LexCard US
TITLE 6

Title 6 — Domestic Security

CHAPTER 1—HOMELAND SECURITY ORGANIZATION

101.

Definitions

1In this chapter, the following definitions apply:

2(1) Each of the terms "American homeland" and "homeland" means the United States.

3(2) The term "appropriate congressional committee" means any committee of the House of Representatives or the Senate having legislative or oversight jurisdiction under the Rules of the House of Representatives or the Senate, respectively, over the matter concerned.

4(3) The term "assets" includes contracts, facilities, property, records, unobligated or unexpended balances of appropriations, and other funds or resources (other than personnel).

5(4) The term "critical infrastructure" has the meaning given that term in section 5195c(e) of title 42.

6(5) The term "Department" means the Department of Homeland Security.

7(6) The term "emergency response providers" includes Federal, State, and local governmental and nongovernmental emergency public safety, fire, law enforcement, emergency response, emergency medical (including hospital emergency facilities), and related personnel, agencies, and authorities.

8(7) The term "EMP" means an electromagnetic pulse caused by a nuclear device or nonnuclear device, including such a pulse caused by an act of terrorism.

9(8) The term "executive agency" means an executive agency and a military department, as defined, respectively, in sections 105 and 102 of title 5.

10(9) The term "functions" includes authorities, powers, rights, privileges, immunities, programs, projects, activities, duties, and responsibilities.

11(10) The term "GMD" means a geomagnetic disturbance caused by a solar storm or another naturally occurring phenomenon.

12(11) The term "intelligence component of the Department" means any element or entity of the Department that collects, gathers, processes, analyzes, produces, or disseminates intelligence information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, or national intelligence, as defined under section 3003(5) of title 50, except—

13(A) the United States Secret Service; and

14(B) the Coast Guard, when operating under the direct authority of the Secretary of Defense or Secretary of the Navy pursuant to section 3 1 of title 14, except that nothing in this paragraph shall affect or diminish the authority and responsibilities of the Commandant of the Coast Guard to command or control the Coast Guard as an armed force or the authority of the Director of National Intelligence with respect to the Coast Guard as an element of the intelligence community (as defined under section 3003(4) of title 50.2

15(12) The term "key resources" means publicly or privately controlled resources essential to the minimal operations of the economy and government.

16(13) The term "local government" means—

17(A) a county, municipality, city, town, township, local public authority, school district, special district, intrastate district, council of governments (regardless of whether the council of governments is incorporated as a nonprofit corporation under State law), regional or interstate government entity, or agency or instrumentality of a local government;

18(B) an Indian tribe or authorized tribal organization, or in Alaska a Native village or Alaska Regional Native Corporation; and

19(C) a rural community, unincorporated town or village, or other public entity.

20(14) The term "major disaster" has the meaning given in section 5122(2) of title 42.

21(15) The term "personnel" means officers and employees.

22(16) The term "Secretary" means the Secretary of Homeland Security.

23(17) The term "State" means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Virgin Islands, Guam, American Samoa, the Commonwealth of the Northern Mariana Islands, and any possession of the United States.

24(18) The term "terrorism" means any activity that—

25(A) involves an act that—

26(i) is dangerous to human life or potentially destructive of critical infrastructure or key resources; and

27(ii) is a violation of the criminal laws of the United States or of any State or other subdivision of the United States; and

28(B) appears to be intended—

29(i) to intimidate or coerce a civilian population;

30(ii) to influence the policy of a government by intimidation or coercion; or

31(iii) to affect the conduct of a government by mass destruction, assassination, or kidnapping.

32(19)(A) The term "United States", when used in a geographic sense, means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Virgin Islands, Guam, American Samoa, the Commonwealth of the Northern Mariana Islands, any possession of the United States, and any waters within the jurisdiction of the United States.

33(B) Nothing in this paragraph or any other provision of this chapter shall be construed to modify the definition of "United States" for the purposes of the Immigration and Nationality Act [8 U.S.C. 1101 et seq.] or any other immigration or nationality law.

34(20) The term "voluntary preparedness standards" means a common set of criteria for preparedness, disaster management, emergency management, and business continuity programs, such as the American National Standards Institute's National Fire Protection Association Standard on Disaster/Emergency Management and Business Continuity Programs (ANSI/NFPA 1600).

102.

Construction; severability

1Any provision of this chapter held to be invalid or unenforceable by its terms, or as applied to any person or circumstance, shall be construed so as to give it the maximum effect permitted by law, unless such holding shall be one of utter invalidity or unenforceability, in which event such provision shall be deemed severable from this chapter and shall not affect the remainder thereof, or the application of such provision to other persons not similarly situated or to other, dissimilar circumstances.

103.

Use of appropriated funds

1Notwithstanding any other provision of this chapter, any report, notification, or consultation addressing directly or indirectly the use of appropriated funds and stipulated by this chapter to be submitted to, or held with, the Congress or any Congressional committee shall also be submitted to, or held with, the Committees on Appropriations of the Senate and the House of Representatives under the same conditions and with the same restrictions as stipulated by this chapter.

103a.

Department of Homeland Security Nonrecurring Expenses Fund

1There is hereby established in the Treasury of the United States a fund to be known as the "Department of Homeland Security Nonrecurring Expenses Fund" (the Fund).

2Unobligated balances of expired discretionary funds appropriated for this or any succeeding fiscal year from the General Fund of the Treasury to the Department of Homeland Security by this or any other Act may be transferred (not later than the end of the fifth fiscal year after the last fiscal year for which such funds are available for the purposes for which appropriated) into the Fund.

3Amounts deposited in the Fund shall be available until expended, and in addition to such other funds as may be available for such purposes, for information technology system modernization and facilities infrastructure improvements necessary for the operation of the Department, subject to approval by the Office of Management and Budget.

4Amounts in the Fund may not be apportioned or allotted for any fiscal year until after the date on which the Act making full-year appropriations for the Department of Homeland Security for the applicable fiscal year is enacted into law, subject to subsection (e).

5The Committees on Appropriations of the House of Representatives and the Senate shall be notified at least 15 days in advance of the planned use of funds.

104.

National biodefense strategy

1The Secretary of Defense, the Secretary of Health and Human Services, the Secretary of Homeland Security, and the Secretary of Agriculture shall jointly develop a national biodefense strategy and associated implementation plan, which shall include a review and assessment of biodefense policies, practices, programs and initiatives. Such Secretaries shall review and, as appropriate, revise the strategy biennially.

2The strategy and associated implementation plan required under subsection (a) shall include each of the following:

3(1) An inventory and assessment of all existing strategies, plans, policies, laws, and interagency agreements related to biodefense, including prevention, deterrence, preparedness, detection, response, attribution, recovery, and mitigation.

4(2) A description of the biological threats, including biological warfare, bioterrorism, naturally occurring infectious diseases, and accidental exposures.

5(3) A description of the current programs, efforts, or activities of the United States Government with respect to preventing the acquisition, proliferation, and use of a biological weapon, preventing an accidental or naturally occurring biological outbreak, and mitigating the effects of a biological epidemic.

6(4) A description of the roles and responsibilities of the Executive Agencies, including internal and external coordination procedures, in identifying and sharing information related to, warning of, and protection against, acts of terrorism using biological agents and weapons and accidental or naturally occurring biological outbreaks.

7(5) An articulation of related or required interagency capabilities and whole-of-Government activities required to support the national biodefense strategy.

8(6) Recommendations for strengthening and improving the current biodefense capabilities, authorities, and command structures of the United States Government.

9(7) Recommendations for improving and formalizing interagency coordination and support mechanisms with respect to providing a robust national biodefense.

10(8) Any other matters the Secretary of Defense, the Secretary of Health and Human Services, the Secretary of Homeland Security, and the Secretary of Agriculture determine necessary.

11Not later than 275 days after December 23, 2016, the Secretary of Defense, the Secretary of Health and Human Services, the Secretary of Homeland Security, and the Secretary of Agriculture shall submit to the appropriate congressional committees the strategy and associated implementation plan required by subsection (a). The strategy and implementation plan shall be submitted in unclassified form, but may include a classified annex.

12Not later than March 1, 2017, and annually thereafter until March 1, 2025, the Secretary of Defense, the Secretary of Health and Human Services, the Secretary of Homeland Security, and the Secretary of Agriculture shall provide to the Committee on Armed Services of the House of Representatives, the Committee on Energy and Commerce of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the Committee on Agriculture of the House of Representatives a joint briefing on the strategy developed under subsection (a) and the status of the implementation of such strategy.

13Not later than 180 days after the date of the submittal of the strategy and implementation plan under subsection (c), the Comptroller General of the United States shall conduct a review of the strategy and implementation plan to analyze gaps and resources mapped against the requirements of the National Biodefense Strategy and existing United States biodefense policy documents.

14In this section, the term "appropriate congressional committees" means the following:

15(1) The congressional defense committees.

16(2) The Committee on Energy and Commerce of the House of Representatives and the Committee on Health, Education, Labor, and Pensions of the Senate.

17(3) The Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate.

18(4) The Committee on Agriculture of the House of Representatives and the Committee on Agriculture, Nutrition, and Forestry of the Senate.

105.

Biodefense analysis and budget submission

1For each fiscal year, beginning in fiscal year 2023, the Director of the Office of Management and Budget, in consultation with the Secretary of Health and Human Services shall—

2(1) conduct a detailed and comprehensive analysis of Federal biodefense programs; and

3(2) develop an integrated biodefense budget submission.

4In accordance with the National Biodefense Strategy, the Director shall develop and disseminate to all Federal departments and agencies a unified definition of the term "biodefense" to identify which programs and activities are included in the annual budget submission required under subsection (a).

5The analysis required under subsection (a) shall include—

6(1) the display of all funds requested for biodefense activities, both mandatory and discretionary, by agency and categorized by biodefense enterprise element, such as threat awareness, prevention, deterrence, preparedness, surveillance and detection, response, attribution (including bioforensic capabilities), recovery, and mitigation; and

7(2) detailed explanations of how each program and activity included aligns with biodefense goals and objectives as part of the National Biodefense Strategy required under section 104 of this title.

8The Director, in consultation with the Secretary of Health and Human Services, shall submit to Congress the analysis required under subsection (a) for a fiscal year concurrently with the President's annual budget request for that fiscal year.

106.

Update of national biodefense implementation plan

1The Secretaries of Health and Human Services, Defense, Agriculture, Homeland Security, and all other Departments and agencies with responsibilities for biodefense, such as the Department of State, in consultation with the Assistant to the President for National Security Affairs and the Director of the Office of Management and Budget, as appropriate, shall jointly, after reviewing the biodefense threat assessment described in subsection (d) and any relevant input from external stakeholders, as appropriate, update the National Biodefense Implementation Plan developed under section 104 of this title to clearly document established processes, roles, and responsibilities related to the National Biodefense Strategy.

2The updated National Biodefense Implementation Plan shall—

3(1) describe the roles and responsibilities of the Federal departments and agencies, including internal and external coordination procedures, in identifying and sharing information between and among Federal departments and agencies, as described in section 104(b)(4) of this title and consistent with the statutory roles and authorities of such departments and agencies;

4(2) describe roles, responsibilities, and processes for decisionmaking, including decisions regarding use of resources for effective risk management across the enterprise;

5(3) describe resource plans for each department and agency with responsibility for biodefense to support implementation of the strategy within the jurisdiction of such department or agency, including for the Biodefense Coordination Team, as appropriate;

6(4) describe guidance and methods for analyzing the data collected from agencies to include non-Federal resources and capabilities to the extent practicable; and

7(5) describe and update, as appropriate, short-, medium-, and long-term goals for executing the National Biodefense Strategy and metrics for meeting each objective of the Strategy.

8The Secretary of Health and Human Services, the Secretary of Defense, the Secretary of Agriculture, and the Secretary of Homeland Security shall, not later than 6 months after the date of the completion of the assessment in subsection (d)(1)(A), submit the updated Implementation Plan to the appropriate congressional committees.

9The Secretaries of Health and Human Services, Defense, Agriculture, and Homeland Security, shall jointly, and in consultation with the Director of National Intelligence, and other agency heads as appropriate—

10(A) conduct an assessment of current and potential biological threats against the United States, both naturally occurring and man-made, either accidental or deliberate, including the potential for catastrophic biological threats, such as a pandemic;

11(B) not later than 1 year after January 1, 2021, submit the findings of the assessment conducted under subparagraph (A) to the Federal officials described in subsection (d)(1)and 1 the appropriate congressional committees described in subsection (e);

12(C) not later than 30 days after the date on which the assessment is submitted under subparagraph (B), conduct a briefing for the appropriate congressional committees on the findings of the assessment;

13(D) update the assessment under subparagraph (A) biennially, as appropriate, and provide the findings of such updated assessments to the Federal officials described in subsection (d)(1) and the appropriate congressional committees; and

14(E) conduct briefings for the appropriate congressional committees as needed any time an assessment under this paragraph is updated.

15Assessments under paragraph (1) shall be submitted in an unclassified format and include a classified annex, as appropriate.

16In this section, the term "appropriate congressional committees" means the following:

17(1) The Committees on Armed Services of the House of Representatives and the Senate.

18(2) The Committee on Energy and Commerce of the House of Representatives and the Committee on Health, Education, Labor, and Pensions of the Senate.

19(3) The Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate.

20(4) The Committee on Agriculture of the House of Representatives and the Committee on Agriculture, Nutrition, and Forestry of the Senate.

21(5) The Permanent Select Committee on Intelligence of the House of Representatives and the Select Committee on Intelligence of the Senate.

22(6) The Committee on Foreign Affairs of the House of Representatives and the Committee on Foreign Relations of the Senate.

23Nothing in this section shall be construed to alter, limit, or duplicate the roles, responsibilities, authorities, or current activities, as established in statute or otherwise through existing practice or policy, of each Federal department or agency with responsibilities for biodefense or otherwise relevant to implementation of the National Biodefense Strategy.

111.

Executive department; mission

1There is established a Department of Homeland Security, as an executive department of the United States within the meaning of title 5.

2The primary mission of the Department is to—

3(A) prevent terrorist attacks within the United States;

4(B) reduce the vulnerability of the United States to terrorism;

5(C) minimize the damage, and assist in the recovery, from terrorist attacks that do occur within the United States;

6(D) carry out all functions of entities transferred to the Department, including by acting as a focal point regarding natural and manmade crises and emergency planning;

7(E) ensure that the functions of the agencies and subdivisions within the Department that are not related directly to securing the homeland are not diminished or neglected except by a specific explicit Act of Congress;

8(F) ensure that the overall economic security of the United States is not diminished by efforts, activities, and programs aimed at securing the homeland;

9(G) ensure that the civil rights and civil liberties of persons are not diminished by efforts, activities, and programs aimed at securing the homeland; and

10(H) monitor connections between illegal drug trafficking and terrorism, coordinate efforts to sever such connections, and otherwise contribute to efforts to interdict illegal drug trafficking.

11Except as specifically provided by law with respect to entities transferred to the Department under this chapter, primary responsibility for investigating and prosecuting acts of terrorism shall be vested not in the Department, but rather in Federal, State, and local law enforcement agencies with jurisdiction over the acts in question.

112.

Secretary; functions

1There is a Secretary of Homeland Security, appointed by the President, by and with the advice and consent of the Senate.

2The Secretary is the head of the Department and shall have direction, authority, and control over it.

3All functions of all officers, employees, and organizational units of the Department are vested in the Secretary.

4The Secretary—

5(1) except as otherwise provided by this chapter, may delegate any of the Secretary's functions to any officer, employee, or organizational unit of the Department;

6(2) shall have the authority to make contracts, grants, and cooperative agreements, and to enter into agreements with other executive agencies, as may be necessary and proper to carry out the Secretary's responsibilities under this chapter or otherwise provided by law; and

7(3) shall take reasonable steps to ensure that information systems and databases of the Department are compatible with each other and with appropriate databases of other Departments.

8With respect to homeland security, the Secretary shall coordinate through the Office of State and Local Coordination 1 (established under section 361 of this title) (including the provision of training and equipment) with State and local government personnel, agencies, and authorities, with the private sector, and with other entities, including by—

9(1) coordinating with State and local government personnel, agencies, and authorities, and with the private sector, to ensure adequate planning, equipment, training, and exercise activities;

10(2) coordinating and, as appropriate, consolidating, the Federal Government's communications and systems of communications relating to homeland security with State and local government personnel, agencies, and authorities, the private sector, other entities, and the public; and

11(3) distributing or, as appropriate, coordinating the distribution of, warnings and information to State and local government personnel, agencies, and authorities and to the public.

12The Secretary may, subject to the direction of the President, attend and participate in meetings of the National Security Council.

13The issuance of regulations by the Secretary shall be governed by the provisions of chapter 5 of title 5, except as specifically provided in this chapter, in laws granting regulatory authorities that are transferred by this chapter, and in laws enacted after November 25, 2002.

14The Secretary shall appoint a Special Assistant to the Secretary who shall be responsible for—

15(1) creating and fostering strategic communications with the private sector to enhance the primary mission of the Department to protect the American homeland;

16(2) advising the Secretary on the impact of the Department's policies, regulations, processes, and actions on the private sector;

17(3) interfacing with other relevant Federal agencies with homeland security missions to assess the impact of these agencies' actions on the private sector;

18(4) creating and managing private sector advisory councils composed of representatives of industries and associations designated by the Secretary to—

19(A) advise the Secretary on private sector products, applications, and solutions as they relate to homeland security challenges;

20(B) advise the Secretary on homeland security policies, regulations, processes, and actions that affect the participating industries and associations; and

21(C) advise the Secretary on private sector preparedness issues, including effective methods for—

22(i) promoting voluntary preparedness standards to the private sector; and

23(ii) assisting the private sector in adopting voluntary preparedness standards;

24(5) working with Federal laboratories, federally funded research and development centers, other federally funded organizations, academia, and the private sector to develop innovative approaches to address homeland security challenges to produce and deploy the best available technologies for homeland security missions;

25(6) promoting existing public-private partnerships and developing new public-private partnerships to provide for collaboration and mutual support to address homeland security challenges;

26(7) assisting in the development and promotion of private sector best practices to secure critical infrastructure;

27(8) providing information to the private sector regarding voluntary preparedness standards and the business justification for preparedness and promoting to the private sector the adoption of voluntary preparedness standards;

28(9) coordinating industry efforts, with respect to functions of the Department of Homeland Security, to identify private sector resources and capabilities that could be effective in supplementing Federal, State, and local government agency efforts to prevent or respond to a terrorist attack;

29(10) coordinating with the Commissioner of U.S. Customs and Border Protection and the Assistant Secretary for Trade Development of the Department of Commerce on issues related to the travel and tourism industries; and

30(11) consulting with the Office of State and Local Government Coordination and Preparedness on all matters of concern to the private sector, including the tourism industry.

31All standards activities of the Department shall be conducted in accordance with section 12(d) of the National Technology Transfer Advancement Act of 1995 (15 U.S.C. 272 note) and Office of Management and Budget Circular A–119.

32The Secretary shall ensure the head of each office and component of the Department takes into account the needs of children, including children within under-served communities, in mission planning and mission execution. In furtherance of this subsection, the Secretary shall require each such head to seek, to the extent practicable, advice and feedback from organizations representing the needs of children. The Federal Advisory Committee Act (5 U.S.C. App.) 2 shall not apply whenever such advice or feedback is sought in accordance with this subsection.

113.

Other officers

1Except as provided under paragraph (2), there are the following officers, appointed by the President, by and with the advice and consent of the Senate:

2(A) A Deputy Secretary of Homeland Security, who shall be the Secretary's first assistant for purposes of subchapter III of chapter 33 of title 5.

3(B) An Under Secretary for Science and Technology.

4(C) A Commissioner of U.S. Customs and Border Protection.

5(D) An Administrator of the Federal Emergency Management Agency.

6(E) A Director of the Bureau of Citizenship and Immigration Services.

7(F) An Under Secretary for Management, who shall be first assistant to the Deputy Secretary of Homeland Security for purposes of subchapter III of chapter 33 of title 5.

8(G) A Director of U.S. Immigration and Customs Enforcement.

9(H) A Director of the Cybersecurity and Infrastructure Security Agency.

10(I) Not more than 12 Assistant Secretaries.

11(J) A General Counsel, who shall be the chief legal officer of the Department.

12(K) An Under Secretary for Strategy, Policy, and Plans.

13If any of the Assistant Secretaries referred to under paragraph (1)(I) is designated to be the Assistant Secretary for Health Affairs, the Assistant Secretary for Legislative Affairs, or the Assistant Secretary for Public Affairs, that Assistant Secretary shall be appointed by the President without the advice and consent of the Senate.

14There shall be in the Department an Office of Inspector General and an Inspector General at the head of such office, as provided in chapter 4 of title 5.

15To assist the Secretary in the performance of the Secretary's functions, there is a Commandant of the Coast Guard, who shall be appointed as provided in section 44 1 of title 14 and who shall report directly to the Secretary. In addition to such duties as may be provided in this chapter and as assigned to the Commandant by the Secretary, the duties of the Commandant shall include those required by section 2 1 of title 14.

16To assist the Secretary in the performance of the Secretary's functions, there are the following officers, appointed by the President:

17(1) A Director of the Secret Service.

18(2) A Chief Information Officer.

19(3) An Officer for Civil Rights and Civil Liberties.

20(4) An Assistant Secretary for the Countering Weapons of Mass Destruction Office.

21(5) Any Director of a Joint Task Force under section 348 of this title.

22There shall be in the Department a Chief Financial Officer, as provided in chapter 9 of title 31.

23Subject to the provisions of this chapter, every officer of the Department shall perform the functions specified by law for the official's office or prescribed by the Secretary.

24Notwithstanding chapter 33 of title 5, the Under Secretary for Management shall serve as the Acting Secretary if by reason of absence, disability, or vacancy in office, neither the Secretary nor Deputy Secretary is available to exercise the duties of the Office of the Secretary.

25Notwithstanding chapter 33 of title 5, the Secretary may designate such other officers of the Department in further order of succession to serve as Acting Secretary.

26The Secretary shall notify the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives of any vacancies that require notification under sections 3345 through 3349d of title 5 (commonly known as the "Federal Vacancies Reform Act of 1998").

114.

Sensitive Security Information

1Using funds made available in this Act, the Secretary of Homeland Security shall provide that each office within the Department that handles documents marked as Sensitive Security Information (SSI) shall have at least one employee in that office with authority to coordinate and make determinations on behalf of the agency that such documents meet the criteria for marking as SSI: Provided, That not later than December 31, 2005, the Secretary shall submit to the Committees on Appropriations of the Senate and the House of Representatives: (1) Department-wide policies for designating, coordinating and marking documents as SSI; (2) Department-wide auditing and accountability procedures for documents designated and marked as SSI; (3) the total number of SSI Coordinators within the Department; and (4) the total number of staff authorized to designate SSI documents within the Department: Provided further, That not later than January 31, 2006, the Secretary shall provide to the Committees on Appropriations of the Senate and the House of Representatives the title of all DHS documents that are designated as SSI in their entirety during the period October 1, 2005, through December 31, 2005: Provided further, That not later than January 31 of each succeeding year, starting on January 31, 2007, the Secretary shall provide annually a similar report to the Committees on Appropriations of the Senate and the House of Representatives on the titles of all DHS documents that are designated as SSI in their entirety during the period of January 1 through December 31 for the preceding year: Provided further, That the Secretary shall promulgate guidance that includes common but extensive examples of SSI that further define the individual categories of information cited under 49 CFR 1520(b)(1) through (16) and eliminates judgment by covered persons in the application of the SSI marking: Provided further, That such guidance shall serve as the primary basis and authority for the marking of DHS information as SSI by covered persons.

115.

Trade and customs revenue functions of the Department

1The Secretary shall designate an appropriate senior official in the office of the Secretary who shall—

2(A) ensure that the trade and customs revenue functions of the Department are coordinated within the Department and with other Federal departments and agencies, and that the impact on legitimate trade is taken into account in any action impacting the functions; and

3(B) monitor and report to Congress on the Department's mandate to ensure that the trade and customs revenue functions of the Department are not diminished, including how spending, operations, and personnel related to these functions have kept pace with the level of trade entering the United States.

4There shall be a Director of Trade Policy (in this subsection referred to as the "Director"), who shall be subject to the direction and control of the official designated pursuant to paragraph (1). The Director shall—

5(A) advise the official designated pursuant to paragraph (1) regarding all aspects of Department policies relating to the trade and customs revenue functions of the Department;

6(B) coordinate the development of Department-wide policies regarding trade and customs revenue functions and trade facilitation; and

7(C) coordinate the trade and customs revenue-related policies of the Department with the policies of other Federal departments and agencies.

8The Comptroller General of the United States shall conduct a study evaluating the extent to which the Department of Homeland Security is meeting its obligations under section 212(b) of this title with respect to the maintenance of customs revenue functions.

9The study shall include an analysis of—

10(A) the extent to which the customs revenue functions carried out by the former United States Customs Service have been consolidated with other functions of the Department (including the assignment of noncustoms revenue functions to personnel responsible for customs revenue collection), discontinued, or diminished following the transfer of the United States Customs Service to the Department;

11(B) the extent to which staffing levels or resources attributable to customs revenue functions have decreased since the transfer of the United States Customs Service to the Department; and

12(C) the extent to which the management structure created by the Department ensures effective trade facilitation and customs revenue collection.

13Not later than 180 days after October 13, 2006, the Comptroller General shall submit to the appropriate congressional committees a report on the results of the study conducted under subsection (a).

14Not later than September 30, 2007, the Secretary shall ensure that the requirements of section 212(b) of this title are fully satisfied and shall report to the Committee on Finance of the Senate and the Committee on Ways and Means of the House of Representatives regarding implementation of this paragraph.

