One Hundred Seventeenth Congress of the United States of America
1st Session
Begun and held at the City of Washington on Sunday, the third day of January, two thousand and twenty one
S. 1917
AN ACT
To establish a K–12 education cybersecurity initiative, and for other purposes.
Short title
This Act may be cited as the K–12 Cybersecurity Act of 2021
.
Findings
Congress finds the following:
K–12 educational institutions across the United States are facing cyber attacks.
Cyber attacks place the information systems of K–12 educational institutions at risk of possible disclosure of sensitive student and employee information, including—
grades and information on scholastic development;
medical records;
family records; and
personally identifiable information.
Providing K–12 educational institutions with resources to aid cybersecurity efforts will help K–12 educational institutions prevent, detect, and respond to cyber events.
K–12 education cybersecurity initiative
Definitions
In this section:
Cybersecurity risk
The term cybersecurity risk has the meaning given the term in section 2209 of the Homeland Security Act of 2002 (6 U.S.C. 659).
Director
The term Director means the Director of Cybersecurity and Infrastructure Security.
Information system
The term information system has the meaning given the term in section 3502 of title 44, United States Code.
K–12 educational institution
The term K–12 educational institution means an elementary school or a secondary school, as those terms are defined in section 8101 of the Elementary and Secondary Education Act of 1965 (20 U.S.C. 7801).
Study
In general
Not later than 120 days after the date of enactment of this Act, the Director, in accordance with subsection (g)(1), shall conduct a study on the specific cybersecurity risks facing K–12 educational institutions that—
analyzes how identified cybersecurity risks specifically impact K–12 educational institutions;
includes an evaluation of the challenges K–12 educational institutions face in—
securing—
information systems owned, leased, or relied upon by K–12 educational institutions; and
sensitive student and employee records; and
implementing cybersecurity protocols;
identifies cybersecurity challenges relating to remote learning; and
evaluates the most accessible ways to communicate cybersecurity recommendations and tools.
Congressional briefing
Not later than 120 days after the date of enactment of this Act, the Director shall provide a Congressional briefing on the study conducted under paragraph (1).
Cybersecurity Recommendations
Not later than 60 days after the completion of the study required under subsection (b)(1), the Director, in accordance with subsection (g)(1), shall develop recommendations that include cybersecurity guidelines designed to assist K–12 educational institutions in facing the cybersecurity risks described in subsection (b)(1), using the findings of the study.
Online training toolkit
Not later than 120 days after the completion of the development of the recommendations required under subsection (c), the Director shall develop an online training toolkit designed for officials at K–12 educational institutions to—
educate the officials about the cybersecurity recommendations developed under subsection (c); and
provide strategies for the officials to implement the recommendations developed under subsection (c).
Public availability
The Director shall make available on the website of the Department of Homeland Security with other information relating to school safety the following:
The findings of the study conducted under subsection (b)(1).
The cybersecurity recommendations developed under subsection (c).
The online training toolkit developed under subsection (d).
Voluntary use
The use of the cybersecurity recommendations developed under (c) by K–12 educational institutions shall be voluntary.
Consultation
In general
In the course of the conduction of the study required under subsection (b)(1) and the development of the recommendations required under subsection (c), the Director shall consult with individuals and entities focused on cybersecurity and education, as appropriate, including—
teachers;
school administrators;
Federal agencies;
non-Federal cybersecurity entities with experience in education issues; and
private sector organizations.
Inapplicability of FACA
The Federal Advisory Committee Act (5 U.S.C App.) shall not apply to any consultation under paragraph (1).
Speaker of the House of Representatives
Vice President of the United States and President of the Senate