that term appears;
by inserting or qualifying cyber incident
after act of terrorism
each place that term appears;
by inserting or qualifying cyber incidents
after acts of terrorism
each place that term appears; and
in subsection (d)(3)—
by striking (3) Certificate.—
and inserting the following:
(3) Certificates.—
Certificates for anti-terrorism technologies
; and
by adding at the end the following:
Certificates for cybersecurity technologies
In general
For cybersecurity technology reviewed and approved by the Secretary, the Secretary will issue a certificate of conformance to the Seller and place the cybersecurity technology on an Approved Product List for Homeland Security.
Subsequent review
Not less frequently than once every 2 years, the Secretary shall conduct a new review of any cybersecurity technology for which the Secretary issued a certification under clause (i).
;
in section 864 (6 U.S.C. 443)—
by inserting or cybersecurity
after anti-terrorism
each place that term appears; and
by inserting or qualifying cyber incident
after act of terrorism
each place that term appears; and
in section 865 (6 U.S.C. 444)—
in paragraph (1)—
in the heading, by inserting or cybersecurity
after anti-terrorism
;
by inserting or cybersecurity
after anti-terrorism
;
by inserting or qualifying cyber incidents
after acts of terrorism
; and
by inserting or incidents
after such acts
; and
by adding at the end the following:
Qualifying cyber incident
The term qualifying cyber incident has the meaning given the term incident in section 3552(b) of title 44, United States Code.
Final agency action
The determination by the Secretary that an act of terrorism or qualifying cyber incident has occurred shall constitute a final agency action subject to review under chapter 7 of title 5, United States Code.
.