15In this section, the term "customs revenue functions" means the functions described in section 212(b)(2) of this title.

16The Secretary shall consult with representatives of the business community involved in international trade, including seeking the advice and recommendations of the Commercial Operations Advisory Committee, not later than 30 days after proposing, and not later than 30 days before finalizing, any Department policies, initiatives, or actions that will have a significant impact on international trade and customs revenue functions.

17Subject to subparagraph (B), the Secretary shall notify the appropriate congressional committees not later than 60 days before proposing, and not later than 60 days before finalizing, any Department policies, initiatives, or actions that will have a major impact on trade and customs revenue functions. Such notifications shall include a description of the proposed policies, initiatives, or actions and any comments or recommendations provided by the Commercial Operations Advisory Committee and other relevant groups regarding the proposed policies, initiatives, or actions.

18If the Secretary determines that it is important to the national security interest of the United States to finalize any Department policies, initiatives, or actions prior to the consultation described in subparagraph (A), the Secretary shall—

19(i) notify and provide any recommendations of the Commercial Operations Advisory Committee received to the appropriate congressional committees not later than 45 days after the date on which the policies, initiatives, or actions are finalized; and

20(ii) to the extent appropriate, modify the policies, initiatives, or actions based upon the consultations with the appropriate congressional committees.

21Not less than 45 days prior to any change in the organization of any of the customs revenue functions of the Department, the Secretary shall notify the Committee on Appropriations, the Committee on Finance, and the Committee on Homeland Security and Governmental Affairs of the Senate, and the Committee on Appropriations, the Committee on Homeland Security, and the Committee on Ways and Means of the House of Representatives of the specific assets, functions, or personnel to be transferred as part of such reorganization, and the reason for such transfer. The notification shall also include—

22(A) an explanation of how trade enforcement functions will be impacted by the reorganization;

23(B) an explanation of how the reorganization meets the requirements of section 212(b) of this title that the Department not diminish the customs revenue and trade facilitation functions formerly performed by the United States Customs Service; and

24(C) any comments or recommendations provided by the Commercial Operations Advisory Committee regarding such reorganization.

25Any congressional committee referred to in paragraph (1) may request that the Commercial Operations Advisory Committee provide a report to the committee analyzing the impact of the reorganization and providing any recommendations for modifying the reorganization.

26Not later than 1 year after any reorganization referred to in paragraph (1) takes place, the Secretary, in consultation with the Commercial Operations Advisory Committee, shall submit a report to the Committee on Finance of the Senate and the Committee on Ways and Means of the House of Representatives. Such report shall include an assessment of the impact of, and any suggested modifications to, such reorganization.

121.

Information and Analysis

1There shall be in the Department an Office of Intelligence and Analysis.

2The Office of Intelligence and Analysis shall be headed by an Under Secretary for Intelligence and Analysis, who shall be appointed by the President, by and with the advice and consent of the Senate.

3The Under Secretary for Intelligence and Analysis shall serve as the Chief Intelligence Officer of the Department.

4The Secretary shall ensure that the responsibilities of the Department relating to information analysis, including those described in subsection (d), are carried out through the Under Secretary for Intelligence and Analysis.

5The responsibilities of the Secretary relating to intelligence and analysis shall be as follows:

6(1) To access, receive, and analyze law enforcement information, intelligence information, and other information from agencies of the Federal Government, State and local government agencies (including law enforcement agencies), and private sector entities, and to integrate such information, in support of the mission responsibilities of the Department and the functions of the National Counterterrorism Center established under section 119 of the National Security Act of 1947 [50 U.S.C. 3056], in order to—

7(A) identify and assess the nature and scope of terrorist threats to the homeland;

8(B) detect and identify threats of terrorism against the United States; and

9(C) understand such threats in light of actual and potential vulnerabilities of the homeland.

10(2) To carry out comprehensive assessments of the vulnerabilities of the key resources and critical infrastructure of the United States, including the performance of risk assessments to determine the risks posed by particular types of terrorist attacks within the United States (including an assessment of the probability of success of such attacks and the feasibility and potential efficacy of various countermeasures to such attacks).

11(3) To integrate relevant information, analysis, and vulnerability assessments (regardless of whether such information, analysis or assessments are provided by or produced by the Department) in order to—

12(A) identify priorities for protective and support measures regarding terrorist and other threats to homeland security by the Department, other agencies of the Federal Government, State, 1 and local government agencies and authorities, the private sector, and other entities; and

13(B) prepare finished intelligence and information products in both classified and unclassified formats, as appropriate, whenever reasonably expected to be of benefit to a State, local, or tribal government (including a State, local, or tribal law enforcement agency) or a private sector entity.

14(4) To ensure, pursuant to section 122 of this title, the timely and efficient access by the Department to all information necessary to discharge the responsibilities under this section, including obtaining such information from other agencies of the Federal Government.

15(5) To review, analyze, and make recommendations for improvements to the policies and procedures governing the sharing of information within the scope of the information sharing environment established under section 485 of this title, including homeland security information, terrorism information, and weapons of mass destruction information, and any policies, guidelines, procedures, instructions, or standards established under that section.

16(6) To disseminate, as appropriate, information analyzed by the Department within the Department, to other agencies of the Federal Government with responsibilities relating to homeland security, and to agencies of State and local governments and private sector entities with such responsibilities in order to assist in the deterrence, prevention, preemption of, or response to, terrorist attacks against the United States.

17(7) To consult with the Director of National Intelligence and other appropriate intelligence, law enforcement, or other elements of the Federal Government to establish collection priorities and strategies for information, including law enforcement-related information, relating to threats of terrorism against the United States through such means as the representation of the Department in discussions regarding requirements and priorities in the collection of such information.

18(8) To consult with State and local governments and private sector entities to ensure appropriate exchanges of information, including law enforcement-related information, relating to threats of terrorism against the United States.

19(9) To ensure that—

20(A) any material received pursuant to this chapter is protected from unauthorized disclosure and handled and used only for the performance of official duties; and

21(B) any intelligence information under this chapter is shared, retained, and disseminated consistent with the authority of the Director of National Intelligence to protect intelligence sources and methods under the National Security Act of 1947 [50 U.S.C. 3001 et seq.] and related procedures and, as appropriate, similar authorities of the Attorney General concerning sensitive law enforcement information.

22(10) To request additional information from other agencies of the Federal Government, State and local government agencies, and the private sector relating to threats of terrorism in the United States, or relating to other areas of responsibility assigned by the Secretary, including the entry into cooperative agreements through the Secretary to obtain such information.

23(11) To establish and utilize, in conjunction with the chief information officer of the Department, a secure communications and information technology infrastructure, including data-mining and other advanced analytical tools, in order to access, receive, and analyze data and information in furtherance of the responsibilities under this section, and to disseminate information acquired and analyzed by the Department, as appropriate.

24(12) To ensure, in conjunction with the chief information officer of the Department, that any information databases and analytical tools developed or utilized by the Department—

25(A) are compatible with one another and with relevant information databases of other agencies of the Federal Government; and

26(B) treat information in such databases in a manner that complies with applicable Federal law on privacy.

27(13) To coordinate training and other support to the elements and personnel of the Department, other agencies of the Federal Government, and State and local governments that provide information to the Department, or are consumers of information provided by the Department, in order to facilitate the identification and sharing of information revealed in their ordinary duties and the optimal utilization of information received from the Department.

28(14) To coordinate with elements of the intelligence community and with Federal, State, and local law enforcement agencies, and the private sector, as appropriate.

29(15) To provide intelligence and information analysis and support to other elements of the Department.

30(16) To coordinate and enhance integration among the intelligence components of the Department, including through strategic oversight of the intelligence activities of such components.

31(17) To establish the intelligence collection, processing, analysis, and dissemination priorities, policies, processes, standards, guidelines, and procedures for the intelligence components of the Department, consistent with any directions from the President and, as applicable, the Director of National Intelligence.

32(18) To establish a structure and process to support the missions and goals of the intelligence components of the Department.

33(19) To ensure that, whenever possible, the Department—

34(A) produces and disseminates unclassified reports and analytic products based on open-source information; and

35(B) produces and disseminates such reports and analytic products contemporaneously with reports or analytic products concerning the same or similar information that the Department produced and disseminated in a classified format.

36(20) To establish within the Office of Intelligence and Analysis an internal continuity of operations plan.

37(21) Based on intelligence priorities set by the President, and guidance from the Secretary and, as appropriate, the Director of National Intelligence—

38(A) to provide to the heads of each intelligence component of the Department guidance for developing the budget pertaining to the activities of such component; and

39(B) to present to the Secretary a recommendation for a consolidated budget for the intelligence components of the Department, together with any comments from the heads of such components.

40(22) To perform such other duties relating to such responsibilities as the Secretary may provide.

41(23)(A) Not later than six months after December 23, 2016, to conduct an intelligence-based review and comparison of the risks and consequences of EMP and GMD facing critical infrastructure, and submit to the Committee on Homeland Security and the Permanent Select Committee on Intelligence of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Select Committee on Intelligence of the Senate—

42(i) a recommended strategy to protect and prepare the critical infrastructure of the homeland against threats of EMP and GMD; and

43(ii) not less frequently than every two years thereafter for the next six years, updates of the recommended strategy.

44(B) The recommended strategy under subparagraph (A) shall—

45(i) be based on findings of the research and development conducted under section 195f of this title;

46(ii) be developed in consultation with the relevant Federal sector-specific agencies (as defined under Presidential Policy Directive-21) for critical infrastructure;

47(iii) be developed in consultation with the relevant sector coordinating councils for critical infrastructure;

48(iv) be informed, to the extent practicable, by the findings of the intelligence-based review and comparison of the risks and consequences of EMP and GMD facing critical infrastructure conducted under subparagraph (A); and

49(v) be submitted in unclassified form, but may include a classified annex.

50(C) The Secretary may, if appropriate, incorporate the recommended strategy into a broader recommendation developed by the Department to help protect and prepare critical infrastructure from terrorism, cyber attacks, and other threats if, as incorporated, the recommended strategy complies with subparagraph (B).

51The Secretary shall provide the Office of Intelligence and Analysis with a staff of analysts having appropriate expertise and experience to assist such offices in discharging responsibilities under this section.

52Analysts under this subsection may include analysts from the private sector.

53Analysts under this subsection shall possess security clearances appropriate for their work under this section.

54In order to assist the Office of Intelligence and Analysis in discharging responsibilities under this section, personnel of the agencies referred to in paragraph (2) may be detailed to the Department for the performance of analytic functions and related duties.

55The agencies referred to in this paragraph are as follows:

56(A) The Department of State.

57(B) The Central Intelligence Agency.

58(C) The Federal Bureau of Investigation.

59(D) The National Security Agency.

60(E) The National Geospatial-Intelligence Agency.

61(F) The Defense Intelligence Agency.

62(G) Any other agency of the Federal Government that the President considers appropriate.

63The Secretary and the head of the agency concerned may enter into cooperative agreements for the purpose of detailing personnel under this subsection.

64The detail of personnel under this subsection may be on a reimbursable or non-reimbursable basis.

65In accordance with subchapter XII, there shall be transferred to the Secretary, for assignment to the Office of Intelligence and Analysis and the Office of Infrastructure Protection under this section, the functions, personnel, assets, and liabilities of the following:

66(1) The National Infrastructure Protection Center of the Federal Bureau of Investigation (other than the Computer Investigations and Operations Section), including the functions of the Attorney General relating thereto.

67(2) The National Communications System of the Department of Defense, including the functions of the Secretary of Defense relating thereto.

68(3) The Critical Infrastructure Assurance Office of the Department of Commerce, including the functions of the Secretary of Commerce relating thereto.

69(4) The National Infrastructure Simulation and Analysis Center of the Department of Energy and the energy security and assurance program and activities of the Department, including the functions of the Secretary of Energy relating thereto.

70(5) The Federal Computer Incident Response Center of the General Services Administration, including the functions of the Administrator of General Services relating thereto.

121a.

Homeland Security Intelligence Program

1There is established within the Department of Homeland Security a Homeland Security Intelligence Program. The Homeland Security Intelligence Program constitutes the intelligence activities of the Office of Intelligence and Analysis of the Department that serve predominantly departmental missions.

122.

Access to information

1Except as otherwise directed by the President, the Secretary shall have such access as the Secretary considers necessary to all information, including reports, assessments, analyses, and unevaluated intelligence relating to threats of terrorism against the United States and to other areas of responsibility assigned by the Secretary, and to all information concerning infrastructure or other vulnerabilities of the United States to terrorism, whether or not such information has been analyzed, that may be collected, possessed, or prepared by any agency of the Federal Government.

2The Secretary shall also have access to other information relating to matters under the responsibility of the Secretary that may be collected, possessed, or prepared by an agency of the Federal Government as the President may further provide.

3Except as otherwise directed by the President, with respect to information to which the Secretary has access pursuant to this section—

4(1) the Secretary may obtain such material upon request, and may enter into cooperative arrangements with other executive agencies to provide such material or provide Department officials with access to it on a regular or routine basis, including requests or arrangements involving broad categories of material, access to electronic databases, or both; and

5(2) regardless of whether the Secretary has made any request or entered into any cooperative arrangement pursuant to paragraph (1), all agencies of the Federal Government shall promptly provide to the Secretary—

6(A) all reports (including information reports containing intelligence which has not been fully evaluated), assessments, and analytical information relating to threats of terrorism against the United States and to other areas of responsibility assigned by the Secretary;

7(B) all information concerning the vulnerability of the infrastructure of the United States, or other vulnerabilities of the United States, to terrorism, whether or not such information has been analyzed;

8(C) all other information relating to significant and credible threats of terrorism against the United States, whether or not such information has been analyzed; and

9(D) such other information or material as the President may direct.

10The Secretary shall be deemed to be a Federal law enforcement, intelligence, protective, national defense, immigration, or national security official, and shall be provided with all information from law enforcement agencies that is required to be given to the Director of National Intelligence, under any provision of the following:

11(1) The USA PATRIOT Act of 2001 (Public Law 107–56).

12(2) Section 2517(6) of title 18.

13(3) Rule 6(e)(3)(C) of the Federal Rules of Criminal Procedure.

14Nothing in this subchapter shall preclude any element of the intelligence community (as that term is defined in section 3003(4) of title 50,1 or any other element of the Federal Government with responsibility for analyzing terrorist threat information, from receiving any intelligence or other information relating to terrorism.

15The Secretary, in consultation with the Director of National Intelligence, shall work to ensure that intelligence or other information relating to terrorism to which the Department has access is appropriately shared with the elements of the Federal Government referred to in paragraph (1), as well as with State and local governments, as appropriate.

123.

Terrorist travel program

1Not later than 90 days after August 3, 2007, the Secretary of Homeland Security, in consultation with the Director of the National Counterterrorism Center and consistent with the strategy developed under section 7201,1 shall establish a program to oversee the implementation of the Secretary's responsibilities with respect to terrorist travel.

2The Secretary of Homeland Security shall designate an official of the Department of Homeland Security to be responsible for carrying out the program. Such official shall be—

3(1) the Assistant Secretary for Policy of the Department of Homeland Security; or

4(2) an official appointed by the Secretary who reports directly to the Secretary.

5The official designated under subsection (b) shall assist the Secretary of Homeland Security in improving the Department's ability to prevent terrorists from entering the United States or remaining in the United States undetected by—

6(1) developing relevant strategies and policies;

7(2) reviewing the effectiveness of existing programs and recommending improvements, if necessary;

8(3) making recommendations on budget requests and on the allocation of funding and personnel;

9(4) ensuring effective coordination, with respect to policies, programs, planning, operations, and dissemination of intelligence and information related to terrorist travel—

10(A) among appropriate subdivisions of the Department of Homeland Security, as determined by the Secretary and including—

11(i) United States Customs and Border Protection;

12(ii) United States Immigration and Customs Enforcement;

13(iii) United States Citizenship and Immigration Services;

14(iv) the Transportation Security Administration; and

15(v) the United States Coast Guard; and

16(B) between the Department of Homeland Security and other appropriate Federal agencies; and

17(5) serving as the Secretary's primary point of contact with the National Counterterrorism Center for implementing initiatives related to terrorist travel and ensuring that the recommendations of the Center related to terrorist travel are carried out by the Department.

18Not later than 180 days after August 3, 2007, the Secretary of Homeland Security shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the implementation of this section.

124.

Homeland Security Advisory System

1The Secretary shall administer the Homeland Security Advisory System in accordance with this section to provide advisories or warnings regarding the threat or risk that acts of terrorism will be committed on the homeland to Federal, State, local, and tribal government authorities and to the people of the United States, as appropriate. The Secretary shall exercise primary responsibility for providing such advisories or warnings.

2In administering the Homeland Security Advisory System, the Secretary shall—

3(1) establish criteria for the issuance and revocation of such advisories or warnings;

4(2) develop a methodology, relying on the criteria established under paragraph (1), for the issuance and revocation of such advisories or warnings;

5(3) provide, in each such advisory or warning, specific information and advice regarding appropriate protective measures and countermeasures that may be taken in response to the threat or risk, at the maximum level of detail practicable to enable individuals, government entities, emergency response providers, and the private sector to act appropriately;

6(4) whenever possible, limit the scope of each such advisory or warning to a specific region, locality, or economic sector believed to be under threat or at risk; and

7(5) not, in issuing any advisory or warning, use color designations as the exclusive means of specifying homeland security threat conditions that are the subject of the advisory or warning.

124a.

Homeland security information sharing

1Consistent with section 485 of this title, the Secretary, acting through the Under Secretary for Intelligence and Analysis, shall integrate the information and standardize the format of the products of the intelligence components of the Department containing homeland security information, terrorism information, weapons of mass destruction information, or national intelligence (as defined in section 3003(5) of title 50) except for any internal security protocols or personnel information of such intelligence components, or other administrative processes that are administered by any chief security officer of the Department.

2For each intelligence component of the Department, the Secretary shall designate an information sharing and knowledge management officer who shall report to the Under Secretary for Intelligence and Analysis regarding coordinating the different systems used in the Department to gather and disseminate homeland security information or national intelligence (as defined in section 3003(5) of title 50).

3The Secretary, acting through the Under Secretary for Intelligence and Analysis or the Director of the Cybersecurity and Infrastructure Security Agency, as appropriate, shall—

4(A) establish Department-wide procedures for the review and analysis of information provided by State, local, and tribal governments and the private sector;

5(B) as appropriate, integrate such information into the information gathered by the Department and other departments and agencies of the Federal Government; and

6(C) make available such information, as appropriate, within the Department and to other departments and agencies of the Federal Government.

7The Secretary shall develop mechanisms to provide feedback regarding the analysis and utility of information provided by any entity of State, local, or tribal government or the private sector that provides such information to the Department.

8The Secretary, acting through the Under Secretary for Intelligence and Analysis or the Director of the Cybersecurity and Infrastructure Security Agency, as appropriate, shall provide to employees of the Department opportunities for training and education to develop an understanding of—

9(A) the definitions of homeland security information and national intelligence (as defined in section 3003(5) of title 50); and

10(B) how information available to such employees as part of their duties—

11(i) might qualify as homeland security information or national intelligence; and

12(ii) might be relevant to the Office of Intelligence and Analysis and the intelligence components of the Department.

13The Under Secretary for Intelligence and Analysis shall—

14(A) on an ongoing basis, evaluate how employees of the Office of Intelligence and Analysis and the intelligence components of the Department are utilizing homeland security information or national intelligence, sharing information within the Department, as described in this subchapter, and participating in the information sharing environment established under section 485 of this title; and

15(B) provide to the appropriate component heads regular reports regarding the evaluations under subparagraph (A).

124b.

Comprehensive information technology network architecture

1The Secretary, acting through the Under Secretary for Intelligence and Analysis, shall establish, consistent with the policies and procedures developed under section 485 of this title, and consistent with the enterprise architecture of the Department, a comprehensive information technology network architecture for the Office of Intelligence and Analysis that connects the various databases and related information technology assets of the Office of Intelligence and Analysis and the intelligence components of the Department in order to promote internal information sharing among the intelligence and other personnel of the Department.

2The term "comprehensive information technology network architecture" means an integrated framework for evolving or maintaining existing information technology and acquiring new information technology to achieve the strategic management and information resources management goals of the Office of Intelligence and Analysis.

124c.

Coordination with information sharing environment

1All activities to comply with sections 124, 124a, and 124b of this title shall be—

2(1) consistent with any policies, guidelines, procedures, instructions, or standards established under section 485 of this title;

3(2) implemented in coordination with, as appropriate, the program manager for the information sharing environment established under that section;

4(3) consistent with any applicable guidance issued by the Director of National Intelligence; and

5(4) consistent with any applicable guidance issued by the Secretary relating to the protection of law enforcement information or proprietary information.

6In carrying out the duties and responsibilities under this part, the Under Secretary for Intelligence and Analysis shall take into account the views of the heads of the intelligence components of the Department.

124d.

Intelligence components

1Subject to the direction and control of the Secretary, and consistent with any applicable guidance issued by the Director of National Intelligence, the responsibilities of the head of each intelligence component of the Department are as follows:

2(1) To ensure that the collection, processing, analysis, and dissemination of information within the scope of the information sharing environment, including homeland security information, terrorism information, weapons of mass destruction information, and national intelligence (as defined in section 3003(5) of title 50), are carried out effectively and efficiently in support of the intelligence mission of the Department, as led by the Under Secretary for Intelligence and Analysis.

3(2) To otherwise support and implement the intelligence mission of the Department, as led by the Under Secretary for Intelligence and Analysis.

4(3) To incorporate the input of the Under Secretary for Intelligence and Analysis with respect to performance appraisals, bonus or award recommendations, pay adjustments, and other forms of commendation.

5(4) To coordinate with the Under Secretary for Intelligence and Analysis in developing policies and requirements for the recruitment and selection of intelligence officials of the intelligence component.

6(5) To advise and coordinate with the Under Secretary for Intelligence and Analysis on any plan to reorganize or restructure the intelligence component that would, if implemented, result in realignments of intelligence functions.

7(6) To ensure that employees of the intelligence component have knowledge of, and comply with, the programs and policies established by the Under Secretary for Intelligence and Analysis and other appropriate officials of the Department and that such employees comply with all applicable laws and regulations.

8(7) To perform such other activities relating to such responsibilities as the Secretary may provide.

124e.

Training for employees of intelligence components

1The Secretary shall provide training and guidance for employees, officials, and senior executives of the intelligence components of the Department to develop knowledge of laws, regulations, operations, policies, procedures, and programs that are related to the functions of the Department relating to the collection, processing, analysis, and dissemination of information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, or national intelligence (as defined in section 3003(5) of title 50).

124f.

Intelligence training development for State and local government officials

1The Secretary, acting through the Under Secretary for Intelligence and Analysis, shall—

2(1) develop a curriculum for training State, local, and tribal government officials, including law enforcement officers, intelligence analysts, and other emergency response providers, in the intelligence cycle and Federal laws, practices, and regulations regarding the development, handling, and review of intelligence and other information; and

3(2) ensure that the curriculum includes executive level training for senior level State, local, and tribal law enforcement officers, intelligence analysts, and other emergency response providers.

4To the extent possible, the Federal Law Enforcement Training Center and other existing Federal entities with the capacity and expertise to train State, local, and tribal government officials based on the curriculum developed under subsection (a) shall be used to carry out the training programs created under this section. If such entities do not have the capacity, resources, or capabilities to conduct such training, the Secretary may approve another entity to conduct such training.

5In carrying out the duties described in subsection (a), the Under Secretary for Intelligence and Analysis shall consult with the Director of the Federal Law Enforcement Training Center, the Attorney General, the Director of National Intelligence, the Administrator of the Federal Emergency Management Agency, and other appropriate parties, such as private industry, institutions of higher education, nonprofit institutions, and other intelligence agencies of the Federal Government.

124g.

Information sharing incentives

1In making cash awards under chapter 45 of title 5, the President or the head of an agency, in consultation with the program manager designated under section 485 of this title, may consider the success of an employee in appropriately sharing information within the scope of the information sharing environment established under that section, including homeland security information, terrorism information, and weapons of mass destruction information, or national intelligence (as defined in section 3003(5) of title 50 1, in a manner consistent with any policies, guidelines, procedures, instructions, or standards established by the President or, as appropriate, the program manager of that environment for the implementation and management of that environment.

2The head of each department or agency described in section 485(h) of this title, in consultation with the program manager designated under section 485 of this title, shall adopt best practices regarding effective ways to educate and motivate officers and employees of the Federal Government to participate fully in the information sharing environment, including—

3(1) promotions and other nonmonetary awards; and

4(2) publicizing information sharing accomplishments by individual employees and, where appropriate, the tangible end benefits that resulted.

124h.

Department of Homeland Security State, Local, and Regional Fusion Center Initiative

1The Secretary, in consultation with the program manager of the information sharing environment established under section 485 of this title, the Attorney General, the Privacy Officer of the Department, the Officer for Civil Rights and Civil Liberties of the Department, and the Privacy and Civil Liberties Oversight Board established under section 2000ee of title 42, shall establish a Department of Homeland Security State, Local, and Regional Fusion Center Initiative to establish partnerships with State, local, and regional fusion centers.

