S. 79Senate115th Congress (2017-2019)Passed Senate

Securing Energy Infrastructure Act

Introduced January 10, 2017

AI-Generated Summary

Updated April 15, 2026 at 11:45 AM UTC

The Securing Energy Infrastructure Act creates a two‑year pilot program, run by the Energy Department’s Secretary, to work with key energy companies and manufacturers to find and fix cybersecurity weaknesses in their industrial control systems. The program is run at national laboratories, includes a multi‑agency working group to develop a national strategy, and requires the Secretary to report its findings to Congress. The law also keeps shared information confidential, shields participating companies from lawsuits, and provides $11.5 million in funding.

Key Provisions

  • Within 180 days, the Secretary of Energy must launch a two‑year pilot at national labs to partner with "covered entities" (critical energy infrastructure identified under an existing executive order) to discover new security vulnerabilities and test ways to protect control systems.
  • A working group of at least ten members from federal agencies, industry, reliability organizations, and research institutions will be formed to evaluate the pilot’s technology and create a national cyber‑informed engineering strategy.
  • The Secretary must submit an interim report within 180 days after the first funds are spent and a final report two years later, detailing results, feasibility of methods, and the working group’s evaluations.
  • Information shared under the program is classified as voluntarily shared and is exempt from public‑record disclosure laws; participants are protected from liability for taking part in the voluntary activities.
  • The Act does not give any agency new rule‑making authority and authorizes $10 million for the pilot and $1.5 million for the working group and reporting.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

9 earlier actions
HouseFloor Latest Action

Held at the desk.

December 20, 2018 • 8:30 PM

View full timeline
SenateIntro Referral

Introduced in Senate

January 10, 2017

SenateIntro Referral

Read twice and referred to the Committee on Energy and Natural Resources.

January 10, 2017

SenateCommittee

Committee on Energy and Natural Resources Subcommittee on Energy. Hearings held. With printed Hearing: S.Hrg. 115-262.

March 28, 2017

SenateCommittee

Committee on Energy and Natural Resources. Ordered to be reported with an amendment in the nature of a substitute favorably.

March 8, 2018

SenateCommittee

Committee on Energy and Natural Resources. Reported by Senator Murkowski with an amendment in the nature of a substitute. With written report No. 115-246.

May 10, 2018

SenateCalendars

Placed on Senate Legislative Calendar under General Orders. Calendar No. 410.

May 10, 2018

SenateFloor

Passed Senate with an amendment by Voice Vote.

December 20, 2018

HouseFloor

Received in the House.

December 20, 2018 • 12:42 PM

SenateFloor

Message on Senate action sent to the House.

December 20, 2018

HouseFloor

Held at the desk.

December 20, 2018 • 8:30 PM

Floor Debate

1 member

What members said about S. 79 on the floor

1 Republican
John Boozman
Sen. John BoozmanR-AR · Dec 19, 2018

I ask unanimous consent that the Senate proceed to the immediate consideration of Calendar No. 410, S. 79. I ask unanimous consent that the committee-reported substitute amendment be agreed to and…

Bill Text

3 versions available

Reading Mode
Latest
Engrossed in SenateIssued December 20, 2018

115th CONGRESS

2d Session

S. 79

AN ACT

To provide for the establishment of a pilot program to identify security vulnerabilities of certain entities in the energy sector.

1.

Short title

This Act may be cited as the Securing Energy Infrastructure Act.

2.

Definitions

In this Act:

(1)

Appropriate committee of Congress

The term appropriate committee of Congress means—

(A)

the Select Committee on Intelligence, the Committee on Homeland Security and Governmental Affairs, and the Committee on Energy and Natural Resources of the Senate; and

(B)

the Permanent Select Committee on Intelligence, the Committee on Homeland Security, and the Committee on Energy and Commerce of the House of Representatives.

(2)

Covered entity

The term covered entity means an entity identified pursuant to section 9(a) of Executive Order 13636 of February 12, 2013 (78 Fed. Reg. 11742), relating to identification of critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security.

(3)

Exploit

The term exploit means a software tool designed to take advantage of a security vulnerability.

(4)

Industrial control system

(A)

In general

The term industrial control system means an operational technology used to measure, control, or manage industrial functions.

(B)

Inclusions

The term industrial control system includes supervisory control and data acquisition systems, distributed control systems, and programmable logic or embedded controllers.