2Through the Department of Homeland Security State, Local, and Regional Fusion Center Initiative, and in coordination with the principal officials of participating State, local, or regional fusion centers and the officers designated as the Homeland Security Advisors of the States, the Secretary shall—

3(1) provide operational and intelligence advice and assistance to State, local, and regional fusion centers;

4(2) support efforts to include State, local, and regional fusion centers into efforts to establish an information sharing environment;

5(3) conduct tabletop and live training exercises to regularly assess the capability of individual and regional networks of State, local, and regional fusion centers to integrate the efforts of such networks with the efforts of the Department;

6(4) coordinate with other relevant Federal entities engaged in homeland security-related activities;

7(5) provide analytic and reporting advice and assistance to State, local, and regional fusion centers;

8(6) review information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, that is gathered by State, local, and regional fusion centers, and to incorporate such information, as appropriate, into the Department's own such information;

9(7) provide management assistance to State, local, and regional fusion centers;

10(8) serve as a point of contact to ensure the dissemination of information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information;

11(9) facilitate close communication and coordination between State, local, and regional fusion centers and the Department;

12(10) provide State, local, and regional fusion centers with expertise on Department resources and operations;

13(11) provide training to State, local, and regional fusion centers and encourage such fusion centers to participate in terrorism threat-related exercises conducted by the Department; and

14(12) carry out such other duties as the Secretary determines are appropriate.

15The Under Secretary for Intelligence and Analysis shall, to the maximum extent practicable, assign officers and intelligence analysts from components of the Department to participating State, local, and regional fusion centers.

16Officers and intelligence analysts assigned to participating fusion centers under this subsection may be assigned from the following Department components, in coordination with the respective component head and in consultation with the principal officials of participating fusion centers:

17(A) Office of Intelligence and Analysis.

18(B) Cybersecurity and Infrastructure Security Agency.

19(C) Transportation Security Administration.

20(D) United States Customs and Border Protection.

21(E) United States Immigration and Customs Enforcement.

22(F) United States Coast Guard.

23(G) Other components of the Department, as determined by the Secretary.

24The Secretary shall develop qualifying criteria for a fusion center to participate in the assigning of Department officers or intelligence analysts under this section.

25Any criteria developed under subparagraph (A) may include—

26(i) whether the fusion center, through its mission and governance structure, focuses on a broad counterterrorism approach, and whether that broad approach is pervasive through all levels of the organization;

27(ii) whether the fusion center has sufficient numbers of adequately trained personnel to support a broad counterterrorism mission;

28(iii) whether the fusion center has—

29(I) access to relevant law enforcement, emergency response, private sector, open source, and national security data; and

30(II) the ability to share and analytically utilize that data for lawful purposes;

31(iv) whether the fusion center is adequately funded by the State, local, or regional government to support its counterterrorism mission; and

32(v) the relevancy of the mission of the fusion center to the particular source component of Department officers or intelligence analysts.

33Before being assigned to a fusion center under this section, an officer or intelligence analyst shall undergo—

34(i) appropriate intelligence analysis or information sharing training using an intelligence-led policing curriculum that is consistent with—

35(I) standard training and education programs offered to Department law enforcement and intelligence personnel; and

36(II) the Criminal Intelligence Systems Operating Policies under part 23 of title 28, Code of Federal Regulations (or any corresponding similar rule or regulation);

37(ii) appropriate privacy and civil liberties training that is developed, supported, or sponsored by the Privacy Officer appointed under section 142 of this title and the Officer for Civil Rights and Civil Liberties of the Department, in consultation with the Privacy and Civil Liberties Oversight Board established under section 2000ee of title 42; and

38(iii) such other training prescribed by the Under Secretary for Intelligence and Analysis.

39In determining the eligibility of an officer or intelligence analyst to be assigned to a fusion center under this section, the Under Secretary for Intelligence and Analysis shall consider the familiarity of the officer or intelligence analyst with the State, locality, or region, as determined by such factors as whether the officer or intelligence analyst—

40(i) has been previously assigned in the geographic area; or

41(ii) has previously worked with intelligence officials or law enforcement or other emergency response providers from that State, locality, or region.

42The Under Secretary for Intelligence and Analysis—

43(A) shall ensure that each officer or intelligence analyst assigned to a fusion center under this section has the appropriate security clearance to contribute effectively to the mission of the fusion center; and

44(B) may request that security clearance processing be expedited for each such officer or intelligence analyst and may use available funds for such purpose.

45Each officer or intelligence analyst assigned to a fusion center under this section shall satisfy any other qualifications the Under Secretary for Intelligence and Analysis may prescribe.

46An officer or intelligence analyst assigned to a fusion center under this section shall—

47(1) assist law enforcement agencies and other emergency response providers of State, local, and tribal governments and fusion center personnel in using information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, to develop a comprehensive and accurate threat picture;

48(2) review homeland security-relevant information from law enforcement agencies and other emergency response providers of State, local, and tribal government;

49(3) create intelligence and other information products derived from such information and other homeland security-relevant information provided by the Department; and

50(4) assist in the dissemination of such products, as coordinated by the Under Secretary for Intelligence and Analysis, to law enforcement agencies and other emergency response providers of State, local, and tribal government, other fusion centers, and appropriate Federal agencies.

51The Secretary shall make it a priority to assign officers and intelligence analysts under this section from United States Customs and Border Protection, United States Immigration and Customs Enforcement, and the Coast Guard to participating State, local, and regional fusion centers located in jurisdictions along land or maritime borders of the United States in order to enhance the integrity of and security at such borders by helping Federal, State, local, and tribal law enforcement authorities to identify, investigate, and otherwise interdict persons, weapons, and related contraband that pose a threat to homeland security.

52When performing the responsibilities described in subsection (d), officers and intelligence analysts assigned to participating State, local, and regional fusion centers under this section shall have, as a primary responsibility, the creation of border intelligence products that—

53(A) assist State, local, and tribal law enforcement agencies in deploying their resources most efficiently to help detect and interdict terrorists, weapons of mass destruction, and related contraband at land or maritime borders of the United States;

54(B) promote more consistent and timely sharing of border security-relevant information among jurisdictions along land or maritime borders of the United States; and

55(C) enhance the Department's situational awareness of the threat of acts of terrorism at or involving the land or maritime borders of the United States.

56In order to fulfill the objectives described under subsection (d), each officer or intelligence analyst assigned to a fusion center under this section shall have appropriate access to all relevant Federal databases and information systems, consistent with any policies, guidelines, procedures, instructions, or standards established by the President or, as appropriate, the program manager of the information sharing environment for the implementation and management of that environment.

57The Secretary shall create a voluntary mechanism for any State, local, or tribal law enforcement officer or other emergency response provider who is a consumer of the intelligence or other information products referred to in subsection (d) to provide feedback to the Department on the quality and utility of such intelligence products.

58Not later than one year after August 3, 2007, and annually thereafter, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report that includes a description of the consumer feedback obtained under paragraph (1) and, if applicable, how the Department has adjusted its production of intelligence products in response to that consumer feedback.

59The authorities granted under this section shall supplement the authorities granted under section 121(d) of this title and nothing in this section shall be construed to abrogate the authorities granted under section 121(d) of this title.

60Nothing in this section shall be construed to require a State, local, or regional government or entity to accept the assignment of officers or intelligence analysts of the Department into the fusion center of that State, locality, or region.

61The Secretary, in consultation with the Attorney General, shall establish guidelines for fusion centers created and operated by State and local governments, to include standards that any such fusion center shall—

62(1) collaboratively develop a mission statement, identify expectations and goals, measure performance, and determine effectiveness for that fusion center;

63(2) create a representative governance structure that includes law enforcement officers and other emergency response providers and, as appropriate, the private sector;

64(3) create a collaborative environment for the sharing of intelligence and information among Federal, State, local, and tribal government agencies (including law enforcement officers and other emergency response providers), the private sector, and the public, consistent with any policies, guidelines, procedures, instructions, or standards established by the President or, as appropriate, the program manager of the information sharing environment;

65(4) leverage the databases, systems, and networks available from public and private sector entities, in accordance with all applicable laws, to maximize information sharing;

66(5) develop, publish, and adhere to a privacy and civil liberties policy consistent with Federal, State, and local law;

67(6) provide, in coordination with the Privacy Officer of the Department and the Officer for Civil Rights and Civil Liberties of the Department, appropriate privacy and civil liberties training for all State, local, tribal, and private sector representatives at the fusion center;

68(7) ensure appropriate security measures are in place for the facility, data, and personnel;

69(8) select and train personnel based on the needs, mission, goals, and functions of that fusion center;

70(9) offer a variety of intelligence and information services and products to recipients of fusion center intelligence and information; and

71(10) incorporate law enforcement officers, other emergency response providers, and, as appropriate, the private sector, into all relevant phases of the intelligence and fusion process, consistent with the mission statement developed under paragraph (1), either through full time representatives or liaison relationships with the fusion center to enable the receipt and sharing of information and intelligence.

72Not later than 1 year after March 2, 2020, and not less frequently than once every 5 years thereafter, the Secretary shall develop or update a strategy for Department engagement with fusion centers. Such strategy shall be developed and updated in consultation with the heads of intelligence components of the Department, the Chief Privacy Officer, the Officer for Civil Rights and Civil Liberties, officials of fusion centers, officers designated as Homeland Security Advisors, and the heads of other relevant agencies, as appropriate. Such strategy shall include the following:

73(1) Specific goals and objectives for sharing information and engaging with fusion centers—

74(A) through the direct deployment of personnel from intelligence components of the Department;

75(B) through the use of Department unclassified and classified information sharing systems, including the Homeland Security Information Network and the Homeland Secure Data Network, or any successor systems; and

76(C) through any additional means.

77(2) The performance metrics to be used to measure success in achieving the goals and objectives referred to in paragraph (1).

78(3) A 5-year plan for continued engagement with fusion centers.

79In this section—

80(1) the term "fusion center" means a collaborative effort of 2 or more Federal, State, local, or tribal government agencies that combines resources, expertise, or information with the goal of maximizing the ability of such agencies to detect, prevent, investigate, apprehend, and respond to criminal or terrorist activity;

81(2) the term "information sharing environment" means the information sharing environment established under section 485 of this title;

82(3) the term "intelligence analyst" means an individual who regularly advises, administers, supervises, or performs work in the collection, gathering, analysis, evaluation, reporting, production, or dissemination of information on political, economic, social, cultural, physical, geographical, scientific, or military conditions, trends, or forces in foreign or domestic areas that directly or indirectly affect national security;

83(4) the term "intelligence-led policing" means the collection and analysis of information to produce an intelligence end product designed to inform law enforcement decision making at the tactical and strategic levels; and

84(5) the term "terrorism information" has the meaning given that term in section 485 of this title.

85There is authorized to be appropriated $10,000,000 for each of fiscal years 2008 through 2012, to carry out this section, except for subsection (i), including for hiring officers and intelligence analysts to replace officers and intelligence analysts who are assigned to fusion centers under this section.

124h

–1. Threat information sharing

1The Secretary of Homeland Security shall prioritize the assignment of officers and intelligence analysts under section 124h of this title from the Transportation Security Administration and, as appropriate, from the Office of Intelligence and Analysis of the Department of Homeland Security, to locations with participating State, local, and regional fusion centers in jurisdictions with a high-risk surface transportation asset in order to enhance the security of such assets, including by improving timely sharing, in a manner consistent with the protection of privacy rights, civil rights, and civil liberties, of information regarding threats of terrorism and other threats, including targeted violence.

2Officers and intelligence analysts assigned to locations with participating State, local, and regional fusion centers under this section shall participate in the generation and dissemination of transportation security intelligence products, with an emphasis on such products that relate to threats of terrorism and other threats, including targeted violence, to surface transportation assets that—

3(1) assist State, local, and Tribal law enforcement agencies in deploying their resources, including personnel, most efficiently to help detect, prevent, investigate, apprehend, and respond to such threats;

4(2) promote more consistent and timely sharing with and among jurisdictions of threat information; and

5(3) enhance the Department of Homeland Security's situational awareness of such threats.

6The Secretary of Homeland Security shall make available to appropriate owners and operators of surface transportation assets, and to any other person that the Secretary determines appropriate to foster greater sharing of classified information relating to threats of terrorism and other threats, including targeted violence, to surface transportation assets, the process of application for security clearances under Executive Order No. 13549 (75 Fed. Reg. 162; 1 relating to a classified national security information program) or any successor Executive order.

7Not later than one year after December 27, 2021, the Secretary of Homeland Security shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report that includes a detailed description of the measures used to ensure privacy rights, civil rights, and civil liberties protections in carrying out this section.

8Not later than two years after December 27, 2021, the Comptroller General of the United States shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a review of the implementation of this section, including an assessment of the measures used to ensure privacy rights, civil rights, and civil liberties protections, and any recommendations to improve this implementation, together with any recommendations to improve information sharing with State, local, Tribal, territorial, and private sector entities to prevent, identify, and respond to threats of terrorism and other threats, including targeted violence, to surface transportation assets.

9In this section:

10(1) The term "surface transportation asset" includes facilities, equipment, or systems used to provide transportation services by—

11(A) a public transportation agency (as such term is defined in section 1131(5) of this title);

12(B) a railroad carrier (as such term is defined in section 20102(3) of title 49);

13(C) an owner or operator of—

14(i) an entity offering scheduled, fixed-route transportation services by over-the-road bus (as such term is defined in section 1151(4) of this title); or

15(ii) a bus terminal; or

16(D) other transportation facilities, equipment, or systems, as determined by the Secretary.

17(2) The term "targeted violence" means an incident of violence in which an attacker selected a particular target in order to inflict mass injury or death with no discernable political or ideological motivation beyond mass injury or death.

18(3) The term "terrorism" means the terms—

19(A) domestic terrorism (as such term is defined in section 2331(5) of title 18, United States Code); and

20(B) international terrorism (as such term is defined in section 2331(1) of title 18).

124i.

Homeland Security Information Sharing Fellows Program

1The Secretary, acting through the Under Secretary for Intelligence and Analysis, and in consultation with the Chief Human Capital Officer, shall establish a fellowship program in accordance with this section for the purpose of—

2(A) detailing State, local, and tribal law enforcement officers and intelligence analysts to the Department in accordance with subchapter VI of chapter 33 of title 5 to participate in the work of the Office of Intelligence and Analysis in order to become familiar with—

3(i) the relevant missions and capabilities of the Department and other Federal agencies; and

4(ii) the role, programs, products, and personnel of the Office of Intelligence and Analysis; and

5(B) promoting information sharing between the Department and State, local, and tribal law enforcement officers and intelligence analysts by assigning such officers and analysts to—

6(i) serve as a point of contact in the Department to assist in the representation of State, local, and tribal information requirements;

7(ii) identify information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, that is of interest to State, local, and tribal law enforcement officers, intelligence analysts, and other emergency response providers;

8(iii) assist Department analysts in preparing and disseminating products derived from information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, that are tailored to State, local, and tribal law enforcement officers and intelligence analysts and designed to prepare for and thwart acts of terrorism; and

9(iv) assist Department analysts in preparing products derived from information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, that are tailored to State, local, and tribal emergency response providers and assist in the dissemination of such products through appropriate Department channels.

10The program under this section shall be known as the "Homeland Security Information Sharing Fellows Program".

11In order to be eligible for selection as an Information Sharing Fellow under the program under this section, an individual shall—

12(A) have homeland security-related responsibilities;

13(B) be eligible for an appropriate security clearance;

14(C) possess a valid need for access to classified information, as determined by the Under Secretary for Intelligence and Analysis;

15(D) be an employee of an eligible entity; and

16(E) have undergone appropriate privacy and civil liberties training that is developed, supported, or sponsored by the Privacy Officer and the Officer for Civil Rights and Civil Liberties, in consultation with the Privacy and Civil Liberties Oversight Board established under section 2000ee of title 42.

17In this subsection, the term "eligible entity" means—

18(A) a State, local, or regional fusion center;

19(B) a State or local law enforcement or other government entity that serves a major metropolitan area, suburban area, or rural area, as determined by the Secretary;

20(C) a State or local law enforcement or other government entity with port, border, or agricultural responsibilities, as determined by the Secretary;

21(D) a tribal law enforcement or other authority; or

22(E) such other entity as the Secretary determines is appropriate.

23No State, local, or tribal law enforcement or other government entity shall be required to participate in the Homeland Security Information Sharing Fellows Program.

24The Under Secretary for Intelligence and Analysis shall establish procedures to provide for the nomination and selection of individuals to participate in the Homeland Security Information Sharing Fellows Program.

25The Under Secretary for Intelligence and Analysis shall—

26(A) select law enforcement officers and intelligence analysts representing a broad cross-section of State, local, and tribal agencies; and

27(B) ensure that the number of Information Sharing Fellows selected does not impede the activities of the Office of Intelligence and Analysis.

124j.

Rural Policing Institute

1The Secretary shall establish a Rural Policing Institute, which shall be administered by the Federal Law Enforcement Training Center, to target training to law enforcement agencies and other emergency response providers located in rural areas. The Secretary, through the Rural Policing Institute, shall—

2(1) evaluate the needs of law enforcement agencies and other emergency response providers in rural areas;

3(2) develop expert training programs designed to address the needs of law enforcement agencies and other emergency response providers in rural areas as identified in the evaluation conducted under paragraph (1), including training programs about intelligence-led policing and protections for privacy, civil rights, and civil liberties;

4(3) provide the training programs developed under paragraph (2) to law enforcement agencies and other emergency response providers in rural areas; and

5(4) conduct outreach efforts to ensure that local and tribal governments in rural areas are aware of the training programs developed under paragraph (2) so they can avail themselves of such programs.

6The training at the Rural Policing Institute established under subsection (a) shall—

7(1) be configured in a manner so as not to duplicate or displace any law enforcement or emergency response program of the Federal Law Enforcement Training Center or a local or tribal government entity in existence on August 3, 2007; and

8(2) to the maximum extent practicable, be delivered in a cost-effective manner at facilities of the Department, on closed military installations with adequate training facilities, or at facilities operated by the participants.

9In this section, the term "rural" means an area that is not located in a metropolitan statistical area, as defined by the Office of Management and Budget.

10There are authorized to be appropriated to carry out this section (including for contracts, staff, and equipment)—

11(1) $10,000,000 for fiscal year 2008; and

12(2) $5,000,000 for each of fiscal years 2009 through 2013.

124k.

Interagency Threat Assessment and Coordination Group

1To improve the sharing of information within the scope of the information sharing environment established under section 485 of this title with State, local, tribal, and private sector officials, the Director of National Intelligence, through the program manager for the information sharing environment, in coordination with the Secretary, shall coordinate and oversee the creation of an Interagency Threat Assessment and Coordination Group (referred to in this section as the "ITACG").

2The ITACG shall consist of—

3(1) an ITACG Advisory Council to set policy and develop processes for the integration, analysis, and dissemination of federally-coordinated information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information; and

4(2) an ITACG Detail comprised of State, local, and tribal homeland security and law enforcement officers and intelligence analysts detailed to work in the National Counterterrorism Center with Federal intelligence analysts for the purpose of integrating, analyzing, and assisting in the dissemination of federally-coordinated information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, through appropriate channels identified by the ITACG Advisory Council.

5The Secretary, or the Secretary's designee, in coordination with the Director of the National Counterterrorism Center and the ITACG Advisory Council, shall—

6(1) create policies and standards for the creation of information products derived from information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, that are suitable for dissemination to State, local, and tribal governments and the private sector;

7(2) evaluate and develop processes for the timely dissemination of federally-coordinated information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, to State, local, and tribal governments and the private sector;

8(3) establish criteria and a methodology for indicating to State, local, and tribal governments and the private sector the reliability of information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, disseminated to them;

9(4) educate the intelligence community about the requirements of the State, local, and tribal homeland security, law enforcement, and other emergency response providers regarding information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information;

10(5) establish and maintain the ITACG Detail, which shall assign an appropriate number of State, local, and tribal homeland security and law enforcement officers and intelligence analysts to work in the National Counterterrorism Center who shall—

11(A) educate and advise National Counterterrorism Center intelligence analysts about the requirements of the State, local, and tribal homeland security and law enforcement officers, and other emergency response providers regarding information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information;

12(B) assist National Counterterrorism Center intelligence analysts in integrating, analyzing, and otherwise preparing versions of products derived from information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information that are unclassified or classified at the lowest possible level and suitable for dissemination to State, local, and tribal homeland security and law enforcement agencies in order to help deter and prevent terrorist attacks;

13(C) implement, in coordination with National Counterterrorism Center intelligence analysts, the policies, processes, procedures, standards, and guidelines developed by the ITACG Advisory Council;

14(D) assist in the dissemination of products derived from information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, to State, local, and tribal jurisdictions only through appropriate channels identified by the ITACG Advisory Council;

15(E) make recommendations, as appropriate, to the Secretary or the Secretary's designee, for the further dissemination of intelligence products that could likely inform or improve the security of a State, local, or tribal government, (including a State, local, or tribal law enforcement agency) or a private sector entity; and

16(F) report directly to the senior intelligence official from the Department under paragraph (6);

17(6) detail a senior intelligence official from the Department of Homeland Security to the National Counterterrorism Center, who shall—

18(A) manage the day-to-day operations of the ITACG Detail;

19(B) report directly to the Director of the National Counterterrorism Center or the Director's designee; and

20(C) in coordination with the Director of the Federal Bureau of Investigation, and subject to the approval of the Director of the National Counterterrorism Center, select a deputy from the pool of available detailees from the Federal Bureau of Investigation in the National Counterterrorism Center;

21(7) establish, within the ITACG Advisory Council, a mechanism to select law enforcement officers and intelligence analysts for placement in the National Counterterrorism Center consistent with paragraph (5), using criteria developed by the ITACG Advisory Council that shall encourage participation from a broadly representative group of State, local, and tribal homeland security and law enforcement agencies; and

22(8) compile an annual assessment of the ITACG Detail's performance, including summaries of customer feedback, in preparing, disseminating, and requesting the dissemination of intelligence products intended for State, local and tribal government (including State, local, and tribal law enforcement agencies) and private sector entities.

23The Secretary, or the Secretary's designee, shall serve as the chair of the ITACG Advisory Council, which shall include—

24(1) representatives of—

25(A) the Department;

26(B) the Federal Bureau of Investigation;

27(C) the National Counterterrorism Center;

28(D) the Department of Defense;

29(E) the Department of Energy;

30(F) the Department of State; and

31(G) other Federal entities as appropriate;

32(2) the program manager of the information sharing environment, designated under section 485(f) of this title, or the program manager's designee; and

33(3) executive level law enforcement and intelligence officials from State, local, and tribal governments.

34The Secretary, in consultation with the Director of National Intelligence, the Attorney General, and the program manager of the information sharing environment established under section 485 of this title, shall—

35(1) establish procedures for selecting members of the ITACG Advisory Council and for the proper handling and safeguarding of products derived from information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, by those members; and

36(2) ensure that at least 50 percent of the members of the ITACG Advisory Council are from State, local, and tribal governments.

37Beginning not later than 90 days after August 3, 2007, the ITACG Advisory Council shall meet regularly, but not less than quarterly, at the facilities of the National Counterterrorism Center of the Office of the Director of National Intelligence.

38Pursuant to section 3056(f)(E) 1 of title 50, the Director of the National Counterterrorism Center, acting through the senior intelligence official from the Department of Homeland Security detailed pursuant to subsection (d)(6),2 shall ensure that—

39(A) the products derived from information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, prepared by the National Counterterrorism Center and the ITACG Detail for distribution to State, local, and tribal homeland security and law enforcement agencies reflect the requirements of such agencies and are produced consistently with the policies, processes, procedures, standards, and guidelines established by the ITACG Advisory Council;

40(B) in consultation with the ITACG Advisory Council and consistent with sections 3024(f)(1)(B)(iii) and 3056(f)(E) 1 of title 50, all products described in subparagraph (A) are disseminated through existing channels of the Department and the Department of Justice and other appropriate channels to State, local, and tribal government officials and other entities;

41(C) all detailees under subsection (d)(5) 2 have appropriate access to all relevant information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, available at the National Counterterrorism Center in order to accomplish the objectives under that paragraph;

42(D) all detailees under subsection (d)(5) 2 have the appropriate security clearances and are trained in the procedures for handling, processing, storing, and disseminating classified products derived from information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information; and

43(E) all detailees under subsection (d)(5) 2 complete appropriate privacy and civil liberties training.

44Chapter 10 of title 5 shall not apply to the ITACG or any subsidiary groups thereof.

45There are authorized to be appropriated such sums as may be necessary for each of fiscal years 2008 through 2012 to carry out this section, including to obtain security clearances for the State, local, and tribal participants in the ITACG.

124l.

Transferred

124m.

Classified Information Advisory Officer

1The Secretary shall identify and designate within the Department a Classified Information Advisory Officer, as described in this section.

2The responsibilities of the Classified Information Advisory Officer shall be as follows:

3(1) To develop and disseminate educational materials and to develop and administer training programs to assist State, local, and tribal governments (including State, local, and tribal law enforcement agencies) and private sector entities—

4(A) in developing plans and policies to respond to requests related to classified information without communicating such information to individuals who lack appropriate security clearances;

5(B) regarding the appropriate procedures for challenging classification designations of information received by personnel of such entities; and

6(C) on the means by which such personnel may apply for security clearances.

7(2) To inform the Under Secretary for Intelligence and Analysis on policies and procedures that could facilitate the sharing of classified information with such personnel, as appropriate.

8Not later than 90 days after October 7, 2010, the Secretary shall—

9(1) designate the initial Classified Information Advisory Officer; and

10(2) submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a written notification of the designation.

124m

–1. Departmental coordination on counter threats

1There is authorized in the Department, for a period of 2 years beginning after December 27, 2020, a Counter Threats Advisory Board (in this section referred to as the "Board") which shall—

2(1) be composed of senior representatives of departmental operational components and headquarters elements; and

3(2) coordinate departmental intelligence activities and policy and information related to the mission and functions of the Department that counter threats.

4There shall be a charter to govern the structure and mission of the Board, which shall—

5(1) direct the Board to focus on the current threat environment and the importance of aligning departmental activities to counter threats under the guidance of the Secretary; and

6(2) be reviewed and updated as appropriate.

7The Board shall be composed of senior representatives of departmental operational components and headquarters elements.

8The Under Secretary for Intelligence and Analysis shall serve as the Chair of the Board.

9The Secretary shall appoint additional members of the Board from among the following:

10(A) The Transportation Security Administration.

11(B) U.S. Customs and Border Protection.

12(C) U.S. Immigration and Customs Enforcement.

13(D) The Federal Emergency Management Agency.

14(E) The Coast Guard.

15(F) U.S. Citizenship and Immigration Services.

16(G) The United States Secret Service.

17(H) The Cybersecurity and Infrastructure Security Agency.

18(I) The Office of Operations Coordination.

19(J) The Office of the General Counsel.

20(K) The Office of Intelligence and Analysis.

21(L) The Office of Strategy, Policy, and Plans.

22(M) The Science and Technology Directorate.

23(N) The Office for State and Local Law Enforcement.

24(O) The Privacy Office.

25(P) The Office for Civil Rights and Civil Liberties.

26(Q) Other departmental offices and programs as determined appropriate by the Secretary.

27The Board shall—

28(1) meet on a regular basis to discuss intelligence and coordinate ongoing threat mitigation efforts and departmental activities, including coordination with other Federal, State, local, tribal, territorial, and private sector partners; and

29(2) make recommendations to the Secretary.

30The Board shall advise the Secretary on the issuance of terrorism alerts under section 124 of this title.

31No additional funds are authorized to carry out this section.

124n.

Protection of certain facilities and assets from unmanned aircraft

1Notwithstanding section 46502 of title 49 or sections 32, 1030, 1367 and chapters 119 and 206 of title 18, the Secretary and the Attorney General may, for their respective Departments, take, and may authorize personnel with assigned duties that include the security or protection of people, facilities, or assets, to take such actions as are described in subsection (b)(1) that are necessary to mitigate a credible threat (as defined by the Secretary or the Attorney General, in consultation with the Secretary of Transportation) that an unmanned aircraft system or unmanned aircraft poses to the safety or security of a covered facility or asset.

2The actions authorized in subsection (a) are the following:

3(A) During the operation of the unmanned aircraft system, detect, identify, monitor, and track the unmanned aircraft system or unmanned aircraft, without prior consent, including by means of intercept or other access of a wire communication, an oral communication, or an electronic communication used to control the unmanned aircraft system or unmanned aircraft.

4(B) Warn the operator of the unmanned aircraft system or unmanned aircraft, including by passive or active, and direct or indirect physical, electronic, radio, and electromagnetic means.

5(C) Disrupt control of the unmanned aircraft system or unmanned aircraft, without prior consent, including by disabling the unmanned aircraft system or unmanned aircraft by intercepting, interfering, or causing interference with wire, oral, electronic, or radio communications used to control the unmanned aircraft system or unmanned aircraft.

6(D) Seize or exercise control of the unmanned aircraft system or unmanned aircraft.

7(E) Seize or otherwise confiscate the unmanned aircraft system or unmanned aircraft.

8(F) Use reasonable force, if necessary, to disable, damage, or destroy the unmanned aircraft system or unmanned aircraft.

9The Secretary and the Attorney General shall develop for their respective Departments the actions described in paragraph (1) in coordination with the Secretary of Transportation.

10The Secretary and the Attorney General shall conduct research, testing, training on, and evaluation of any equipment, including any electronic equipment, to determine its capability and utility prior to the use of any such technology for any action described in subsection (b)(1).

11The Secretary and the Attorney General shall coordinate with the Administrator of the Federal Aviation Administration when any action authorized by this section might affect aviation safety, civilian aviation and aerospace operations, aircraft airworthiness, or the use of the airspace.

12Any unmanned aircraft system or unmanned aircraft described in subsection (a) that is seized by the Secretary or the Attorney General is subject to forfeiture to the United States.

13The Secretary, the Attorney General, and the Secretary of Transportation may prescribe regulations and shall issue guidance in the respective areas of each Secretary or the Attorney General to carry out this section.

14The Secretary and the Attorney General shall coordinate the development of their respective guidance under paragraph (1) with the Secretary of Transportation.

15The Secretary and the Attorney General shall respectively coordinate with the Secretary of Transportation and the Administrator of the Federal Aviation Administration before issuing any guidance, or otherwise implementing this section, if such guidance or implementation might affect aviation safety, civilian aviation and aerospace operations, aircraft airworthiness, or the use of airspace.

16The regulations or guidance issued to carry out actions authorized under subsection (b) by each Secretary or the Attorney General, as the case may be, shall ensure that—

17(1) the interception or acquisition of, or access to, or maintenance or use of, communications to or from an unmanned aircraft system under this section is conducted in a manner consistent with the First and Fourth Amendments to the Constitution of the United States and applicable provisions of Federal law;

18(2) communications to or from an unmanned aircraft system are intercepted or acquired only to the extent necessary to support an action described in subsection (b)(1);

19(3) records of such communications are maintained only for as long as necessary, and in no event for more than 180 days, unless the Secretary of Homeland Security or the Attorney General determine 1 that maintenance of such records is necessary to investigate or prosecute a violation of law, directly support an ongoing security operation, is required under Federal law, or for the purpose of any litigation;

20(4) such communications are not disclosed outside the Department of Homeland Security or the Department of Justice unless the disclosure—

21(A) is necessary to investigate or prosecute a violation of law;

22(B) would support the Department of Defense, a Federal law enforcement agency, or the enforcement activities of a regulatory agency of the Federal Government in connection with a criminal or civil investigation of, or any regulatory, statutory, or other enforcement action relating to an action described in subsection (b)(1);

23(C) is between the Department of Homeland Security and the Department of Justice in the course of a security or protection operation of either agency or a joint operation of such agencies; or

24(D) is otherwise required by law; and

25(5) to the extent necessary, the Department of Homeland Security and the Department of Justice are authorized to share threat information, which shall not include communications referred to in subsection (b), with State, local, territorial, or tribal law enforcement agencies in the course of a security or protection operation.

26The Secretary and the Attorney General shall submit to Congress, as a part of the homeland security or justice budget materials for each fiscal year after fiscal year 2019, a consolidated funding display that identifies the funding source for the actions described in subsection (b)(1) within the Department of Homeland Security or the Department of Justice. The funding display shall be in unclassified form, but may contain a classified annex.

27On a semiannual basis during the period beginning 6 months after October 5, 2018, and ending on the date specified in subsection (i), the Secretary and the Attorney General shall, respectively, provide a briefing to the appropriate congressional committees on the activities carried out pursuant to this section.

28Each briefing required under paragraph (1) shall be conducted jointly with the Secretary of Transportation.

29Each briefing required under paragraph (1) shall include—

30(A) policies, programs, and procedures to mitigate or eliminate impacts of such activities to the National Airspace System;

31(B) a description of instances in which actions described in subsection (b)(1) have been taken, including all such instances that may have resulted in harm, damage, or loss to a person or to private property;

32(C) a description of the guidance, policies, or procedures established to address privacy, civil rights, and civil liberties issues implicated by the actions allowed under this section, as well as any changes or subsequent efforts that would significantly affect privacy, civil rights or civil liberties;

33(D) a description of options considered and steps taken to mitigate any identified impacts to the national airspace system related to the use of any system or technology, including the minimization of the use of any technology that disrupts the transmission of radio or electronic signals, for carrying out the actions described in subsection (b)(1);

34(E) a description of instances in which communications intercepted or acquired during the course of operations of an unmanned aircraft system were held for more than 180 days or shared outside of the Department of Justice or the Department of Homeland Security;

35(F) how the Secretary, the Attorney General, and the Secretary of Transportation have informed the public as to the possible use of authorities under this section; 2

36(G) how the Secretary, the Attorney General, and the Secretary of Transportation have engaged with Federal, State, and local law enforcement agencies to implement and use such authorities.

37Each briefing required under paragraph (1) shall be in unclassified form, but may be accompanied by an additional classified briefing.

38Within 30 days of deploying any new technology to carry out the actions described in subsection (b)(1), the Secretary and the Attorney General shall, respectively, submit a notification to the appropriate congressional committees. Such notification shall include a description of options considered to mitigate any identified impacts to the national airspace system related to the use of any system or technology, including the minimization of the use of any technology that disrupts the transmission of radio or electronic signals, for carrying out the actions described in subsection (b)(1).

39Nothing in this section may be construed to—

40(1) vest in the Secretary or the Attorney General any authority of the Secretary of Transportation or the Administrator of the Federal Aviation Administration;

41(2) vest in the Secretary of Transportation or the Administrator of the Federal Aviation Administration any authority of the Secretary or the Attorney General;

42(3) vest in the Secretary of Homeland Security any authority of the Attorney General;

43(4) vest in the Attorney General any authority of the Secretary of Homeland Security; or

44(5) provide a new basis of liability for any State, local, territorial, or tribal law enforcement officers who participate in the protection of a mass gathering identified by the Secretary or Attorney General under subsection (k)(3)(C)(iii)(II), act within the scope of their authority, and do not exercise the authority granted to the Secretary and Attorney General by this section.

45The authority to carry out this section with respect to a covered facility or asset specified in subsection (k)(3) shall terminate on March 14, 2025.

46Nothing in this section shall be construed to provide the Secretary or the Attorney General with additional authorities beyond those described in subsections (a) and (k)(3)(C)(iii).

47In this section:

48(1) The term "appropriate congressional committees" means—

49(A) the Committee on Homeland Security and Governmental Affairs, the Committee on Commerce, Science, and Transportation, and the Committee on the Judiciary of the Senate; and

50(B) the Committee on Homeland Security, the Committee on Transportation and Infrastructure, the Committee on Energy and Commerce, and the Committee on the Judiciary of the House of Representatives.

51(2) The term "budget", with respect to a fiscal year, means the budget for that fiscal year that is submitted to Congress by the President under section 1105(a) of title 31.

52(3) The term "covered facility or asset" means any facility or asset that—

53(A) is identified as high-risk and a potential target for unlawful unmanned aircraft activity by the Secretary or the Attorney General, in coordination with the Secretary of Transportation with respect to potentially impacted airspace, through a risk-based assessment for purposes of this section (except that in the case of the missions described in subparagraph (C)(i)(II) and (C)(iii)(I), such missions shall be presumed to be for the protection of a facility or asset that is assessed to be high-risk and a potential target for unlawful unmanned aircraft activity);

54(B) is located in the United States (including the territories and possessions, territorial seas or navigable waters of the United States); and

55(C) directly relates to one or more—

56(i) missions authorized to be performed by the Department of Homeland Security, consistent with governing statutes, regulations, and orders issued by the Secretary, pertaining to—

57(I) security or protection functions of the U.S. Customs and Border Protection, including securing or protecting facilities, aircraft, and vessels, whether moored or underway;

58(II) United States Secret Service protection operations pursuant to sections 3056(a) and 3056A(a) of title 18 and the Presidential Protection Assistance Act of 1976 (18 U.S.C. 3056 note); or

59(III) protection of facilities pursuant to section 1315(a) of title 40;

60(ii) missions authorized to be performed by the Department of Justice, consistent with governing statutes, regulations, and orders issued by the Attorney General, pertaining to—

61(I) personal protection operations by—

62(aa) the Federal Bureau of Investigation as specified in section 533 of title 28; and

63(bb) the United States Marshals Service of Federal jurists, court officers, witnesses, and other threatened persons in the interests of justice, as specified in section 566(e)(1)(A) of title 28;

64(II) protection of penal, detention, and correctional facilities and operations conducted by the Federal Bureau of Prisons; or

65(III) protection of the buildings and grounds leased, owned, or operated by or for the Department of Justice, and the provision of security for Federal courts, as specified in section 566(a) of title 28;

66(iii) missions authorized to be performed by the Department of Homeland Security or the Department of Justice, acting together or separately, consistent with governing statutes, regulations, and orders issued by the Secretary or the Attorney General, respectively, pertaining to—

67(I) protection of a National Special Security Event and Special Event Assessment Rating event;

68(II) the provision of support to State, local, territorial, or tribal law enforcement, upon request of the chief executive officer of the State or territory, to ensure protection of people and property at mass gatherings, that is limited to a specified timeframe and location, within available resources, and without delegating any authority under this section to State, local, territorial, or tribal law enforcement; or

69(III) protection of an active Federal law enforcement investigation, emergency response, or security function, that is limited to a specified timeframe and location; and 3

70(iv) missions authorized to be performed by the United States Coast Guard, including those described in clause (iii) as directed by the Secretary, and as further set forth in section 104 4 of title 14, and consistent with governing statutes, regulations, and orders issued by the Secretary of the Department in which the Coast Guard is operating.

71(4) The terms "electronic communication", "intercept", "oral communication", and "wire communication" have the meaning 5 given those terms in section 2510 of title 18.

72(5) The term "homeland security or justice budget materials", with respect to a fiscal year, means the materials submitted to Congress by the Secretary and the Attorney General in support of the budget for that fiscal year.

73(6) For purposes of subsection (a), the term "personnel" means officers and employees of the Department of Homeland Security or the Department of Justice.

74(7) The terms "unmanned aircraft" and "unmanned aircraft system" have the meanings given those terms in section 44801, 6 of title 49.

75(8) For purposes of this section, the term "risk-based assessment" includes an evaluation of threat information specific to a covered facility or asset and, with respect to potential impacts on the safety and efficiency of the national airspace system and the needs of law enforcement and national security at each covered facility or asset identified by the Secretary or the Attorney General, respectively, of each of the following factors:

76(A) Potential impacts to safety, efficiency, and use of the national airspace system, including potential effects on manned aircraft and unmanned aircraft systems, aviation safety, airport operations, infrastructure, and air navigation services related to the use of any system or technology for carrying out the actions described in subsection (b)(1).

77(B) Options for mitigating any identified impacts to the national airspace system related to the use of any system or technology, including minimizing when possible the use of any technology which disrupts the transmission of radio or electronic signals, for carrying out the actions described in subsection (b)(1).

78(C) Potential consequences of the impacts of any actions taken under subsection (b)(1) to the national airspace system and infrastructure if not mitigated.

79(D) The ability to provide reasonable advance notice to aircraft operators consistent with the safety of the national airspace system and the needs of law enforcement and national security.

80(E) The setting and character of any covered facility or asset, including whether it is located in a populated area or near other structures, whether the facility is open to the public, whether the facility is also used for nongovernmental functions, and any potential for interference with wireless communications or for injury or damage to persons or property.

81(F) The setting, character, timeframe, and national airspace system impacts of National Special Security Event and Special Event Assessment Rating events.

82(G) Potential consequences to national security, public safety, or law enforcement if threats posed by unmanned aircraft systems are not mitigated or defeated.

83Not later than 1 year after October 5, 2018, the Secretary shall conduct, in coordination with the Attorney General and the Secretary of Transportation, an assessment to the appropriate congressional committees, including—

84(A) an evaluation of the threat from unmanned aircraft systems to United States critical infrastructure (as defined in this chapter) and to domestic large hub airports (as defined in section 40102 of title 49);

85(B) an evaluation of current Federal and 7 State, local, territorial, or tribal law enforcement authorities to counter the threat identified in subparagraph (A), and recommendations, if any, for potential changes to existing authorities to allow State, local, territorial, and tribal law enforcement to assist Federal law enforcement to counter the threat where appropriate;

86(C) an evaluation of the knowledge of, efficiency of, and effectiveness of current procedures and resources available to owners of critical infrastructure and domestic large hub airports when they believe a threat from unmanned aircraft systems is present and what additional actions, if any, the Department of Homeland Security or the Department of Transportation could implement under existing authorities to assist these entities to counter the threat identified in subparagraph (A);

87(D) an assessment of what, if any, additional authorities are needed by each Department and law enforcement to counter the threat identified in subparagraph (A); and

88(E) an assessment of what, if any, additional research and development the Department needs to counter the threat identified in subparagraph (A).

89The report required under paragraph (1) shall be submitted in unclassified form, but may contain a classified annex.

125.

Annual report on intelligence activities of the Department of Homeland Security

1For each fiscal year and along with the budget materials submitted in support of the budget of the Department of Homeland Security pursuant to section 1105(a) of title 31, the Under Secretary for Intelligence and Analysis of the Department shall submit to the congressional intelligence committees a report for such fiscal year on each intelligence activity of each intelligence component of the Department, as designated by the Under Secretary, that includes the following:

2(1) The amount of funding requested for each such intelligence activity.

3(2) The number of full-time employees funded to perform each such intelligence activity.

4(3) The number of full-time contractor employees (or the equivalent of full-time in the case of part-time contractor employees) funded to perform or in support of each such intelligence activity.

5(4) A determination as to whether each such intelligence activity is predominantly in support of national intelligence or departmental missions.

6(5) The total number of analysts of the Intelligence Enterprise of the Department that perform—

7(A) strategic analysis; or

8(B) operational analysis.

9Not later than 120 days after December 19, 2014, the Secretary of Homeland Security, acting through the Under Secretary for Intelligence and Analysis, shall submit to the congressional intelligence committees a report that—

10(1) examines the feasibility and advisability of including the budget request for all intelligence activities of each intelligence component of the Department that predominantly support departmental missions, as designated by the Under Secretary for Intelligence and Analysis, in the Homeland Security Intelligence Program; and

11(2) includes a plan to enhance the coordination of department-wide intelligence activities to achieve greater efficiencies in the performance of the Department of Homeland Security intelligence functions.

12In this section, the term "intelligence component of the Department" has the meaning given that term in section 101 of this title.

126.

Department of Homeland Security data framework

1The Secretary of Homeland Security shall develop a data framework to integrate existing Department of Homeland Security datasets and systems, as appropriate, for access by authorized personnel in a manner consistent with relevant legal authorities and privacy, civil rights, and civil liberties policies and protections.

2In developing the framework required under paragraph (1), the Secretary of Homeland Security shall ensure, in accordance with all applicable statutory and regulatory requirements, the following information is included:

3(A) All information acquired, held, or obtained by an office or component of the Department of Homeland Security that falls within the scope of the information sharing environment, including homeland security information, terrorism information, weapons of mass destruction information, and national intelligence.

4(B) Any information or intelligence relevant to priority mission needs and capability requirements of the homeland security enterprise, as determined appropriate by the Secretary.

5The Secretary of Homeland Security shall ensure that the data framework required under this section is accessible to employees of the Department of Homeland Security who the Secretary determines—

6(A) have an appropriate security clearance;

7(B) are assigned to perform a function that requires access to information in such framework; and

8(C) are trained in applicable standards for safeguarding and using such information.

9The Secretary of Homeland Security shall—

10(A) issue guidance for Department of Homeland Security employees authorized to access and contribute to the data framework pursuant to paragraph (1); and

11(B) ensure that such guidance enforces a duty to share between offices and components of the Department when accessing or contributing to such framework for mission needs.

12The Secretary of Homeland Security shall promulgate data standards and instruct components of the Department of Homeland Security to make available information through the data framework required under this section in a machine-readable standard format, to the greatest extent practicable.

13The Secretary of Homeland Security may exclude information from the data framework required under this section if the Secretary determines inclusion of such information may—

14(1) jeopardize the protection of sources, methods, or activities;

15(2) compromise a criminal or national security investigation;

16(3) be inconsistent with other Federal laws or regulations; or

17(4) be duplicative or not serve an operational purpose if included in such framework.

18The Secretary of Homeland Security shall incorporate into the data framework required under this section systems capabilities for auditing and ensuring the security of information included in such framework. Such capabilities shall include the following:

19(1) Mechanisms for identifying insider threats.

20(2) Mechanisms for identifying security risks.

21(3) Safeguards for privacy, civil rights, and civil liberties.

22Not later than 2 years after December 19, 2018, the Secretary of Homeland Security shall ensure the data framework required under this section has the ability to include appropriate information in existence within the Department of Homeland Security to meet the critical mission operations of the Department of Homeland Security.

23The Secretary of Homeland Security shall submit to the appropriate congressional committees regular updates on the status of the data framework until the framework is fully operational.

24Not later than 60 days after the date on which the data framework required under this section is fully operational, the Secretary of Homeland Security shall provide notice to the appropriate congressional committees that the data framework is fully operational.

25The Secretary of Homeland Security shall annually brief Congress on component use of the data framework required under this section to support operations that disrupt terrorist activities and incidents in the homeland.

26In this section:

27The terms "appropriate congressional committee" and "homeland" have the meaning given those terms in section 101 of this title.

28The term "homeland security information" has the meaning given such term in section 482 of this title.

29The term "national intelligence" has the meaning given such term in section 3003(5) of title 50.

30The term "terrorism information" has the meaning given such term in section 485 of this title.

131

to 134. Transferred

141.

Procedures for sharing information

1The Secretary shall establish procedures on the use of information shared under this subchapter that—

2(1) limit the redissemination of such information to ensure that it is not used for an unauthorized purpose;

3(2) ensure the security and confidentiality of such information;

4(3) protect the constitutional and statutory rights of any individuals who are subjects of such information; and

5(4) provide data integrity through the timely removal and destruction of obsolete or erroneous names and information.

142.

Privacy officer

1The Secretary shall appoint a senior official in the Department, who shall report directly to the Secretary, to assume primary responsibility for privacy policy, including—

2(1) assuring that the use of technologies sustain, and do not erode, privacy protections relating to the use, collection, and disclosure of personal information;

3(2) assuring that personal information contained in Privacy Act systems of records is handled in full compliance with fair information practices as set out in the Privacy Act of 1974 [5 U.S.C. 552a];

4(3) evaluating legislative and regulatory proposals involving collection, use, and disclosure of personal information by the Federal Government;

5(4) conducting a privacy impact assessment of proposed rules of the Department or that of the Department on the privacy of personal information, including the type of personal information collected and the number of people affected;

6(5) coordinating with the Officer for Civil Rights and Civil Liberties to ensure that—

7(A) programs, policies, and procedures involving civil rights, civil liberties, and privacy considerations are addressed in an integrated and comprehensive manner; and

8(B) Congress receives appropriate reports on such programs, policies, and procedures; and

9(6) preparing a report to Congress on an annual basis on activities of the Department that affect privacy, including complaints of privacy violations, implementation of the Privacy Act of 1974 [5 U.S.C. 552a], internal controls, and other matters.

10The senior official appointed under subsection (a) may—

11(A) have access to all records, reports, audits, reviews, documents, papers, recommendations, and other materials available to the Department that relate to programs and operations with respect to the responsibilities of the senior official under this section;

12(B) make such investigations and reports relating to the administration of the programs and operations of the Department as are, in the senior official's judgment, necessary or desirable;

13(C) subject to the approval of the Secretary, require by subpoena the production, by any person other than a Federal agency, of all information, documents, reports, answers, records, accounts, papers, and other data and documentary evidence necessary to performance of the responsibilities of the senior official under this section; and

14(D) administer to or take from any person an oath, affirmation, or affidavit, whenever necessary to performance of the responsibilities of the senior official under this section.

15Any subpoena issued under paragraph (1)(C) shall, in the case of contumacy or refusal to obey, be enforceable by order of any appropriate United States district court.

16Any oath, affirmation, or affidavit administered or taken under paragraph (1)(D) by or before an employee of the Privacy Office designated for that purpose by the senior official appointed under subsection (a) shall have the same force and effect as if administered or taken by or before an officer having a seal of office.

17The senior official appointed under subsection (a) shall—

18(A) report to, and be under the general supervision of, the Secretary; and

19(B) coordinate activities with the Inspector General of the Department in order to avoid duplication of effort.

20Except as provided in subparagraph (B), the senior official appointed under subsection (a) may investigate any matter relating to possible violations or abuse concerning the administration of any program or operation of the Department relevant to the purposes under this section.

21Before initiating any investigation described under subparagraph (A), the senior official shall refer the matter and all related complaints, allegations, and information to the Inspector General of the Department.

22Not later than 30 days after the receipt of a matter referred under clause (i), the Inspector General shall—

23(aa) make a determination regarding whether the Inspector General intends to initiate an audit or investigation of the matter referred under clause (i); and

24(bb) notify the senior official of that determination.

25If the Inspector General notifies the senior official under subclause (I)(bb) that the Inspector General intended to initiate an audit or investigation, but does not initiate that audit or investigation within 90 days after providing that notification, the Inspector General shall further notify the senior official that an audit or investigation was not initiated. The further notification under this subclause shall be made not later than 3 days after the end of that 90-day period.

26The senior official may investigate a matter referred under clause (i) if—

27(I) the Inspector General notifies the senior official under clause (ii)(I)(bb) that the Inspector General does not intend to initiate an audit or investigation relating to that matter; or

28(II) the Inspector General provides a further notification under clause (ii)(II) relating to that matter.

29Any employee of the Office of Inspector General who audits or investigates any matter referred under clause (i) shall be required to receive adequate training on privacy laws, rules, and regulations, to be provided by an entity approved by the Inspector General in consultation with the senior official appointed under subsection (a).

30If the Secretary removes the senior official appointed under subsection (a) or transfers that senior official to another position or location within the Department, the Secretary shall—

31(1) promptly submit a written notification of the removal or transfer to Houses of Congress; and

32(2) include in any such notification the reasons for the removal or transfer.

33The senior official appointed under subsection (a) shall—

34(1) submit reports directly to the Congress regarding performance of the responsibilities of the senior official under this section, without any prior comment or amendment by the Secretary, Deputy Secretary, or any other officer or employee of the Department or the Office of Management and Budget; and

35(2) inform the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives not later than—

36(A) 30 days after the Secretary disapproves the senior official's request for a subpoena under subsection (b)(1)(C) or the Secretary substantively modifies the requested subpoena; or

37(B) 45 days after the senior official's request for a subpoena under subsection (b)(1)(C), if that subpoena has not either been approved or disapproved by the Secretary.