(5)

National Laboratory

The term National Laboratory has the meaning given the term in section 2 of the Energy Policy Act of 2005 (42 U.S.C. 15801).

(6)

Program

The term Program means the pilot program established under section 3.

(7)

Secretary

The term Secretary means the Secretary of Energy.

(8)

Security vulnerability

The term security vulnerability means any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control.

3.

Pilot program for securing energy infrastructure

Not later than 180 days after the date of enactment of this Act, the Secretary shall establish a 2-year control systems implementation pilot program within the National Laboratories for the purposes of—

(1)

partnering with covered entities in the energy sector (including critical component manufacturers in the supply chain) that voluntarily participate in the Program to identify new classes of security vulnerabilities of the covered entities; and

(2)

evaluating technology and standards, in partnership with covered entities, to isolate and defend industrial control systems of covered entities from security vulnerabilities and exploits in the most critical systems of the covered entities, including—

(A)

analog and nondigital control systems;

(B)

purpose-built control systems; and

(C)

physical controls.

4.

Working group to evaluate program standards and develop strategy

(a)

Establishment

The Secretary shall establish a working group—

(1)

to evaluate the technology and standards used in the Program under section 3(2); and

(2)

to develop a national cyber-informed engineering strategy to isolate and defend covered entities from security vulnerabilities and exploits in the most critical systems of the covered entities.

(b)

Membership

The working group established under subsection (a) shall be composed of not fewer than 10 members, to be appointed by the Secretary, at least 1 member of which shall represent each of the following:

(1)

The Department of Energy.

(2)

The energy industry, including electric utilities and manufacturers recommended by the Energy Sector coordinating councils.

(3)
(A)

The Department of Homeland Security; or

(B)

the Industrial Control Systems Cyber Emergency Response Team.

(4)

The North American Electric Reliability Corporation.

(5)

The Nuclear Regulatory Commission.

(6)
(A)

The Office of the Director of National Intelligence; or

(B)

the intelligence community (as defined in section 3 of the National Security Act of 1947 (50 U.S.C. 3003)).

(7)
(A)

The Department of Defense; or

(B)

the Assistant Secretary of Defense for Homeland Security and America's Security Affairs.

(8)

A State or regional energy agency.

(9)

A national research body or academic institution.

(10)

The National Laboratories.

5.

Reports on the Program

(a)

Interim report

Not later than 180 days after the date on which funds are first disbursed under the Program, the Secretary shall submit to the appropriate committees of Congress an interim report that—

(1)

describes the results of the Program;

(2)

includes an analysis of the feasibility of each method studied under the Program; and

(3)

describes the results of the evaluations conducted by the working group established under section 4(a).

(b)

Final report

Not later than 2 years after the date on which funds are first disbursed under the Program, the Secretary shall submit to the appropriate committees of Congress a final report that—

(1)

describes the results of the Program;

(2)

includes an analysis of the feasibility of each method studied under the Program; and

(3)

describes the results of the evaluations conducted by the working group established under section 4(a).

6.

Exemption from disclosure

Information shared by or with the Federal Government or a State, Tribal, or local government under this Act shall be—

(1)

deemed to be voluntarily shared information;

(2)

exempt from disclosure under section 552 of title 5, United States Code, or any provision of any State, Tribal, or local freedom of information law, open government law, open meetings law, open records law, sunshine law, or similar law requiring the disclosure of information or records; and

(3)

withheld from the public, without discretion, under section 552(b)(3) of title 5, United States Code, or any provision of a State, Tribal, or local law requiring the disclosure of information or records.

7.

Protection from liability

(a)

In general

A cause of action against a covered entity for engaging in the voluntary activities authorized under section 3—

(1)

shall not lie or be maintained in any court; and

(2)

shall be promptly dismissed by the applicable court.

(b)

Voluntary activities

Nothing in this Act subjects any covered entity to liability for not engaging in the voluntary activities authorized under section 3.

8.

No new regulatory authority for Federal agencies

Nothing in this Act authorizes the Secretary or the head of any other department or agency of the Federal Government to issue new regulations.

9.

Authorization of appropriations

(a)

Pilot Program

There is authorized to be appropriated $10,000,000 to carry out section 3.

(b)

Working Group and Report

There is authorized to be appropriated $1,500,000 to carry out sections 4 and 5.

(c)

Availability

Amounts made available under subsections (a) and (b) shall remain available until expended.

Passed the Senate December 20 (legislative day, December 19), 2018.

Secretary