143

to 145. Transferred

146.

Cybersecurity workforce assessment and strategy

1Not later than 180 days after December 18, 2014, and annually thereafter for 3 years, the Secretary shall assess the cybersecurity workforce of the Department.

2The assessment required under paragraph (1) shall include, at a minimum—

3(A) an assessment of the readiness and capacity of the workforce of the Department to meet its cybersecurity mission;

4(B) information on where cybersecurity workforce positions are located within the Department;

5(C) information on which cybersecurity workforce positions are—

6(i) performed by—

7(I) permanent full-time equivalent employees of the Department, including, to the greatest extent practicable, demographic information about such employees;

8(II) independent contractors; and

9(III) individuals employed by other Federal agencies, including the National Security Agency; or

10(ii) vacant; and

11(D) information on—

12(i) the percentage of individuals within each Cybersecurity Category and Specialty Area who received essential training to perform their jobs; and

13(ii) in cases in which such essential training was not received, what challenges, if any, were encountered with respect to the provision of such essential training.

14The Secretary shall—

15(A) not later than 1 year after December 18, 2014, develop a comprehensive workforce strategy to enhance the readiness, capacity, training, recruitment, and retention of the cybersecurity workforce of the Department; and

16(B) maintain and, as necessary, update the comprehensive workforce strategy developed under subparagraph (A).

17The comprehensive workforce strategy developed under paragraph (1) shall include a description of—

18(A) a multi-phased recruitment plan, including with respect to experienced professionals, members of disadvantaged or underserved communities, the unemployed, and veterans;

19(B) a 5-year implementation plan;

20(C) a 10-year projection of the cybersecurity workforce needs of the Department;

21(D) any obstacle impeding the hiring and development of a cybersecurity workforce in the Department; and

22(E) any gap in the existing cybersecurity workforce of the Department and a plan to fill any such gap.

23The Secretary submit 1 to the appropriate congressional committees annual updates on—

24(1) the cybersecurity workforce assessment required under subsection (a); and

25(2) the progress of the Secretary in carrying out the comprehensive workforce strategy required to be developed under subsection (b).

147

to 151. Transferred

161.

Establishment of Office; Director

1There is hereby established within the Department of Justice an Office of Science and Technology (hereinafter in this subchapter referred to as the "Office").

2The Office shall be under the general authority of the Assistant Attorney General, Office of Justice Programs, and shall be established within the National Institute of Justice.

3The Office shall be headed by a Director, who shall be an individual appointed based on approval by the Office of Personnel Management of the executive qualifications of the individual.

162.

Mission of Office; duties

1The mission of the Office shall be—

2(1) to serve as the national focal point for work on law enforcement technology; and

3(2) to carry out programs that, through the provision of equipment, training, and technical assistance, improve the safety and effectiveness of law enforcement technology and improve access to such technology by Federal, State, and local law enforcement agencies.

4In carrying out its mission, the Office shall have the following duties:

5(1) To provide recommendations and advice to the Attorney General.

6(2) To establish and maintain advisory groups (which shall be exempt from the provisions of chapter 10 of title 5) to assess the law enforcement technology needs of Federal, State, and local law enforcement agencies.

7(3) To establish and maintain performance standards in accordance with the National Technology Transfer and Advancement Act of 1995 (Public Law 104–113) for, and test and evaluate law enforcement technologies that may be used by, Federal, State, and local law enforcement agencies.

8(4) To establish and maintain a program to certify, validate, and mark or otherwise recognize law enforcement technology products that conform to standards established and maintained by the Office in accordance with the National Technology Transfer and Advancement Act of 1995 (Public Law 104–113). The program may, at the discretion of the Office, allow for supplier's declaration of conformity with such standards.

9(5) To work with other entities within the Department of Justice, other Federal agencies, and the executive office of the President to establish a coordinated Federal approach on issues related to law enforcement technology.

10(6) To carry out research, development, testing, evaluation, and cost-benefit analyses in fields that would improve the safety, effectiveness, and efficiency of law enforcement technologies used by Federal, State, and local law enforcement agencies, including, but not limited to—

11(A) weapons capable of preventing use by unauthorized persons, including personalized guns;

12(B) protective apparel;

13(C) bullet-resistant and explosion-resistant glass;

14(D) monitoring systems and alarm systems capable of providing precise location information;

15(E) wire and wireless interoperable communication technologies;

16(F) tools and techniques that facilitate investigative and forensic work, including computer forensics;

17(G) equipment for particular use in counterterrorism, including devices and technologies to disable terrorist devices;

18(H) guides to assist State and local law enforcement agencies;

19(I) DNA identification technologies; and

20(J) tools and techniques that facilitate investigations of computer crime.

21(7) To administer a program of research, development, testing, and demonstration to improve the interoperability of voice and data public safety communications.

22(8) To serve on the Technical Support Working Group of the Department of Defense, and on other relevant interagency panels, as requested.

23(9) To develop, and disseminate to State and local law enforcement agencies, technical assistance and training materials for law enforcement personnel, including prosecutors.

24(10) To operate the regional National Law Enforcement and Corrections Technology Centers and, to the extent necessary, establish additional centers through a competitive process.

25(11) To administer a program of acquisition, research, development, and dissemination of advanced investigative analysis and forensic tools to assist State and local law enforcement agencies in combating cybercrime.

26(12) To support research fellowships in support of its mission.

27(13) To serve as a clearinghouse for information on law enforcement technologies.

28(14) To represent the United States and State and local law enforcement agencies, as requested, in international activities concerning law enforcement technology.

29(15) To enter into contracts and cooperative agreements and provide grants, which may require in-kind or cash matches from the recipient, as necessary to carry out its mission.

30(16) To carry out other duties assigned by the Attorney General to accomplish the mission of the Office.

31Except as otherwise expressly provided by law, all research and development carried out by or through the Office shall be carried out on a competitive basis.

32Federal agencies shall, upon request from the Office and in accordance with Federal law, provide the Office with any data, reports, or other information requested, unless compliance with such request is otherwise prohibited by law.

33Decisions concerning publications issued by the Office shall rest solely with the Director of the Office.

34The Office may transfer funds to other Federal agencies or provide funding to non-Federal entities through grants, cooperative agreements, or contracts to carry out its duties under this section: Provided, That any such transfer or provision of funding shall be carried out in accordance with section 605 of Public Law 107–77.

35The Director of the Office shall include with the budget justification materials submitted to Congress in support of the Department of Justice budget for each fiscal year (as submitted with the budget of the President under section 1105(a) of title 31) a report on the activities of the Office. Each such report shall include the following:

36(1) For the period of 5 fiscal years beginning with the fiscal year for which the budget is submitted—

37(A) the Director's assessment of the needs of Federal, State, and local law enforcement agencies for assistance with respect to law enforcement technology and other matters consistent with the mission of the Office; and

38(B) a strategic plan for meeting such needs of such law enforcement agencies.

39(2) For the fiscal year preceding the fiscal year for which such budget is submitted, a description of the activities carried out by the Office and an evaluation of the extent to which those activities successfully meet the needs assessed under paragraph (1)(A) in previous reports.

163.

Definition of law enforcement technology

1For the purposes of this subchapter, the term "law enforcement technology" includes investigative and forensic technologies, corrections technologies, and technologies that support the judicial process.

164.

Abolishment of Office of Science and Technology of National Institute of Justice; transfer of functions

1The Attorney General may transfer to the Office any other program or activity of the Department of Justice that the Attorney General, in consultation with the Committee on the Judiciary of the Senate and the Committee on the Judiciary of the House of Representatives, determines to be consistent with the mission of the Office.

2With respect to any function, power, or duty, or any program or activity, that is established in the Office, those employees and assets of the element of the Department of Justice from which the transfer is made that the Attorney General determines are needed to perform that function, power, or duty, or for that program or activity, as the case may be, shall be transferred to the Office: Provided, That any such transfer shall be carried out in accordance with section 605 of Public Law 107–77.

3Not later than 1 year after November 25, 2002, the Attorney General shall submit to the Committee on the Judiciary of the Senate and the Committee on the Judiciary of the House of Representatives a report on the implementation of this subchapter. The report shall—

4(1) provide an accounting of the amounts and sources of funding available to the Office to carry out its mission under existing authorizations and appropriations, and set forth the future funding needs of the Office; and

5(2) include such other information and recommendations as the Attorney General considers appropriate.

165.

National Law Enforcement and Corrections Technology Centers

1The Director of the Office shall operate and support National Law Enforcement and Corrections Technology Centers (hereinafter in this section referred to as "Centers") and, to the extent necessary, establish new centers through a merit-based, competitive process.

2The purpose of the Centers shall be to—

3(1) support research and development of law enforcement technology;

4(2) support the transfer and implementation of technology;

5(3) assist in the development and dissemination of guidelines and technological standards; and

6(4) provide technology assistance, information, and support for law enforcement, corrections, and criminal justice purposes.

7Each year, the Director shall convene a meeting of the Centers in order to foster collaboration and communication between Center participants.

8Not later than 12 months after November 25, 2002, the Director shall transmit to the Congress a report assessing the effectiveness of the existing system of Centers and identify the number of Centers necessary to meet the technology needs of Federal, State, and local law enforcement in the United States.

181.

Under Secretary for Science and Technology

1There shall be in the Department a Directorate of Science and Technology headed by an Under Secretary for Science and Technology.

182.

Responsibilities and authorities of the Under Secretary for Science and Technology

1The Secretary, acting through the Under Secretary for Science and Technology, shall have the responsibility for—

2(1) advising the Secretary regarding research and development efforts and priorities in support of the Department's missions;

3(2) developing, in consultation with other appropriate executive agencies, a national policy and strategic plan for, identifying priorities, goals, objectives and policies for, and coordinating the Federal Government's civilian efforts to identify and develop countermeasures to chemical, biological, and other emerging terrorist threats, including the development of comprehensive, research-based definable goals for such efforts and development of annual measurable objectives and specific targets to accomplish and evaluate the goals for such efforts;

4(3) supporting the Under Secretary for Intelligence and Analysis and the Director of the Cybersecurity and Infrastructure Security Agency, by assessing and testing homeland security vulnerabilities and possible threats;

5(4) conducting basic and applied research, development, demonstration, testing, and evaluation activities that are relevant to any or all elements of the Department, through both intramural and extramural programs, except that such responsibility does not extend to human health-related research and development activities;

6(5) establishing priorities for, directing, funding, and conducting national research, development, test and evaluation, and procurement of technology and systems for—

7(A) preventing the importation of chemical, biological, and related weapons and material; and

8(B) detecting, preventing, protecting against, and responding to terrorist attacks;

9(6) establishing a system for transferring homeland security developments or technologies to Federal, State, local government, and private sector entities;

10(7) entering into work agreements, joint sponsorships, contracts, or any other agreements with the Department of Energy regarding the use of the national laboratories or sites and support of the science and technology base at those facilities;

11(8) collaborating with the Secretary of Agriculture and the Attorney General as provided in section 8401 of title 7;

12(9) collaborating with the Secretary of Health and Human Services and the Attorney General in determining any new biological agents and toxins that shall be listed as "select agents" in Appendix A of part 72 of title 42, Code of Federal Regulations, pursuant to section 262a of title 42;

13(10) supporting United States leadership in science and technology;

14(11) establishing and administering the primary research and development activities of the Department, including the long-term research and development needs and capabilities for all elements of the Department;

15(12) coordinating and integrating all research, development, demonstration, testing, and evaluation activities of the Department;

16(13) coordinating with other appropriate executive agencies in developing and carrying out the science and technology agenda of the Department to reduce duplication and identify unmet needs;

17(14) developing and overseeing the administration of guidelines for merit review of research and development projects throughout the Department, and for the dissemination of research conducted or sponsored by the Department; and

18(15) carrying out, in coordination with the Drug Enforcement Administration, research, development, testing, evaluation, and cost-benefit analyses to improve the safety, effectiveness, and efficiency of equipment and the effectiveness and efficiency of reference libraries for use by Federal, State, local, Tribal, and territorial law enforcement agencies for the accurate detection of drugs, such as fentanyl and xylazine, including—

19(A) portable equipment that can detect and identify drugs with minimal or no handling of the sample;

20(B) equipment that can separate complex mixtures containing low concentrations of drugs and high concentrations of cutting agents into their component parts to enable signature extraction for field identification and detection; and

21(C) technologies that use machine learning or artificial intelligence (as defined in section 9401 of title 15) and other techniques to predict whether the substances in a sample are controlled substance analogues or other new psychoactive substances not yet included in available reference libraries.

183.

Functions transferred

1In accordance with subchapter XII, there shall be transferred to the Secretary the functions, personnel, assets, and liabilities of the following entities:

2(1) The following programs and activities of the Department of Energy, including the functions of the Secretary of Energy relating thereto (but not including programs and activities relating to the strategic nuclear defense posture of the United States):

3(A) The chemical and biological national security and supporting programs and activities of the nonproliferation and verification research and development program.

4(B) The nuclear smuggling programs and activities within the proliferation detection program of the nonproliferation and verification research and development program. The programs and activities described in this subparagraph may be designated by the President either for transfer to the Department or for joint operation by the Secretary and the Secretary of Energy.

5(C) The nuclear assessment program and activities of the assessment, detection, and cooperation program of the international materials protection and cooperation program.

6(D) Such life sciences activities of the biological and environmental research program related to microbial pathogens as may be designated by the President for transfer to the Department.

7(E) The Environmental Measurements Laboratory.

8(F) The advanced scientific computing research program and activities at Lawrence Livermore National Laboratory.

9(2) The National Bio-Weapons Defense Analysis Center of the Department of Defense, including the functions of the Secretary of Defense related thereto.

184.

Conduct of certain public health-related activities

1With respect to civilian human health-related research and development activities relating to countermeasures for chemical, biological, radiological, and nuclear and other emerging terrorist threats carried out by the Department of Health and Human Services (including the Public Health Service), the Secretary of Health and Human Services shall set priorities, goals, objectives, and policies and develop a coordinated strategy for such activities in collaboration with the Secretary of Homeland Security to ensure consistency with the national policy and strategic plan developed pursuant to section 182(2) of this title.

2In carrying out subsection (a), the Secretary of Health and Human Services shall collaborate with the Secretary in developing specific benchmarks and outcome measurements for evaluating progress toward achieving the priorities and goals described in such subsection.

185.

Federally funded research and development centers

1The Secretary, acting through the Under Secretary for Science and Technology, shall have the authority to establish or contract with 1 or more federally funded research and development centers to provide independent analysis of homeland security issues, or to carry out other responsibilities under this chapter, including coordinating and integrating both the extramural and intramural programs described in section 188 of this title.

186.

Miscellaneous provisions

1To the greatest extent practicable, research conducted or supported by the Department shall be unclassified.

2Nothing in this subchapter shall be construed to preclude any Under Secretary of the Department from carrying out research, development, demonstration, or deployment activities, as long as such activities are coordinated through the Under Secretary for Science and Technology.

3The Secretary, acting through the Under Secretary for Science and Technology, may issue necessary regulations with respect to research, development, demonstration, testing, and evaluation activities of the Department, including the conducting, funding, and reviewing of such activities.

4Not later than 60 days before effecting any transfer of Department of Energy life sciences activities pursuant to section 183(1)(D) of this title, the President shall notify the appropriate congressional committees of the proposed transfer and shall include the reasons for the transfer and a description of the effect of the transfer on the activities of the Department of Energy.

187.

Homeland Security Advanced Research Projects Agency

1In this section:

2The term "Fund" means the Acceleration Fund for Research and Development of Homeland Security Technologies established in subsection (c).

3The term "homeland security research" means research relevant to the detection of, prevention of, protection against, response to, attribution of, and recovery from homeland security threats, particularly acts of terrorism.

4The term "HSARPA" means the Homeland Security Advanced Research Projects Agency established in subsection (b).

5The term "Under Secretary" means the Under Secretary for Science and Technology.

6There is established the Homeland Security Advanced Research Projects Agency.

7HSARPA shall be headed by a Director, who shall be appointed by the Secretary. The Director shall report to the Under Secretary.

8The Director shall administer the Fund to award competitive, merit-reviewed grants, cooperative agreements or contracts to public or private entities, including businesses, federally funded research and development centers, and universities. The Director shall administer the Fund to—

9(A) support basic and applied homeland security research to promote revolutionary changes in technologies that would promote homeland security;

10(B) advance the development, testing and evaluation, and deployment of critical homeland security technologies;

11(C) accelerate the prototyping and deployment of technologies that would address homeland security vulnerabilities; and

12(D) conduct research and development for the purpose of advancing technology for the investigation of child exploitation crimes, including child victim identification, trafficking in persons, and child pornography, and for advanced forensics.

13The Director may solicit proposals to address specific vulnerabilities identified by the Director.

14The Director shall ensure that the activities of HSARPA are coordinated with those of other relevant research agencies, and may run projects jointly with other agencies.

15In hiring personnel for HSARPA, the Secretary shall have the hiring and management authorities described in section 1101 1 of the Strom Thurmond National Defense Authorization Act for Fiscal Year 1999 (5 U.S.C. 3104 note; Public Law 105–261). The term of appointments for employees under subsection (c)(1) of that section may not exceed 5 years before the granting of any extension under subsection (c)(2) of that section.

16The Director, periodically, shall hold homeland security technology demonstrations to improve contact among technology developers, vendors and acquisition personnel.

17There is established the Acceleration Fund for Research and Development of Homeland Security Technologies, which shall be administered by the Director of HSARPA.

18There are authorized to be appropriated $500,000,000 to the Fund for fiscal year 2003 and such sums as may be necessary thereafter.

19Of the funds authorized to be appropriated under paragraph (2), not less than 10 percent of such funds for each fiscal year through fiscal year 2005 shall be authorized only for the Under Secretary, through joint agreement with the Commandant of the Coast Guard, to carry out research and development of improved ports, waterways and coastal security surveillance and perimeter protection capabilities for the purpose of minimizing the possibility that Coast Guard cutters, aircraft, helicopters, and personnel will be diverted from non-homeland security missions to the ports, waterways and coastal security mission.

188.

Conduct of research, development, demonstration, testing and evaluation

1The Secretary, acting through the Under Secretary for Science and Technology, shall carry out the responsibilities under section 182(4) of this title through both extramural and intramural programs.

2The Secretary, acting through the Under Secretary for Science and Technology, shall operate extramural research, development, demonstration, testing, and evaluation programs so as to—

3(A) ensure that colleges, universities, private research institutes, and companies (and consortia thereof) from as many areas of the United States as practicable participate;

4(B) ensure that the research funded is of high quality, as determined through merit review processes developed under section 182(14) of this title; and

5(C) distribute funds through grants, cooperative agreements, and contracts.

6The Secretary, acting through the Under Secretary for Science and Technology, shall designate a university-based center or several university-based centers for homeland security. The purpose of the center or these centers shall be to establish a coordinated, university-based system to enhance the Nation's homeland security.

7Criteria for the designation of colleges or universities as a center for homeland security, shall include, but are not limited to, demonstrated expertise in—

8(i) The training of first responders.

9(ii) Responding to incidents involving weapons of mass destruction and biological warfare.

10(iii) Emergency and diagnostic medical services.

11(iv) Chemical, biological, radiological, and nuclear countermeasures or detection.

12(v) Animal and plant health and diagnostics.

13(vi) Food safety.

14(vii) Water and wastewater operations.

15(viii) Port and waterway security.

16(ix) Multi-modal transportation.

17(x) Information security and information engineering.

18(xi) Engineering.

19(xii) Educational outreach and technical assistance.

20(xiii) Border transportation and security.

21(xiv) The public policy implications and public dissemination of homeland security related research and development.

22To the extent that exercising such discretion is in the interest of homeland security, and with respect to the designation of any given university-based center for homeland security, the Secretary may except certain criteria as specified in subparagraph (B) and consider additional criteria beyond those specified in subparagraph (B). Upon designation of a university-based center for homeland security, the Secretary shall that day publish in the Federal Register the criteria that were excepted or added in the selection process and the justification for the set of criteria that were used for that designation.

23The Secretary shall report annually, from the date of enactment, to Congress concerning the implementation of this section. That report shall indicate which center or centers have been designated and how the designation or designations enhance homeland security, as well as report any decisions to revoke or modify such designations.

24There are authorized to be appropriated such sums as may be necessary to carry out this paragraph.

25In carrying out the duties under section 182 of this title, the Secretary, acting through the Under Secretary for Science and Technology, may draw upon the expertise of any laboratory of the Federal Government, whether operated by a contractor or the Government.

26The Secretary, acting through the Under Secretary for Science and Technology, may establish a headquarters laboratory for the Department at any laboratory or site and may establish additional laboratory units at other laboratories or sites.

27If the Secretary chooses to establish a headquarters laboratory pursuant to paragraph (2), then the Secretary shall do the following:

28(A) Establish criteria for the selection of the headquarters laboratory in consultation with the National Academy of Sciences, appropriate Federal agencies, and other experts.

29(B) Publish the criteria in the Federal Register.

30(C) Evaluate all appropriate laboratories or sites against the criteria.

31(D) Select a laboratory or site on the basis of the criteria.

32(E) Report to the appropriate congressional committees on which laboratory was selected, how the selected laboratory meets the published criteria, and what duties the headquarters laboratory shall perform.

33No laboratory shall begin operating as the headquarters laboratory of the Department until at least 30 days after the transmittal of the report required by paragraph (3)(E).

34In this subsection:

35The term "country of concern" means a country that—

36(i) is a covered nation, as such term is defined in section 4872(d) of title 10; or

37(ii) the Secretary determines is engaged in conduct that is detrimental to the national security of the United States.

38The terms "nonprofit organization", "small business firm", and "subject invention" have the meanings given such terms in section 201 of title 35.

39The term "manufactured substantially in the United States" means an item is a domestic end product.

40The term "domestic end product" has the meaning given such term in section 25.003 of title 48, Code of Federal Regulations, or any successor thereto.

41Subject to subparagraph (B), in individual cases, the requirements under section 204 of title 35 may be waived by the Secretary upon a showing by the small business firm, nonprofit organization, or assignee that reasonable but unsuccessful efforts have been made to grant licenses on similar terms to potential licensees that would be likely to manufacture substantially in the United States or that under the circumstances domestic manufacture is not commercially feasible.

42Before granting a waiver under subparagraph (A), the Secretary shall comply with the procedures developed and implemented by the Department pursuant to section 70923(b)(2) of the Build America, Buy America Act (enacted as subtitle A of title IX of division G of Public Law 117–58).

43The Secretary may not grant a waiver under subparagraph (A) if, as a result of such waiver, products embodying the applicable subject invention, or produced through the use of the applicable subject invention, would be manufactured substantially in a country of concern.

189.

Utilization of Department of Energy national laboratories and sites in support of homeland security activities

1In carrying out the missions of the Department, the Secretary may utilize the Department of Energy national laboratories and sites through any 1 or more of the following methods, as the Secretary considers appropriate:

2(A) A joint sponsorship arrangement referred to in subsection (b).

3(B) A direct contract between the Department and the applicable Department of Energy laboratory or site, subject to subsection (c).

4(C) Any "work for others" basis made available by that laboratory or site.

5(D) Any other method provided by law.

6Notwithstanding any other law governing the administration, mission, use, or operations of any of the Department of Energy national laboratories and sites, such laboratories and sites are authorized to accept and perform work for the Secretary, consistent with resources provided, and perform such work on an equal basis to other missions at the laboratory and not on a noninterference basis with other missions of such laboratory or site.

7The Department may be a joint sponsor, under a multiple agency sponsorship arrangement with the Department of Energy, of 1 or more Department of Energy national laboratories in the performance of work.

8The Department may be a joint sponsor of a Department of Energy site in the performance of work as if such site were a federally funded research and development center and the work were performed under a multiple agency sponsorship arrangement with the Department.

9The Department of Energy shall be the primary sponsor under a multiple agency sponsorship arrangement referred to in paragraph (1) or (2).

10The Secretary of Energy shall act as the lead agent in coordinating the formation and performance of a joint sponsorship arrangement under this subsection between the Department and a Department of Energy national laboratory or site.

11Any work performed by a Department of Energy national laboratory or site under a joint sponsorship arrangement under this subsection shall comply with the policy on the use of federally funded research and development centers under the Federal Acquisition Regulations.

12The Department shall provide funds for work at the Department of Energy national laboratories or sites, as the case may be, under a joint sponsorship arrangement under this subsection under the same terms and conditions as apply to the primary sponsor of such national laboratory under section 3303(a)(1)(C) of title 41 or of such site to the extent such section applies to such site as a federally funded research and development center by reason of this subsection.

13To the extent that programs or activities transferred by this chapter from the Department of Energy to the Department of Homeland Security are being carried out through direct contracts with the operator of a national laboratory or site of the Department of Energy, the Secretary of Homeland Security and the Secretary of Energy shall ensure that direct contracts for such programs and activities between the Department of Homeland Security and such operator are separate from the direct contracts of the Department of Energy with such operator.

14In connection with any utilization of the Department of Energy national laboratories and sites under this section, the Secretary may permit the director of any such national laboratory or site to enter into cooperative research and development agreements or to negotiate licensing agreements with any person, any agency or instrumentality, of the United States, any unit of State or local government, and any other entity under the authority granted by section 3710a of title 15. Technology may be transferred to a non-Federal party to such an agreement consistent with the provisions of sections 3710 and 3710a of title 15.

15In the case of an activity carried out by the operator of a Department of Energy national laboratory or site in connection with any utilization of such laboratory or site under this section, the Department of Homeland Security shall reimburse the Department of Energy for costs of such activity through a method under which the Secretary of Energy waives any requirement for the Department of Homeland Security to pay administrative charges or personnel costs of the Department of Energy or its contractors in excess of the amount that the Secretary of Energy pays for an activity carried out by such contractor and paid for by the Department of Energy.

16No funds authorized to be appropriated or otherwise made available to the Department in any fiscal year may be obligated or expended for laboratory directed research and development activities carried out by the Department of Energy unless such activities support the missions of the Department of Homeland Security.

17There is established within the Directorate of Science and Technology an Office for National Laboratories, which shall be responsible for the coordination and utilization of the Department of Energy national laboratories and sites under this section in a manner to create a networked laboratory system for the purpose of supporting the missions of the Department.

18The Secretary of Energy shall ensure that any research, development, test, and evaluation activities conducted within the Department of Energy that are directly or indirectly related to homeland security are fully coordinated with the Secretary to minimize duplication of effort and maximize the effective application of Federal budget resources.

190.

Transfer of Plum Island Animal Disease Center, Department of Agriculture

1In accordance with subchapter XII, the Secretary of Agriculture shall transfer to the Secretary of Homeland Security the Plum Island Animal Disease Center of the Department of Agriculture, including the assets and liabilities of the Center.

2On completion of the transfer of the Plum Island Animal Disease Center under subsection (a), the Secretary of Homeland Security and the Secretary of Agriculture shall enter into an agreement to ensure that the Department of Agriculture is able to carry out research, diagnostic, and other activities of the Department of Agriculture at the Center.

3The Secretary of Agriculture shall continue to direct the research, diagnostic, and other activities of the Department of Agriculture at the Center described in subsection (b).

4At least 180 days before any change in the biosafety level at the Plum Island Animal Disease Center, the President shall notify Congress of the change and describe the reasons for the change.

5No change described in paragraph (1) may be made earlier than 180 days after the completion of the transition period (as defined in section 541 of this title).

191.

Homeland Security Science and Technology Advisory Committee

1There is established within the Department a Homeland Security Science and Technology Advisory Committee (in this section referred to as the "Advisory Committee"). The Advisory Committee shall make recommendations with respect to the activities of the Under Secretary for Science and Technology, including identifying research areas of potential importance to the security of the Nation.

2The Advisory Committee shall consist of 20 members appointed by the Under Secretary for Science and Technology, which shall include emergency first-responders or representatives of organizations or associations of emergency first-responders. The Advisory Committee shall also include representatives of citizen groups, including economically disadvantaged communities. The individuals appointed as members of the Advisory Committee—

3(A) shall be eminent in fields such as emergency response, research, engineering, new product development, business, and management consulting;

4(B) shall be selected solely on the basis of established records of distinguished service;

5(C) shall not be employees of the Federal Government; and

6(D) shall be so selected as to provide representation of a cross-section of the research, development, demonstration, and deployment activities supported by the Under Secretary for Science and Technology.

7The Under Secretary for Science and Technology may enter into an arrangement for the National Research Council to select members of the Advisory Committee, but only if the panel used by the National Research Council reflects the representation described in paragraph (1).

8Except as otherwise provided in this subsection, the term of office of each member of the Advisory Committee shall be 3 years.

9The original members of the Advisory Committee shall be appointed to three classes. One class of six shall have a term of 1 year, one class of seven a term of 2 years, and one class of seven a term of 3 years.

10A member appointed to fill a vacancy occurring before the expiration of the term for which the member's predecessor was appointed shall be appointed for the remainder of such term.

11A person who has completed two consecutive full terms of service on the Advisory Committee shall thereafter be ineligible for appointment during the 1-year period following the expiration of the second such term.

12The Advisory Committee shall meet at least quarterly at the call of the Chair or whenever one-third of the members so request in writing. Each member shall be given appropriate notice of the call of each meeting, whenever possible not less than 15 days before the meeting.

13A majority of the members of the Advisory Committee not having a conflict of interest in the matter being considered by the Advisory Committee shall constitute a quorum.

14The Advisory Committee shall establish rules for determining when 1 of its members has a conflict of interest in a matter being considered by the Advisory Committee.

15The Advisory Committee shall render an annual report to the Under Secretary for Science and Technology for transmittal to Congress on or before January 31 of each year. Such report shall describe the activities and recommendations of the Advisory Committee during the previous year.

16The Advisory Committee may render to the Under Secretary for transmittal to Congress such additional reports on specific policy matters as it considers appropriate.

17Section 1013 of title 5 shall not apply to the Advisory Committee.

18The Department of Homeland Security Science and Technology Advisory Committee shall terminate on December 31, 2008.

192.

Homeland Security Institute

1The Secretary shall establish a federally funded research and development center to be known as the "Homeland Security Institute" (in this section referred to as the "Institute").

2The Institute shall be administered as a separate entity by the Secretary.

3The duties of the Institute shall be determined by the Secretary, and may include the following:

4(1) Systems analysis, risk analysis, and simulation and modeling to determine the vulnerabilities of the Nation's critical infrastructures and the effectiveness of the systems deployed to reduce those vulnerabilities.

5(2) Economic and policy analysis to assess the distributed costs and benefits of alternative approaches to enhancing security.

6(3) Evaluation of the effectiveness of measures deployed to enhance the security of institutions, facilities, and infrastructure that may be terrorist targets.

7(4) Identification of instances when common standards and protocols could improve the interoperability and effective utilization of tools developed for field operators and first responders.

8(5) Assistance for Federal agencies and departments in establishing testbeds to evaluate the effectiveness of technologies under development and to assess the appropriateness of such technologies for deployment.

9(6) Design of metrics and use of those metrics to evaluate the effectiveness of homeland security programs throughout the Federal Government, including all national laboratories.

10(7) Design of and support for the conduct of homeland security-related exercises and simulations.

11(8) Creation of strategic technology development plans to reduce vulnerabilities in the Nation's critical infrastructure and key resources.

12In carrying out the duties described in subsection (c), the Institute shall consult widely with representatives from private industry, institutions of higher education, nonprofit institutions, other Government agencies, and federally funded research and development centers.

13The Institute shall utilize the capabilities of the National Infrastructure Simulation and Analysis Center.

14The Institute shall transmit to the Secretary and Congress an annual report on the activities of the Institute under this section.

15The Homeland Security Institute shall terminate 5 years after its establishment.

193.

Technology clearinghouse to encourage and support innovative solutions to enhance homeland security

1The Secretary, acting through the Under Secretary for Science and Technology, shall establish and promote a program to encourage technological innovation in facilitating the mission of the Department (as described in section 111 of this title).

2The program described in subsection (a) shall include the following components:

3(1) The establishment of a centralized Federal clearinghouse for information relating to technologies that would further the mission of the Department for dissemination, as appropriate, to Federal, State, and local government and private sector entities for additional review, purchase, or use.

4(2) The issuance of announcements seeking unique and innovative technologies to advance the mission of the Department.

5(3) The establishment of a technical assistance team to assist in screening, as appropriate, proposals submitted to the Secretary (except as provided in subsection (c)(2)) to assess the feasibility, scientific and technical merits, and estimated cost of such proposals, as appropriate.

6(4) The provision of guidance, recommendations, and technical assistance, as appropriate, to assist Federal, State, and local government and private sector efforts to evaluate and implement the use of technologies described in paragraph (1) or (2).

7(5) The provision of information for persons seeking guidance on how to pursue proposals to develop or deploy technologies that would enhance homeland security, including information relating to Federal funding, regulation, or acquisition.

8Nothing in this section shall be construed as authorizing the Secretary or the technical assistance team established under subsection (b)(3) to set standards for technology to be used by the Department, any other executive agency, any State or local government entity, or any private sector entity.

9The technical assistance team established under subsection (b)(3) shall not consider or evaluate proposals submitted in response to a solicitation for offers for a pending procurement or for a specific agency requirement.

10In carrying out this section, the Secretary shall coordinate with the Technical Support Working Group (organized under the April 1982 National Security Decision Directive Numbered 30).

194.

Enhancement of public safety communications interoperability

1The Secretary of Homeland Security, in consultation with the Secretary of Commerce and the Chairman of the Federal Communications Commission, shall establish a program to enhance public safety interoperable communications at all levels of government. Such program shall—

2(A) establish a comprehensive national approach to achieving public safety interoperable communications;

3(B) coordinate with other Federal agencies in carrying out subparagraph (A);

4(C) develop, in consultation with other appropriate Federal agencies and State and local authorities, appropriate minimum capabilities for communications interoperability for Federal, State, and local public safety agencies;

5(D) accelerate, in consultation with other Federal agencies, including the National Institute of Standards and Technology, the private sector, and nationally recognized standards organizations as appropriate, the development of national voluntary consensus standards for public safety interoperable communications, recognizing—

6(i) the value, life cycle, and technical capabilities of existing communications infrastructure;

7(ii) the need for cross-border interoperability between States and nations;

8(iii) the unique needs of small, rural communities; and

9(iv) the interoperability needs for daily operations and catastrophic events;

10(E) encourage the development and implementation of flexible and open architectures incorporating, where possible, technologies that currently are commercially available, with appropriate levels of security, for short-term and long-term solutions to public safety communications interoperability;

11(F) assist other Federal agencies in identifying priorities for research, development, and testing and evaluation with regard to public safety interoperable communications;

12(G) identify priorities within the Department of Homeland Security for research, development, and testing and evaluation with regard to public safety interoperable communications;

13(H) establish coordinated guidance for Federal grant programs for public safety interoperable communications;

14(I) provide technical assistance to State and local public safety agencies regarding planning, acquisition strategies, interoperability architectures, training, and other functions necessary to achieve public safety communications interoperability;

15(J) develop and disseminate best practices to improve public safety communications interoperability; and

16(K) develop appropriate performance measures and milestones to systematically measure the Nation's progress toward achieving public safety communications interoperability, including the development of national voluntary consensus standards.

17The Secretary may establish an Office for Interoperability and Compatibility within the Directorate of Science and Technology to carry out this subsection.

18If the Secretary establishes such office, the Secretary shall, through such office—

19(i) carry out Department of Homeland Security responsibilities and authorities relating to the SAFECOM Program; and

20(ii) carry out section 510 1 of the Homeland Security Act of 2002, as added by subsection (d).

21There are authorized to be appropriated to the Secretary to carry out this subsection—

22(A) $22,105,000 for fiscal year 2005;

23(B) $22,768,000 for fiscal year 2006;

24(C) $23,451,000 for fiscal year 2007;

25(D) $24,155,000 for fiscal year 2008; and

26(E) $24,879,000 for fiscal year 2009.

27Not later than 120 days after December 17, 2004, the Secretary shall report to the Congress on Department of Homeland Security plans for accelerating the development of national voluntary consensus standards for public safety interoperable communications, a schedule of milestones for such development, and achievements of such development.

28Not later than 18 months after December 17, 2004, the President shall establish a mechanism for coordinating cross-border interoperability issues between—

29(1) the United States and Canada; and

30(2) the United States and Mexico.

31In awarding grants to any State, region, local government, or Indian tribe for the purposes of enhancing interoperable communications capabilities for emergency response providers, the Secretary may commit to obligate Federal assistance beyond the current fiscal year, subject to the limitations and restrictions in this subsection.

32No multiyear interoperability commitment may exceed 3 years in duration.

33The total amount of assistance the Secretary has committed to obligate for any future fiscal year under paragraph (1) may not exceed $150,000,000.

34Pursuant to paragraph (1), the Secretary may issue a letter of intent to an applicant committing to obligate from future budget authority an amount, not more than the Federal Government's share of the project's cost, for an interoperability communications project (including interest costs and costs of formulating the project).

35A letter of intent under this paragraph shall establish a schedule under which the Secretary will reimburse the applicant for the Federal Government's share of the project's costs, as amounts become available, if the applicant, after the Secretary issues the letter, carries out the project before receiving amounts under a grant issued by the Secretary.

36An applicant that is issued a letter of intent under this subsection shall notify the Secretary of the applicant's intent to carry out a project pursuant to the letter before the project begins.

37The Secretary shall transmit a written notification to the Congress no later than 3 days before the issuance of a letter of intent under this section.

38A letter of intent issued under this section is not an obligation of the Government under section 1501 of title 31 and is not deemed to be an administrative commitment for financing. An obligation or administrative commitment may be made only as amounts are provided in authorization and appropriations laws.

39Nothing in this subsection shall be construed—

40(i) to prohibit the obligation of amounts pursuant to a letter of intent under this subsection in the same fiscal year as the letter of intent is issued; or

41(ii) to apply to, or replace, Federal assistance intended for interoperable communications that is not provided pursuant to a commitment under this subsection.

42Any applicant requesting funding assistance from the Secretary for interoperable communications for emergency response providers shall submit an Interoperable Communications Plan to the Secretary for approval. Such a plan shall—

43(1) describe the current state of communications interoperability in the applicable jurisdictions among Federal, State, and local emergency response providers and other relevant private resources;

44(2) describe the available and planned use of public safety frequency spectrum and resources for interoperable communications within such jurisdictions;

45(3) describe how the planned use of spectrum and resources for interoperable communications is compatible with surrounding capabilities and interoperable communications plans of Federal, State, and local governmental entities, military installations, foreign governments, critical infrastructure, and other relevant entities;

46(4) include a 5-year plan for the dedication of Federal, State, and local government and private resources to achieve a consistent, secure, and effective interoperable communications system, including planning, system design and engineering, testing and technology development, procurement and installation, training, and operations and maintenance;

47(5) describe how such 5-year plan meets or exceeds any applicable standards and grant requirements established by the Secretary;

48(6) include information on the governance structure used to develop the plan, including such information about all agencies and organizations that participated in developing the plan and the scope and timeframe of the plan; and

49(7) describe the method by which multi-jurisdictional, multidisciplinary input is provided from all regions of the jurisdiction, including any high-threat urban areas located in the jurisdiction, and the process for continuing to incorporate such input.

50In this section:

51The term "interoperable communications" means the ability of emergency response providers and relevant Federal, State, and local government agencies to communicate with each other as necessary, through a dedicated public safety network utilizing information technology systems and radio communications systems, and to exchange voice, data, and video with one another on demand, in real time, as necessary.

52The term "emergency response providers" has the meaning that term has under section 101 of this title.

53The Congress finds that—

54(A) many first responders working in the same jurisdiction or in different jurisdictions cannot effectively and efficiently communicate with one another; and

55(B) their inability to do so threatens the public's safety and may result in unnecessary loss of lives and property.

56It is the sense of Congress that interoperable emergency communications systems and radios should continue to be deployed as soon as practicable for use by the first responder community, and that upgraded and new digital communications systems and new digital radios must meet prevailing national, voluntary consensus standards for interoperability.

195.

Office for Interoperability and Compatibility

1The Director of the Office for Interoperability and Compatibility shall—

2(1) assist the Secretary in developing and implementing the science and technology aspects of the program described in subparagraphs (D), (E), (F), and (G) of section 194(a)(1) of this title;

3(2) in coordination with the Federal Communications Commission, the National Institute of Standards and Technology, and other Federal departments and agencies with responsibility for standards, support the creation of national voluntary consensus standards for interoperable emergency communications;

4(3) establish a comprehensive research, development, testing, and evaluation program for improving interoperable emergency communications;

5(4) establish, in coordination with the Director for Emergency Communications,1 requirements for interoperable emergency communications capabilities, which shall be nonproprietary where standards for such capabilities exist, for all public safety radio and data communications systems and equipment purchased using homeland security assistance administered by the Department, excluding any alert and warning device, technology, or system;

6(5) carry out the Department's responsibilities and authorities relating to research, development, testing, evaluation, or standards-related elements of the SAFECOM Program;

7(6) evaluate and assess new technology in real-world environments to achieve interoperable emergency communications capabilities;

8(7) encourage more efficient use of existing resources, including equipment, to achieve interoperable emergency communications capabilities;

9(8) test public safety communications systems that are less prone to failure, support new nonvoice services, use spectrum more efficiently, and cost less than existing systems;

10(9) coordinate with the private sector to develop solutions to improve emergency communications capabilities and achieve interoperable emergency communications capabilities; and

11(10) conduct pilot projects, in coordination with the Director for Emergency Communications,1 to test and demonstrate technologies, including data and video, that enhance—

12(A) the ability of emergency response providers and relevant government officials to continue to communicate in the event of natural disasters, acts of terrorism, and other man-made disasters; and

13(B) interoperable emergency communications capabilities.

14The Director of the Office for Interoperability and Compatibility shall coordinate with the Director for Emergency Communications 1 with respect to the SAFECOM program.

15The Secretary shall provide the Office for Interoperability and Compatibility the resources and staff necessary to carry out the responsibilities under this section.

195a.

Emergency communications interoperability research and development

1The Under Secretary for Science and Technology, acting through the Director of the Office for Interoperability and Compatibility, shall establish a comprehensive research and development program to support and promote—

2(1) the ability of emergency response providers and relevant government officials to continue to communicate in the event of natural disasters, acts of terrorism, and other man-made disasters; and

3(2) interoperable emergency communications capabilities among emergency response providers and relevant government officials, including by—

4(A) supporting research on a competitive basis, including through the Directorate of Science and Technology and Homeland Security Advanced Research Projects Agency; and

5(B) considering the establishment of a Center of Excellence under the Department of Homeland Security Centers of Excellence Program focused on improving emergency response providers' communication capabilities.

6The purposes of the program established under subsection (a) include—

7(1) supporting research, development, testing, and evaluation on emergency communication capabilities;

8(2) understanding the strengths and weaknesses of the public safety communications systems in use;

9(3) examining how current and emerging technology can make emergency response providers more effective, and how Federal, State, local, and tribal government agencies can use this technology in a coherent and cost-effective manner;

10(4) investigating technologies that could lead to long-term advancements in emergency communications capabilities and supporting research on advanced technologies and potential systemic changes to dramatically improve emergency communications; and

11(5) evaluating and validating advanced technology concepts, and facilitating the development and deployment of interoperable emergency communication capabilities.

12For purposes of this section, the term "interoperable", with respect to emergency communications, has the meaning given the term in section 578 of this title.

195b.

National Biosurveillance Integration Center

1The Secretary, acting through the Assistant Secretary for the Countering Weapons of Mass Destruction Office, shall establish, operate, and maintain a National Biosurveillance Integration Center (referred to in this section as the "NBIC"), which shall be headed by a Directing Officer, under an office or directorate of the Department that is in existence as of August 3, 2007.

2The primary mission of the NBIC is to—

3(1) enhance the capability of the Federal Government to—

4(A) rapidly identify, characterize, localize, and track a biological event of national concern by integrating and analyzing data relating to human health, animal, plant, food, and environmental monitoring systems (both national and international); and

5(B) disseminate alerts and other information to Member Agencies and, in coordination with (and where possible through) Member Agencies, to agencies of State, local, and tribal governments, as appropriate, to enhance the ability of such agencies to respond to a biological event of national concern; and

6(2) oversee development and operation of the National Biosurveillance Integration System.

7The NBIC shall detect, as early as possible, a biological event of national concern that presents a risk to the United States or the infrastructure or key assets of the United States, including by—

8(1) consolidating data from all relevant surveillance systems maintained by Member Agencies to detect biological events of national concern across human, animal, and plant species;

9(2) seeking private sources of surveillance, both foreign and domestic, when such sources would enhance coverage of critical surveillance gaps;

10(3) using an information technology system that uses the best available statistical and other analytical tools to identify and characterize biological events of national concern in as close to real-time as is practicable;

11(4) providing the infrastructure for such integration, including information technology systems and space, and support for personnel from Member Agencies with sufficient expertise to enable analysis and interpretation of data;

12(5) working with Member Agencies to create information technology systems that use the minimum amount of patient data necessary and consider patient confidentiality and privacy issues at all stages of development and apprise the Privacy Officer of such efforts; and

13(6) alerting Member Agencies and, in coordination with (and where possible through) Member Agencies, public health agencies of State, local, and tribal governments regarding any incident that could develop into a biological event of national concern.

14The Directing Officer of the NBIC shall—

15(A) on an ongoing basis, monitor the availability and appropriateness of surveillance systems used by the NBIC and those systems that could enhance biological situational awareness or the overall performance of the NBIC;

16(B) on an ongoing basis, review and seek to improve the statistical and other analytical methods used by the NBIC;

17(C) receive and consider other relevant homeland security information, as appropriate; and

18(D) provide technical assistance, as appropriate, to all Federal, regional, State, local, and tribal government entities and private sector entities that contribute data relevant to the operation of the NBIC.

19The Directing Officer of the NBIC shall—

20(A) on an ongoing basis, evaluate available data for evidence of a biological event of national concern; and

21(B) integrate homeland security information with NBIC data to provide overall situational awareness and determine whether a biological event of national concern has occurred.

22The Directing Officer of the NBIC shall—

23(i) establish a method of real-time communication with the National Operations Center;

24(ii) in the event that a biological event of national concern is detected, notify the Secretary and disseminate results of NBIC assessments relating to that biological event of national concern to appropriate Federal response entities and, in coordination with relevant Member Agencies, regional, State, local, and tribal governmental response entities in a timely manner;

25(iii) provide any report on NBIC assessments to Member Agencies and, in coordination with relevant Member Agencies, any affected regional, State, local, or tribal government, and any private sector entity considered appropriate that may enhance the mission of such Member Agencies, governments, or entities or the ability of the Nation to respond to biological events of national concern; and

26(iv) share NBIC incident or situational awareness reports, and other relevant information, consistent with the information sharing environment established under section 485 of this title and any policies, guidelines, procedures, instructions, or standards established under that section.

27The Directing Officer of the NBIC shall implement the activities described in subparagraph (A) consistent with the policies, guidelines, procedures, instructions, or standards established under section 485 of this title and in consultation with the Director of National Intelligence, the Under Secretary for Intelligence and Analysis, and other offices or agencies of the Federal Government, as appropriate.

28Each Member Agency shall—

29(A) use its best efforts to integrate biosurveillance information into the NBIC, with the goal of promoting information sharing between Federal, State, local, and tribal governments to detect biological events of national concern;

30(B) provide timely information to assist the NBIC in maintaining biological situational awareness for accurate detection and response purposes;

31(C) enable the NBIC to receive and use biosurveillance information from member agencies to carry out its requirements under subsection (c);

32(D) connect the biosurveillance data systems of that Member Agency to the NBIC data system under mutually agreed protocols that are consistent with subsection (c)(5);

33(E) participate in the formation of strategy and policy for the operation of the NBIC and its information sharing;

34(F) provide personnel to the NBIC under an interagency personnel agreement and consider the qualifications of such personnel necessary to provide human, animal, and environmental data analysis and interpretation support to the NBIC; and

35(G) retain responsibility for the surveillance and intelligence systems of that department or agency, if applicable.

36The Directing Officer of the NBIC shall hire individuals with the necessary expertise to develop and operate the NBIC.

37Upon the request of the Directing Officer of the NBIC, the head of any Federal department or agency may detail, on a reimbursable basis, any of the personnel of that department or agency to the Department to assist the NBIC in carrying out this section.

38The Directing Officer of the NBIC shall—

39(1) establish an interagency working group to facilitate interagency cooperation and to advise the Directing Officer of the NBIC regarding recommendations to enhance the biosurveillance capabilities of the Department; and

40(2) invite Member Agencies to serve on that working group.

41The authority of the Directing Officer of the NBIC under this section shall not affect any authority or responsibility of any other department or agency of the Federal Government with respect to biosurveillance activities under any program administered by that department or agency.

42There are authorized to be appropriated such sums as are necessary to carry out this section.

43In this section:

44(1) The terms "biological agent" and "toxin" have the meanings given those terms in section 178 of title 18.

45(2) The term "biological event of national concern" means—

46(A) an act of terrorism involving a biological agent or toxin; or

47(B) a naturally occurring outbreak of an infectious disease that may result in a national epidemic.

48(3) The term "homeland security information" has the meaning given that term in section 482 of this title.

49(4) The term "Member Agency" means any Federal department or agency that, at the discretion of the head of that department or agency, has entered a memorandum of understanding regarding participation in the NBIC.

50(5) The term "Privacy Officer" means the Privacy Officer appointed under section 142 of this title.

195c.

Promoting antiterrorism through international cooperation program

1In this section:

2The term "Director" means the Director selected under subsection (b)(2).

3The term "international cooperative activity" includes—

4(A) coordinated research projects, joint research projects, or joint ventures;

5(B) joint studies or technical demonstrations;

6(C) coordinated field exercises, scientific seminars, conferences, symposia, and workshops;

7(D) training of scientists and engineers;

8(E) visits and exchanges of scientists, engineers, or other appropriate personnel;

9(F) exchanges or sharing of scientific and technological information; and

10(G) joint use of laboratory facilities and equipment.

11The Under Secretary shall establish the Science and Technology Homeland Security International Cooperative Programs Office.

12The Office shall be headed by a Director, who—

13(A) shall be selected, in consultation with the Assistant Secretary for International Affairs, by and shall report to the Under Secretary; and

14(B) may be an officer of the Department serving in another position.

15The Director shall be responsible for developing, in coordination with the Department of State and, as appropriate, the Department of Defense, the Department of Energy, and other Federal agencies, understandings and agreements to allow and to support international cooperative activity in support of homeland security.

16The Director shall be responsible for developing, in coordination with the Office of International Affairs and other Federal agencies, strategic priorities for international cooperative activity for the Department in support of homeland security.

17The Director shall facilitate the planning, development, and implementation of international cooperative activity to address the strategic priorities developed under subparagraph (B) through mechanisms the Under Secretary considers appropriate, including grants, cooperative agreements, or contracts to or with foreign public or private entities, governmental organizations, businesses (including small businesses and socially and economically disadvantaged small businesses (as those terms are defined in sections 632 and 637 of title 15, respectively)), federally funded research and development centers, and universities.

18The Director shall facilitate the matching of United States entities engaged in homeland security research with non-United States entities engaged in homeland security research so that they may partner in homeland security research activities.

19The Director shall ensure that the activities under this subsection are coordinated with the Office of International Affairs and the Department of State and, as appropriate, the Department of Defense, the Department of Energy, and other relevant Federal agencies or interagency bodies. The Director may enter into joint activities with other Federal agencies.

20The Director shall ensure that funding and resources expended in international cooperative activity will be equitably matched by the foreign partner government or other entity through direct funding, funding of complementary activities, or the provision of staff, facilities, material, or equipment.

21The Secretary may require a recipient of a grant under this section—

22(I) to make a matching contribution of not more than 50 percent of the total cost of the proposed project for which the grant is awarded; and

23(II) to repay to the Secretary the amount of the grant (or a portion thereof), interest on such amount at an appropriate rate, and such charges for administration of the grant as the Secretary determines appropriate.

24The Secretary may not require that repayment under clause (i)(II) be more than 150 percent of the amount of the grant, adjusted for inflation on the basis of the Consumer Price Index.

25Partners may include Israel, the United Kingdom, Canada, Australia, Singapore, and other allies in the global war on terrorism as determined to be appropriate by the Secretary of Homeland Security and the Secretary of State.

26The Director may make or accept loans of equipment for research and development and comparative testing purposes.

27If the Science and Technology Homeland Security International Cooperative Programs Office participates in an international cooperative activity with a foreign partner on a cost-sharing basis, any reimbursements or contributions received from that foreign partner to meet its share of the project may be credited to appropriate current appropriations accounts of the Directorate of Science and Technology.

28Not later than one year after August 3, 2007, and every 5 years thereafter, the Under Secretary, acting through the Director, shall submit to Congress a report containing—

29(1) a brief description of each grant, cooperative agreement, or contract made or entered into under subsection (b)(3)(C), including the participants, goals, and amount and sources of funding;

30(2) a list of international cooperative activities underway, including the participants, goals, expected duration, and amount and sources of funding, including resources provided to support the activities in lieu of direct funding; and 1

31(3) for international cooperative activities identified in the previous reporting period, a status update on the progress of such activities, including whether goals were realized, explaining any lessons learned, and evaluating overall success; and

32(4) a discussion of obstacles encountered in the course of forming, executing, or implementing agreements for international cooperative activities, including administrative, legal, or diplomatic challenges or resource constraints.

33As part of the international cooperative activities authorized in this section, the Under Secretary, in coordination with the Assistant Secretary for the Countering Weapons of Mass Destruction Office, the Department of State, and appropriate officials of the Department of Agriculture, the Department of Defense, and the Department of Health and Human Services, may enter into cooperative activities with foreign countries, including African nations, to strengthen American preparedness against foreign animal and zoonotic diseases overseas that could harm the Nation's agricultural and public health sectors if they were to reach the United States.

34As part of the international cooperative activities authorized in this section, the Under Secretary, in coordination with the Department of State and appropriate Federal officials, may enter into cooperative research activities with Israel to strengthen preparedness against cyber threats and enhance capabilities in cybersecurity.

35Nothing in this section shall be construed to alter or affect the following provisions of law:

36(1) Title V of the Foreign Relations Authorization Act, Fiscal Year 1979 (22 U.S.C. 2656a et seq.).

37(2) Section 112b(g) of title 1.

38(3) Section 2651a(e)(2) of title 22.

39(4) Sections 2752 and 2767 of title 22.

40(5) Section 2382(c) of title 22.

41There are authorized to be appropriated to carry out this section such sums as are necessary.

195d.

Social media working group

1The Secretary shall establish within the Department a social media working group (in this section referred to as the "Group").

2In order to enhance the dissemination of information through social media technologies between the Department and appropriate stakeholders and to improve use of social media technologies in support of preparedness, response, and recovery, the Group shall identify, and provide guidance and best practices to the emergency preparedness and response community on, the use of social media technologies before, during, and after a natural disaster or an act of terrorism or other man-made disaster.

3Membership of the Group shall be composed of a cross section of subject matter experts from Federal, State, local, tribal, territorial, and nongovernmental organization practitioners, including representatives from the following entities:

4(A) The Office of Public Affairs of the Department.

5(B) The Office of the Chief Information Officer of the Department.

6(C) The Privacy Office of the Department.

7(D) The Federal Emergency Management Agency.

8(E) The Office of Disability Integration and Coordination of the Federal Emergency Management Agency.

9(F) The American Red Cross.

10(G) The Forest Service.

11(H) The Centers for Disease Control and Prevention.

12(I) The United States Geological Survey.

13(J) The National Oceanic and Atmospheric Administration.

14The Secretary, or a designee of the Secretary, shall serve as the chairperson of the Group.

15The chairperson shall designate, on a rotating basis, a representative from a State or local government who is a member of the Group to serve as the co-chairperson of the Group.

16The chairperson shall appoint, on a rotating basis, qualified individuals to the Group. The total number of such additional members shall—

17(A) be equal to or greater than the total number of regular members under paragraph (1); and

18(B) include—

19(i) not fewer than 3 representatives from the private sector; and

20(ii) representatives from—

21(I) State, local, tribal, and territorial entities, including from—

22(aa) law enforcement;

23(bb) fire services;

24(cc) emergency management; and

25(dd) public health entities;

26(II) universities and academia; and

27(III) nonprofit disaster relief organizations.

28The chairperson shall establish term limits for individuals appointed to the Group under paragraph (3).

29To the extent practicable, the Group shall work with entities in the public and private sectors to carry out subsection (b).

30Not later than 90 days after November 5, 2015, the Group shall hold its initial meeting.

31After the initial meeting under paragraph (1), the Group shall meet—

32(A) at the call of the chairperson; and

33(B) not less frequently than twice each year.

34Each meeting of the Group may be held virtually.

35During each year in which the Group meets, the Group shall submit to the appropriate congressional committees a report that includes the following:

36(1) A review and analysis of current and emerging social media technologies being used to support preparedness and response activities related to natural disasters and acts of terrorism and other man-made disasters.

37(2) A review of best practices and lessons learned on the use of social media technologies during the response to natural disasters and acts of terrorism and other man-made disasters that occurred during the period covered by the report at issue.

38(3) Recommendations to improve the Department's use of social media technologies for emergency management purposes.

39(4) Recommendations to improve public awareness of the type of information disseminated through social media technologies, and how to access such information, during a natural disaster or an act of terrorism or other man-made disaster.

40(5) A review of available training for Federal, State, local, tribal, and territorial officials on the use of social media technologies in response to a natural disaster or an act of terrorism or other man-made disaster.

41(6) A review of coordination efforts with the private sector to discuss and resolve legal, operational, technical, privacy, and security concerns.

42The Group shall terminate on the date that is 5 years after November 5, 2015, unless the chairperson renews the Group for a successive 5-year period, prior to the date on which the Group would otherwise terminate, by submitting to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a certification that the continued existence of the Group is necessary to fulfill the purpose described in subsection (b).

43The chairperson may continue to renew the Group for successive 5-year periods by submitting a certification in accordance with paragraph (1) prior to the date on which the Group would otherwise terminate.

195e.

Transparency in research and development

1The Secretary shall maintain a detailed list of the following:

2(A) Each classified and unclassified research and development project, and all appropriate details for each such project, including the component of the Department responsible for each such project.

3(B) Each task order for a Federally Funded Research and Development Center not associated with a research and development project.

4(C) Each task order for a University-based center of excellence not associated with a research and development project.

5(D) The indicators developed and tracked by the Under Secretary for Science and Technology with respect to transitioned projects pursuant to subsection (c).

6Paragraph (1) shall not apply to a project completed or otherwise terminated before December 23, 2016.

7The list required under paragraph (1) shall be updated as frequently as possible, but not less frequently than once per quarter.

8For purposes of the list required under paragraph (1), the Secretary shall provide a definition for the term "research and development".

9Not later than January 1, 2017, and annually thereafter, the Secretary shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a classified and unclassified report, as applicable, that lists each ongoing classified and unclassified project at the Department, including all appropriate details of each such project.

10For each project that has been transitioned to practice from research and development, the Under Secretary for Science and Technology shall develop and track indicators to demonstrate the uptake of the technology or project among customers or end-users.

11To the fullest extent possible, the tracking of a project required under paragraph (1) shall continue for the three-year period beginning on the date on which such project was transitioned to practice from research and development.

12In this section:

13The term "all appropriate details" means, with respect to a research and development project—

14(A) the name of such project, including both classified and unclassified names if applicable;

15(B) the name of the component of the Department carrying out such project;

16(C) an abstract or summary of such project;

17(D) funding levels for such project;

18(E) project duration or timeline;

19(F) the name of each contractor, grantee, or cooperative agreement partner involved in such project;

20(G) expected objectives and milestones for such project; and

21(H) to the maximum extent practicable, relevant literature and patents that are associated with such project.

22The term "classified" means anything containing—

23(A) classified national security information as defined in section 6.1 of Executive Order 13526 (50 U.S.C. 3161 note) or any successor order;

24(B) Restricted Data or data that was formerly Restricted Data, as defined in section 2014(y) of title 42;

25(C) material classified at the Sensitive Compartmented Information (SCI) level, as defined in section 3345 of title 50; or

26(D) information relating to a special access program, as defined in section 6.1 of Executive Order 13526 (50 U.S.C. 3161 note) or any successor order.

27The term "controlled unclassified information" means information described as "Controlled Unclassified Information" under Executive Order 13556 (50 U.S.C. 3501 note) 1 or any successor order.

28The term "project" means a research or development project, program, or activity administered by the Department, whether ongoing, completed, or otherwise terminated.

29Nothing in this section overrides or otherwise affects the requirements specified in section 468 of this title.

195f.

EMP and GMD mitigation research and development and threat assessment, response, and recovery

1In furtherance of domestic preparedness and response, the Secretary, acting through the Under Secretary for Science and Technology, and in consultation with other relevant executive agencies, relevant State, local, and tribal governments, and relevant owners and operators of critical infrastructure, shall, to the extent practicable, conduct research and development to mitigate the consequences of threats of EMP and GMD.

2The scope of the research and development under subsection (a) shall include the following:

3(1) An objective scientific analysis—

4(A) evaluating the risks to critical infrastructure from a range of threats of EMP and GMD; and

5(B) which shall—

6(i) be conducted in conjunction with the Office of Intelligence and Analysis; and

7(ii) include a review and comparison of the range of threats and hazards facing critical infrastructure of the electrical grid.

8(2) Determination of the critical utilities and national security assets and infrastructure that are at risk from threats of EMP and GMD.

9(3) An evaluation of emergency planning and response technologies that would address the findings and recommendations of experts, including those of the Commission to Assess the Threat to the United States from Electromagnetic Pulse Attack, which shall include a review of the feasibility of rapidly isolating one or more portions of the electrical grid from the main electrical grid.

10(4) An analysis of technology options that are available to improve the resiliency of critical infrastructure to threats of EMP and GMD, including an analysis of neutral current blocking devices that may protect high-voltage transmission lines.

11(5) The restoration and recovery capabilities of critical infrastructure under differing levels of damage and disruption from various threats of EMP and GMD, as informed by the objective scientific analysis conducted under paragraph (1).

12(6) An analysis of the feasibility of a real-time alert system to inform electrical grid operators and other stakeholders within milliseconds of a high-altitude nuclear explosion.

13Section 673 of this title, and any regulations issued pursuant to such section, shall apply to any information shared with the Federal Government under this section.

14Information shared by the Federal Government with a State, local, or tribal government under this section shall be exempt from disclosure under any provision of State, local, or tribal freedom of information law, open government law, open meetings law, open records law, sunshine law, or similar law requiring the disclosure of information or records.

15Beginning not later than June 19, 2020, the Secretary shall provide timely distribution of information on EMPs and GMDs to Federal, State, and local governments, owners and operators of critical infrastructure, and other persons determined appropriate by the Secretary.

16The Secretary shall brief the appropriate congressional committees on the effectiveness of the distribution of information under clause (i).

17The Administrator of the Federal Emergency Management Agency shall—

18(I) coordinate the response to and recovery from the effects of EMPs and GMDs on critical infrastructure, in coordination with the heads of appropriate Sector-Specific Agencies, and on matters related to the bulk power system, in consultation with the Secretary of Energy and the Federal Energy Regulatory Commission; and

19(II) to the extent practicable, incorporate events that include EMPs and extreme GMDs as a factor in preparedness scenarios and exercises.

20The Administrator of the Federal Emergency Management Agency, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, and on matters related to the bulk power system, the Secretary of Energy and the Federal Energy Regulatory Commission, shall—

21(I) not later than June 19, 2020, develop plans and procedures to coordinate the response to and recovery from EMP and GMD events; and

22(II) not later than December 21, 2020, conduct a national exercise to test the preparedness and response of the Nation to the effect of an EMP or extreme GMD event.

23The Secretary, in coordination with the heads of relevant Sector-Specific Agencies, shall—

24(I) without duplication of existing or ongoing efforts, conduct research and development to better understand and more effectively model the effects of EMPs and GMDs on critical infrastructure (which shall not include any system or infrastructure of the Department of Defense or any system or infrastructure of the Department of Energy associated with nuclear weapons activities); and

25(II) develop technologies to enhance the resilience of and better protect critical infrastructure.

26Not later than March 26, 2020, and in coordination with the heads of relevant Sector-Specific Agencies, the Secretary shall submit to the appropriate congressional committees a research and development action plan to rapidly address modeling shortfall and technology development.

27The Administrator of the Federal Emergency Management Agency, in coordination with relevant stakeholders, shall maintain a network of systems, such as the alerting capabilities of the integrated public alert and warning system authorized under section 321o of this title, that are capable of providing appropriate emergency information to the public before (if possible), during, and in the aftermath of an EMP or GMD.

28Not later than December 21, 2020, the Administrator of the Federal Emergency Management Agency, shall brief the appropriate congressional committees regarding the maintenance of systems, including the alerting capabilities of the integrated public alert and warning system authorized under section 321o of this title.

29The Secretary, in coordination with the Secretary of Defense, the Secretary of Energy, and the Secretary of Commerce, and informed by intelligence-based threat assessments, shall conduct a quadrennial EMP and GMD risk assessment.

30Not later than March 26, 2020, and every four years thereafter until 2032, the Secretary, the Secretary of Defense, the Secretary of Energy, and the Secretary of Commerce shall provide a briefing to the appropriate congressional committees regarding the quadrennial EMP and GMD risk assessment.

31The Secretary, in coordination with the Secretary of Defense, the Secretary of Energy, the Secretary of Commerce, and the heads of other relevant Sector-Specific Agencies, shall use the results of the quadrennial EMP and GMD risk assessments to better understand and to improve resilience to the effects of EMPs and GMDs across all critical infrastructure sectors, including coordinating the prioritization of critical infrastructure at greatest risk to the effects of EMPs and GMDs.

32Not later than December 21, 2020, and every four years thereafter until 2032, the Secretary, in coordination with the Secretary of Defense, the Secretary of Energy, the heads of other appropriate agencies, and, as appropriate, private-sector partners, shall submit to the appropriate congressional committees, a report that—

33(i) assesses the technological options available to improve the resilience of critical infrastructure to the effects of EMPs and GMDs; and

34(ii) identifies gaps in available technologies and opportunities for technological developments to inform research and development activities.

35Not later than December 20, 2020, the Secretary, in coordination with the heads of Sector-Specific Agencies, the Secretary of Defense, and the Secretary of Energy, shall—

36(I) review test data regarding the effects of EMPs and GMDs on critical infrastructure systems, networks, and assets representative of those throughout the Nation; and

37(II) identify any gaps in the test data.

38Not later than 180 days after identifying gaps in test data under clause (i), the Secretary, in coordination with the heads of Sector-Specific Agencies and in consultation with the Secretary of Defense and the Secretary of Energy, shall use the sector partnership structure identified in the National Infrastructure Protection Plan to develop an integrated cross-sector plan to address the identified gaps.

39The heads of each agency identified in the plan developed under clause (ii) shall implement the plan in collaboration with the voluntary efforts of the private sector, as appropriate.

40In this subsection:

41(A) The term "appropriate congressional committees" means—

42(i) the Committee on Homeland Security and Governmental Affairs, the Committee on Armed Services, the Committee on Energy and Natural Resources, and the Committee on Commerce, Science, and Transportation of the Senate; and

43(ii) the Committee on Transportation and Infrastructure, the Committee on Homeland Security, the Committee on Armed Services, the Committee on Energy and Commerce, and the Committee on Science, Space and Technology of the House of Representatives.

44(B) The terms "prepare" and "preparedness" mean the actions taken to plan, organize, equip, train, and exercise to build and sustain the capabilities necessary to prevent, protect against, mitigate the effects of, respond to, and recover from those threats that pose the greatest risk to the security of the homeland, including the prediction and notification of impending EMPs and GMDs.

45(C) The term "Sector Risk Management Agency" has the meaning given that term in section 650 of this title.

46Nothing in this section may be construe— 1

47(1) to affect in any manner the authority of the executive branch to implement Executive Order 13865, dated March 26, 2019, and entitled "Coordinating National Resilience to Electromagnetic Pulses", or any other authority existing on the day before December 20, 2019, of any other component of the Department or any other Federal department or agency, including the authority provided to the Sector Risk Management Agency specified in section 61003(c) of division F of the Fixing America's Surface Transportation Act (6 U.S.C. 121 note), including the authority under section 824o of title 16, and including the authority of independent agencies to be independent; or

48(2) as diminishing or transferring any authorities vested in the Administrator of the Federal Emergency Management Agency or in the Agency prior to December 20, 2019.

195g.

Countering Unmanned Aircraft Systems Coordinator

1The Secretary shall designate an individual in a Senior Executive Service position (as defined in section 3132 of title 5) of the Department within the Office of Strategy, Policy, and Plans as the Countering Unmanned Aircraft Systems Coordinator (in this section referred to as the "Coordinator") and provide appropriate staff to carry out the responsibilities of the Coordinator.

2The Coordinator shall—

3(A) oversee and coordinate with relevant Department offices and components, including the Office of Civil Rights and Civil Liberties and the Privacy Office, on the development of guidance and regulations to counter threats associated with unmanned aircraft systems (in this section referred to as "UAS") as described in section 124n of this title;

4(B) promote research and development of counter UAS technologies in coordination within the Science and Technology Directorate;

5(C) coordinate with the relevant components and offices of the Department, including the Office of Intelligence and Analysis, to ensure the sharing of information, guidance, and intelligence relating to countering UAS threats, counter UAS threat assessments, and counter UAS technology, including the retention of UAS and counter UAS incidents within the Department;

6(D) serve as the Department liaison, in coordination with relevant components and offices of the Department, to the Department of Defense, Federal, State, local, and Tribal law enforcement entities, and the private sector regarding the activities of the Department relating to countering UAS;

7(E) maintain the information required under section 124n(g)(3) of this title; and

8(F) carry out other related counter UAS authorities and activities under section 124n of this title, as directed by the Secretary.

9The Coordinator shall, in addition to other assigned duties, coordinate with relevant Department components and offices to ensure testing, evaluation, or deployment of a system used to identify, assess, or defeat a UAS is carried out in accordance with applicable Federal laws.

10The Coordinator shall, among other assigned duties, working with the Office of Partnership and Engagement and other relevant Department offices and components, or other Federal agencies, as appropriate, serve as the principal Department official responsible for sharing to the private sector information regarding counter UAS technology, particularly information regarding instances in which counter UAS technology may impact lawful private sector services or systems.

195h.

National Urban Security Technology Laboratory

1The Secretary, acting through the Under Secretary for Science and Technology, shall designate the laboratory described in subsection (b) as an additional laboratory pursuant to the authority under section 188(c)(2) of this title. Such laboratory shall be used to test and evaluate emerging technologies and conduct research and development to assist emergency response providers in preparing for, and protecting against, threats of terrorism.

2The laboratory described in this subsection is the laboratory—

3(1) known, as of December 27, 2021, as the National Urban Security Technology Laboratory; and

4(2) transferred to the Department pursuant to section 183(1)(E) of this title.

5The National Urban Security Technology Laboratory shall—

6(1) conduct tests, evaluations, and assessments of current and emerging technologies, including, as appropriate, the cybersecurity of such technologies that can connect to the internet, for emergency response providers;

7(2) act as a technical advisor to emergency response providers; and

8(3) carry out other such activities as the Secretary determines appropriate.

9Nothing in this section may be construed as affecting in any manner the authorities or responsibilities of the Countering Weapons of Mass Destruction Office of the Department.

195i.

Chemical Security Analysis Center

1The Secretary, acting through the Under Secretary for Science and Technology, shall designate the laboratory described in subsection (b) as an additional laboratory pursuant to the authority under section 188(c)(2) of this title, which shall be used to conduct studies, analyses, and research to assess and address domestic chemical security events.

2The laboratory described in this subsection is the laboratory known, as of December 23, 2022, as the Chemical Security Analysis Center.

3Pursuant to the authority under section 182(4) of this title, the Chemical Security Analysis Center shall—

4(1) identify and develop approaches and mitigation strategies to domestic chemical security threats, including the development of comprehensive, research-based definable goals relating to such approaches and mitigation strategies;

5(2) provide an enduring science-based chemical threat and hazard analysis capability;

6(3) provide expertise regarding risk and consequence modeling, chemical sensing and detection, analytical chemistry, acute chemical toxicology, synthetic chemistry and reaction characterization, and nontraditional chemical agents and emerging chemical threats;

7(4) staff and operate a technical assistance program that provides operational support and subject matter expertise, design and execute laboratory and field tests, and provide a comprehensive knowledge repository of chemical threat information that is continuously updated with data from scientific, intelligence, operational, and private sector sources;

8(5) consult, as appropriate, with the Countering Weapons of Mass Destruction Office of the Department to mitigate, prepare, and respond to threats, hazards, and risks associated with domestic chemical security events; and

9(6) carry out such other activities authorized under this section as the Secretary determines appropriate.

10Nothing in this section amends, alters, or affects—

11(1) the responsibilities of the Countering Weapons of Mass Destruction Office of the Department; or

12(2) the activities or requirements authorized to other entities within the Federal Government, including the activities and requirements of the Environmental Protection Agency under section 7412(r) of title 42, the Toxic Substances Control Act (15 U.S.C. 2601 et seq.), and the Comprehensive Environmental Response, Compensation, and Liability Act of 1980 (commonly referred to as "Superfund"; 42 U.S.C. 9601 et seq.).

201.

Repealed. Pub. L. 114–125, title VIII, §802(g)(2), Feb. 24, 2016, 130 Stat. 212

202.

Border, maritime, and transportation responsibilities

1The Secretary shall be responsible for the following:

2(1) Preventing the entry of terrorists and the instruments of terrorism into the United States.

3(2) Securing the borders, territorial waters, ports, terminals, waterways, and air, land, and sea transportation systems of the United States, including managing and coordinating those functions transferred to the Department at ports of entry.

4(3) Carrying out the immigration enforcement functions vested by statute in, or performed by, the Commissioner of Immigration and Naturalization (or any officer, employee, or component of the Immigration and Naturalization Service) immediately before the date on which the transfer of functions specified under section 251 of this title takes effect.

5(4) Establishing and administering rules, in accordance with section 236 of this title, governing the granting of visas or other forms of permission, including parole, to enter the United States to individuals who are not a citizen or an alien lawfully admitted for permanent residence in the United States.

6(5) Establishing national immigration enforcement policies and priorities.

7(6) Except as provided in part C of this subchapter, administering the customs laws of the United States.

8(7) Conducting the inspection and related administrative functions of the Department of Agriculture transferred to the Secretary of Homeland Security under section 231 of this title.

9(8) In carrying out the foregoing responsibilities, ensuring the speedy, orderly, and efficient flow of lawful traffic and commerce.

203.

Functions transferred

1In accordance with subchapter XII (relating to transition provisions), there shall be transferred to the Secretary the functions, personnel, assets, and liabilities of—

2(1) the United States Customs Service of the Department of the Treasury, including the functions of the Secretary of the Treasury relating thereto;

3(2) the Transportation Security Administration of the Department of Transportation, including the functions of the Secretary of Transportation, and of the Under Secretary of Transportation for Security, relating thereto;

4(3) the Federal Protective Service of the General Services Administration, including the functions of the Administrator of General Services relating thereto;

5(4) the Federal Law Enforcement Training Center of the Department of the Treasury; and

6(5) the Office for Domestic Preparedness of the Office of Justice Programs, including the functions of the Attorney General relating thereto.

204.

Surface Transportation Security Advisory Committee

1The Administrator of the Transportation Security Administration (referred to in this section as "Administrator") shall establish within the Transportation Security Administration the Surface Transportation Security Advisory Committee (referred to in this section as the "Advisory Committee").

2The Advisory Committee may advise, consult with, report to, and make recommendations to the Administrator on surface transportation security matters, including the development, refinement, and implementation of policies, programs, initiatives, rulemakings, and security directives pertaining to surface transportation security.

3The Advisory Committee shall consider risk-based security approaches in the performance of its duties.

4The Advisory Committee shall be composed of—

5(A) voting members appointed by the Administrator under paragraph (2); and

6(B) nonvoting members, serving in an advisory capacity, who shall be designated by—

7(i) the Transportation Security Administration;

8(ii) the Department of Transportation;

9(iii) the Coast Guard; and

10(iv) such other Federal department or agency as the Administrator considers appropriate.

11The Administrator shall appoint voting members from among stakeholders representing each mode of surface transportation, such as passenger rail, freight rail, mass transit, pipelines, highways, over-the-road bus, school bus industry, and trucking, including representatives from—

12(A) associations representing such modes of surface transportation;

13(B) labor organizations representing such modes of surface transportation;

14(C) groups representing the users of such modes of surface transportation, including asset manufacturers, as appropriate;

15(D) relevant law enforcement, first responders, and security experts; and

16(E) such other groups as the Administrator considers appropriate.

17The Advisory Committee shall select a chairperson from among its voting members.

18The term of each voting member of the Advisory Committee shall be 2 years, but a voting member may continue to serve until the Administrator appoints a successor.

19A voting member of the Advisory Committee may be reappointed.

20The Administrator may review the participation of a member of the Advisory Committee and remove such member for cause at any time.

21The Administrator may remove any member of the Advisory Committee that the Administrator determines should be restricted from reviewing, discussing, or possessing classified information or sensitive security information.

22The members of the Advisory Committee shall not receive any compensation from the Government by reason of their service on the Advisory Committee.

23The Administrator shall require the Advisory Committee to meet at least semiannually in person or through web conferencing and may convene additional meetings as necessary.

24At least 1 of the meetings of the Advisory Committee each year shall be—

25(i) announced in the Federal Register;

26(ii) announced on a public website; and

27(iii) open to the public.

28The Advisory Committee shall maintain a record of the persons present at each meeting.

29Unless otherwise prohibited by other Federal law, minutes of the meetings shall be published on the public website under subsection (e)(5).

30The Advisory Committee may redact or summarize, as necessary, minutes of the meetings to protect classified or other sensitive information in accordance with law.

31Not later than 60 days after the date on which a voting member is appointed to the Advisory Committee and before that voting member may be granted any access to classified information or sensitive security information, the Administrator shall determine if the voting member should be restricted from reviewing, discussing, or possessing classified information or sensitive security information.

32If a voting member is not restricted from reviewing, discussing, or possessing sensitive security information under subparagraph (A) and voluntarily signs a nondisclosure agreement, the voting member may be granted access to sensitive security information that is relevant to the voting member's service on the Advisory Committee.

33Access to classified materials shall be managed in accordance with Executive Order 13526 of December 29, 2009 (75 Fed. Reg. 707), or any subsequent corresponding Executive order.

34Voting members shall protect sensitive security information in accordance with part 1520 of title 49, Code of Federal Regulations.

35Voting members shall protect classified information in accordance with the applicable requirements for the particular level of classification.

36The Advisory Committee may meet with 1 or more of the following advisory committees to discuss multimodal security issues and other security-related issues of common concern:

37(A) Aviation Security Advisory Committee established under section 44946 of title 49.

38(B) Maritime Security Advisory Committee established under section 70112 of title 46.

39(C) Railroad Safety Advisory Committee established by the Federal Railroad Administration.

40The Advisory Committee may request the assistance of subject matter experts with expertise related to the jurisdiction of the Advisory Committee.

41The Advisory Committee shall periodically submit reports to the Administrator on matters requested by the Administrator or by a majority of the members of the Advisory Committee.

42The Advisory Committee shall submit to the Administrator and the appropriate congressional committees an annual report that provides information on the activities, findings, and recommendations of the Advisory Committee during the preceding year.

43Not later than 6 months after the date that the Administrator receives an annual report under subparagraph (A), the Administrator shall publish a public version of the report, in accordance with section 552a(b) of title 5.

44The Administrator shall consider the information, advice, and recommendations of the Advisory Committee in formulating policies, programs, initiatives, rulemakings, and security directives pertaining to surface transportation security.

45Not later than 90 days after the date that the Administrator receives a recommendation from the Advisory Committee under subsection (d)(2), the Administrator shall submit to the Advisory Committee written feedback on the recommendation, including—

46(A) if the Administrator agrees with the recommendation, a plan describing the actions that the Administrator has taken, will take, or recommends that the head of another Federal department or agency take to implement the recommendation; or

47(B) if the Administrator disagrees with the recommendation, a justification for that determination.

48Not later than 30 days after the date the Administrator submits feedback under paragraph (2), the Administrator shall—

49(A) notify the appropriate congressional committees of the feedback, including the determination under subparagraph (A) or subparagraph (B) of that paragraph, as applicable; and

50(B) provide the appropriate congressional committees with a briefing upon request.

51Not later than 90 days after the date the Administrator receives a recommendation from the Advisory Committee under subsection (d)(2) that the Administrator agrees with, and quarterly thereafter until the recommendation is fully implemented, the Administrator shall submit a report to the appropriate congressional committees or post on the public website under paragraph (5) an update on the status of the recommendation.

52The Administrator shall maintain a public website that—

53(A) lists the members of the Advisory Committee; and

54(B) provides the contact information for the Advisory Committee.

55The Federal Advisory Committee Act (5 U.S.C. App.) 1 shall not apply to the Advisory Committee or any subcommittee established under this section.

205.

Ombudsman for immigration detention

1Within the Department, there shall be a position of Immigration Detention Ombudsman (in this section referred to as the "Ombudsman"). The Ombudsman shall be independent of Department agencies and officers and shall report directly to the Secretary. The Ombudsman shall be a senior official with a background in civil rights enforcement, civil detention care and custody, and immigration law.

2The functions of the Ombudsman shall be to—

3(1) Establish and administer an independent, neutral, and confidential process to receive, investigate, resolve, and provide redress, including referral for investigation to the Office of the Inspector General, referral to U.S. Citizenship and Immigration Services for immigration relief, or any other action determined appropriate, for cases in which Department officers or other personnel, or contracted, subcontracted, or cooperating entity personnel, are found to have engaged in misconduct or violated the rights of individuals in immigration detention;

4(2) Establish an accessible and standardized process regarding complaints against any officer or employee of U.S. Customs and Border Protection or U.S. Immigration and Customs Enforcement, or any contracted, subcontracted, or cooperating entity personnel, for violations of law, standards of professional conduct, contract terms, or policy related to immigration detention;

5(3) Conduct unannounced inspections of detention facilities holding individuals in federal immigration custody, including those owned or operated by units of State or local government and privately-owned or operated facilities;

6(4) Review, examine, and make recommendations to address concerns or violations of contract terms identified in reviews, audits, investigations, or detainee interviews regarding immigration detention facilities and services;

7(5) Provide assistance to individuals affected by potential misconduct, excessive force, or violations of law or detention standards by Department of Homeland Security officers or other personnel, or contracted, subcontracted, or cooperating entity personnel; and

8(6) Ensure that the functions performed by the Ombudsman are complementary to existing functions within the Department of Homeland Security.

9The Ombudsman or designated personnel of the Ombudsman, shall be provided unfettered access to any location within each such detention facility and shall be permitted confidential access to any detainee at the detainee's request and any departmental records concerning such detainee.

10The Director of U.S. Immigration and Customs Enforcement and the Commissioner of U.S. Customs and Border Protection shall each establish procedures to provide formal responses to recommendations submitted to such officials by the Ombudsman within 60 days of receiving such recommendations.

11The Secretary shall establish procedures to provide the Ombudsman access to all departmental records necessary to execute the responsibilities of the Ombudsman under subsection (b) or (c) not later than 60 days after a request from the Ombudsman for such information.

12The Ombudsman shall prepare a report to Congress on an annual basis on its activities, findings, and recommendations.

211.

Establishment of U.S. Customs and Border Protection; Commissioner, Deputy Commissioner, and operational offices

1There is established in the Department an agency to be known as U.S. Customs and Border Protection.

2There shall be at the head of U.S. Customs and Border Protection a Commissioner of U.S. Customs and Border Protection (in this section referred to as the "Commissioner").

3As an exercise of the rulemaking power of the Senate, any nomination for the Commissioner submitted to the Senate for confirmation, and referred to a committee, shall be referred to the Committee on Finance.

4The Commissioner shall—

5(1) coordinate and integrate the security, trade facilitation, and trade enforcement functions of U.S. Customs and Border Protection;

6(2) ensure the interdiction of persons and goods illegally entering or exiting the United States;

7(3) facilitate and expedite the flow of legitimate travelers and trade;

8(4) direct and administer the commercial operations of U.S. Customs and Border Protection, and the enforcement of the customs and trade laws of the United States;

9(5) detect, respond to, and interdict terrorists, drug smugglers and traffickers, human smugglers and traffickers, and other persons who may undermine the security of the United States, in cases in which such persons are entering, or have recently entered, the United States;

10(6) safeguard the borders of the United States to protect against the entry of dangerous goods;

11(7) ensure the overall economic security of the United States is not diminished by efforts, activities, and programs aimed at securing the homeland;

12(8) in coordination with U.S. Immigration and Customs Enforcement and United States Citizenship and Immigration Services, enforce and administer all immigration laws, as such term is defined in paragraph (17) of section 1101(a) of title 8, including—

13(A) the inspection, processing, and admission of persons who seek to enter or depart the United States; and

14(B) the detection, interdiction, removal, departure from the United States, short-term detention, and transfer of persons unlawfully entering, or who have recently unlawfully entered, the United States;

15(9) develop and implement screening and targeting capabilities, including the screening, reviewing, identifying, and prioritizing of passengers and cargo across all international modes of transportation, both inbound and outbound;

16(10) in coordination with the Secretary, deploy technology to collect the data necessary for the Secretary to administer the biometric entry and exit data system pursuant to section 1365b of title 8;

17(11) enforce and administer the laws relating to agricultural import and entry inspection referred to in section 231 of this title;

18(12) in coordination with the Under Secretary for Management of the Department, ensure U.S. Customs and Border Protection complies with Federal law, the Federal Acquisition Regulation, and the Department's acquisition management directives for major acquisition programs of U.S. Customs and Border Protection;

19(13) ensure that the policies and regulations of U.S. Customs and Border Protection are consistent with the obligations of the United States pursuant to international agreements;

20(14) enforce and administer—

21(A) the Container Security Initiative program under section 205 of the Security and Accountability for Every Port Act of 2006 (6 U.S.C. 945); and

22(B) the Customs–Trade Partnership Against Terrorism program under subtitle B of title II of such Act (6 U.S.C. 961 et seq.);

23(15) conduct polygraph examinations in accordance with section 221(1) of this title;

24(16) establish the standard operating procedures described in subsection (k);

25(17) carry out the training required under subsection (l);

26(18) carry out section 218 of this title, relating to the issuance of Asia-Pacific Economic Cooperation Business Travel Cards; and

27(19) carry out other duties and powers prescribed by law or delegated by the Secretary.

28There shall be in U.S. Customs and Border Protection a Deputy Commissioner who shall assist the Commissioner in the management of U.S. Customs and Border Protection.

29There is established in U.S. Customs and Border Protection the U.S. Border Patrol.

30There shall be at the head of the U.S. Border Patrol a Chief, who shall—

31(A) be at the level of Executive Assistant Commissioner within U.S. Customs and Border Protection; and

32(B) report to the Commissioner.

33The U.S. Border Patrol shall—

34(A) serve as the law enforcement office of U.S. Customs and Border Protection with primary responsibility for interdicting persons attempting to illegally enter or exit the United States or goods being illegally imported into or exported from the United States at a place other than a designated port of entry;

35(B) deter and prevent the illegal entry of terrorists, terrorist weapons, persons, and contraband; and

36(C) carry out other duties and powers prescribed by the Commissioner.

37There is established in U.S. Customs and Border Protection an office known as Air and Marine Operations.

38There shall be at the head of Air and Marine Operations an Executive Assistant Commissioner, who shall report to the Commissioner.

39Air and Marine Operations shall—

40(A) serve as the law enforcement office within U.S. Customs and Border Protection with primary responsibility to detect, interdict, and prevent acts of terrorism and the unlawful movement of people, illicit drugs, and other contraband across the borders of the United States in the air and maritime environment;

41(B) conduct joint aviation and marine operations with U.S. Immigration and Customs Enforcement;

42(C) conduct aviation and marine operations with international, Federal, State, and local law enforcement agencies, as appropriate;

43(D) administer the Air and Marine Operations Center established under paragraph (4); and

44(E) carry out other duties and powers prescribed by the Commissioner.

45There is established in Air and Marine Operations an Air and Marine Operations Center.

46There shall be at the head of the Air and Marine Operations Center an Executive Director, who shall report to the Executive Assistant Commissioner of Air and Marine Operations.

47The Air and Marine Operations Center shall—

48(i) manage the air and maritime domain awareness of the Department, as directed by the Secretary;

49(ii) monitor and coordinate the airspace for unmanned aerial systems operations of Air and Marine Operations in U.S. Customs and Border Protection;

50(iii) detect, identify, and coordinate a response to threats to national security in the air domain, in coordination with other appropriate agencies, as determined by the Executive Assistant Commissioner;

51(iv) provide aviation and marine support to other Federal, State, tribal, and local agencies; and

52(v) carry out other duties and powers prescribed by the Executive Assistant Commissioner.

53There is established in U.S. Customs and Border Protection an Office of Field Operations.

54There shall be at the head of the Office of Field Operations an Executive Assistant Commissioner, who shall report to the Commissioner.

55The Office of Field Operations shall coordinate the enforcement activities of U.S. Customs and Border Protection at United States air, land, and sea ports of entry to—

56(A) deter and prevent terrorists and terrorist weapons from entering the United States at such ports of entry;

57(B) conduct inspections at such ports of entry to safeguard the United States from terrorism and illegal entry of persons;

58(C) prevent illicit drugs, agricultural pests, and contraband from entering the United States;

59(D) in coordination with the Commissioner, facilitate and expedite the flow of legitimate travelers and trade;

60(E) administer the National Targeting Center established under paragraph (4);

61(F) coordinate with the Executive Assistant Commissioner for the Office of Trade with respect to the trade facilitation and trade enforcement activities of U.S. Customs and Border Protection; and

62(G) carry out other duties and powers prescribed by the Commissioner.

63There is established in the Office of Field Operations a National Targeting Center.

64There shall be at the head of the National Targeting Center an Executive Director, who shall report to the Executive Assistant Commissioner of the Office of Field Operations.

65The National Targeting Center shall—

66(i) serve as the primary forum for targeting operations within U.S. Customs and Border Protection to collect and analyze traveler and cargo information in advance of arrival in the United States to identify and address security risks and strengthen trade enforcement;

67(ii) identify, review, and target travelers and cargo for examination;

68(iii) coordinate the examination of entry and exit of travelers and cargo;

69(iv) develop and conduct commercial risk assessment targeting with respect to cargo destined for the United States;

70(v) coordinate with the Transportation Security Administration, as appropriate;

71(vi) issue Trade Alerts pursuant to section 4318(b) of title 19; and

72(vii) carry out other duties and powers prescribed by the Executive Assistant Commissioner.

73Not later than 30 days after February 24, 2016, and annually thereafter, the Executive Assistant Commissioner shall submit to the Committee on Homeland Security and the Committee on Ways and Means of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Finance of the Senate a report on the staffing model for the Office of Field Operations, including information on how many supervisors, front-line U.S. Customs and Border Protection officers, and support personnel are assigned to each Field Office and port of entry.

74The report required under subparagraph (A) shall, to the greatest extent practicable, be submitted in unclassified form, but may be submitted in classified form, if the Executive Assistant Commissioner determines that such is appropriate and informs the Committee on Homeland Security and the Committee on Ways and Means of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Finance of the Senate of the reasoning for such.

75There is established in U.S. Customs and Border Protection an Office of Intelligence.

76There shall be at the head of the Office of Intelligence an Assistant Commissioner, who shall report to the Commissioner.

77The Office of Intelligence shall—

78(A) develop, provide, coordinate, and implement intelligence capabilities into a cohesive intelligence enterprise to support the execution of the duties and responsibilities of U.S. Customs and Border Protection;

79(B) manage the counterintelligence operations of U.S. Customs and Border Protection;

80(C) establish, in coordination with the Chief Intelligence Officer of the Department, as appropriate, intelligence-sharing relationships with Federal, State, local, and tribal agencies and intelligence agencies;

81(D) conduct risk-based covert testing of U.S. Customs and Border Protection operations, including for nuclear and radiological risks; and

82(E) carry out other duties and powers prescribed by the Commissioner.

83There is established in U.S. Customs and Border Protection an Office of International Affairs.

84There shall be at the head of the Office of International Affairs an Assistant Commissioner, who shall report to the Commissioner.

85The Office of International Affairs, in collaboration with the Office of Policy of the Department, shall—

86(A) coordinate and support U.S. Customs and Border Protection's foreign initiatives, policies, programs, and activities;

87(B) coordinate and support U.S. Customs and Border Protection's personnel stationed abroad;

88(C) maintain partnerships and information-sharing agreements and arrangements with foreign governments, international organizations, and United States agencies in support of U.S. Customs and Border Protection's duties and responsibilities;

89(D) provide necessary capacity building, training, and assistance to foreign customs and border control agencies to strengthen border, global supply chain, and travel security, as appropriate;

90(E) coordinate mission support services to sustain U.S. Customs and Border Protection's global activities;

91(F) coordinate with customs authorities of foreign countries with respect to trade facilitation and trade enforcement;

92(G) coordinate U.S. Customs and Border Protection's engagement in international negotiations;

93(H) advise the Commissioner with respect to matters arising in the World Customs Organization and other international organizations as such matters relate to the policies and procedures of U.S. Customs and Border Protection;

94(I) advise the Commissioner regarding international agreements to which the United States is a party as such agreements relate to the policies and regulations of U.S. Customs and Border Protection; and

95(J) carry out other duties and powers prescribed by the Commissioner.

96There is established in U.S. Customs and Border Protection an Office of Professional Responsibility.

97There shall be at the head of the Office of Professional Responsibility an Assistant Commissioner, who shall report to the Commissioner.

98The Office of Professional Responsibility shall—

99(A) investigate criminal and administrative matters and misconduct by officers, agents, and other employees of U.S. Customs and Border Protection;

100(B) manage integrity-related programs and policies of U.S. Customs and Border Protection;

101(C) conduct research and analysis regarding misconduct of officers, agents, and other employees of U.S. Customs and Border Protection; and

102(D) carry out other duties and powers prescribed by the Commissioner.

103The Commissioner shall establish—

104(A) standard operating procedures for searching, reviewing, retaining, and sharing information contained in communication, electronic, or digital devices encountered by U.S. Customs and Border Protection personnel at United States ports of entry;

105(B) standard use of force procedures that officers and agents of U.S. Customs and Border Protection may employ in the execution of their duties, including the use of deadly force;

106(C) uniform, standardized, and publicly-available procedures for processing and investigating complaints against officers, agents, and employees of U.S. Customs and Border Protection for violations of professional conduct, including the timely disposition of complaints and a written notification to the complainant of the status or outcome, as appropriate, of the related investigation, in accordance with section 552a of title 5 (commonly referred to as the "Privacy Act" or the "Privacy Act of 1974");

107(D) an internal, uniform reporting mechanism regarding incidents involving the use of deadly force by an officer or agent of U.S. Customs and Border Protection, including an evaluation of the degree to which the procedures required under subparagraph (B) were followed; and

108(E) standard operating procedures, acting through the Executive Assistant Commissioner for Air and Marine Operations and in coordination with the Office for Civil Rights and Civil Liberties and the Office of Privacy of the Department, to provide command, control, communication, surveillance, and reconnaissance assistance through the use of unmanned aerial systems, including the establishment of—

109(i) a process for other Federal, State, and local law enforcement agencies to submit mission requests;

110(ii) a formal procedure to determine whether to approve or deny such a mission request;

111(iii) a formal procedure to determine how such mission requests are prioritized and coordinated; and

112(iv) a process regarding the protection and privacy of data and images collected by U.S. Customs and Border Protection through the use of unmanned aerial systems.

113The standard operating procedures established pursuant to subparagraph (A) of paragraph (1) shall require—

114(A) in the case of a search of information conducted on an electronic device by U.S. Customs and Border Protection personnel, the Commissioner to notify the individual subject to such search of the purpose and authority for such search, and how such individual may obtain information on reporting concerns about such search; and

115(B) in the case of information collected by U.S. Customs and Border Protection through a search of an electronic device, if such information is transmitted to another Federal agency for subject matter assistance, translation, or decryption, the Commissioner to notify the individual subject to such search of such transmission.

116The Commissioner may withhold the notifications required under paragraphs (1)(C) and (2) if the Commissioner determines, in the sole and unreviewable discretion of the Commissioner, that such notifications would impair national security, law enforcement, or other operational interests.

117The Commissioner shall review and update every three years the standard operating procedures required under this subsection.

118The Inspector General of the Department of Homeland Security shall develop and annually administer, during each of the three calendar years beginning in the calendar year that begins after February 24, 2016, an auditing mechanism to review whether searches of electronic devices at or between United States ports of entry are being conducted in conformity with the standard operating procedures required under subparagraph (A) of paragraph (1). Such audits shall be submitted to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate and shall include the following:

119(A) A description of the activities of officers and agents of U.S. Customs and Border Protection with respect to such searches.

120(B) The number of such searches.

121(C) The number of instances in which information contained in such devices that were subjected to such searches was retained, copied, shared, or entered in an electronic database.

122(D) The number of such devices detained as the result of such searches.

123(E) The number of instances in which information collected from such devices was subjected to such searches and was transmitted to another Federal agency, including whether such transmissions resulted in a prosecution or conviction.

124The standard use of force procedures established pursuant to subparagraph (B) of paragraph (1) shall require—

125(A) in the case of an incident of the use of deadly force by U.S. Customs and Border Protection personnel, the Commissioner to notify the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate; and

126(B) the Commissioner to provide to such committees a copy of the evaluation pursuant to subparagraph (D) of such paragraph not later than 30 days after completion of such evaluation.

127The Commissioner shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate an annual report, for each of the three calendar years beginning in the calendar year that begins after February 24, 2016, that reviews whether the use of unmanned aerial systems is being conducted in conformity with the standard operating procedures required under subparagraph (E) of paragraph (1). Such reports—

128(A) shall be submitted with the annual budget of the United States Government submitted by the President under section 1105 of title 31;

129(B) may be submitted in classified form if the Commissioner determines that such is appropriate; and

130(C) shall include—

131(i) a detailed description of how, where, and for how long data and images collected through the use of unmanned aerial systems by U.S. Customs and Border Protection are collected and stored; and

132(ii) a list of Federal, State, and local law enforcement agencies that submitted mission requests in the previous year and the disposition of such requests.

133The Commissioner shall require all officers and agents of U.S. Customs and Border Protection to participate in a specified amount of continuing education (to be determined by the Commissioner) to maintain an understanding of Federal legal rulings, court decisions, and departmental policies, procedures, and guidelines.

134The Commissioner shall make every effort to ensure that adequate access to food and water is provided to an individual apprehended and detained at a United States port of entry or between ports of entry as soon as practicable following the time of such apprehension or during subsequent short-term detention.

135The Commissioner shall ensure that an individual apprehended by a U.S. Border Patrol agent or an Office of Field Operations officer is provided with information concerning such individual's rights, including the right to contact a representative of such individual's government for purposes of United States treaty obligations.

136The information referred to in subparagraph (A) may be provided either verbally or in writing, and shall be posted in the detention holding cell in which such individual is being held. The information shall be provided in a language understandable to such individual.

137In this subsection, the term "short-term detention" means detention in a U.S. Customs and Border Protection processing center for 72 hours or less, before repatriation to a country of nationality or last habitual residence.

138When practicable, repatriations shall be limited to daylight hours and avoid locations that are determined to have high indices of crime and violence.

139Not later than 180 days after February 24, 2016, the Comptroller General of the United States shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the procurement process and standards of entities with which U.S. Customs and Border Protection has contracts for the transportation and detention of individuals apprehended by agents or officers of U.S. Customs and Border Protection. Such report should also consider the operational efficiency of contracting the transportation and detention of such individuals.

140The Commissioner shall—

141(A) annually inspect all facilities utilized for short-term detention; and

142(B) make publicly available information collected pursuant to such inspections, including information regarding the requirements under paragraphs (1) and (2) and, where appropriate, issue recommendations to improve the conditions of such facilities.

143The Commissioner shall—

144(A) publish live wait times for travelers entering the United States at the 20 United States airports that support the highest volume of international travel (as determined by available Federal flight data);

145(B) make information about such wait times available to the public in real time through the U.S. Customs and Border Protection website;

146(C) submit to the Committee on Homeland Security and the Committee on Ways and Means of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Finance of the Senate, for each of the five calendar years beginning in the calendar year that begins after February 24, 2016, a report that includes compilations of all such wait times and a ranking of such United States airports by wait times; and

147(D) provide adequate staffing at the U.S. Customs and Border Protection information center to ensure timely access for travelers attempting to submit comments or speak with a representative about their entry experiences.

148The wait times referred to in paragraph (1)(A) shall be determined by calculating the time elapsed between an individual's entry into the U.S. Customs and Border Protection inspection area and such individual's clearance by a U.S. Customs and Border Protection officer.

149The Secretary may establish such other offices or positions of Assistant Commissioners (or other similar officers or officials) as the Secretary determines necessary to carry out the missions, duties, functions, and authorities of U.S. Customs and Border Protection.

150If the Secretary exercises the authority provided under paragraph (1), the Secretary shall notify the Committee on Homeland Security and the Committee on Ways and Means of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Finance of the Senate not later than 30 days before exercising such authority.

151Beginning in fiscal year 2019, in carrying out subsection (c)(8), the Commissioner shall purchase, deploy, and maintain not more than 250 self-powering, 9–1–1 cellular relay rescue beacons along the southern border of the United States at locations determined appropriate by the Commissioner to mitigate migrant deaths.

152The Commissioner shall, on and after February 24, 2016, continue to submit to the Committee on Homeland Security and the Committee on Ways and Means of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Finance of the Senate any report required, on the day before February 24, 2016, to be submitted under any provision of law.

153Nothing in this section may be construed as affecting in any manner the authority, existing on the day before February 24, 2016, of any other Federal agency or component of the Department.

154In this section, the terms "commercial operations", "customs and trade laws of the United States", "trade enforcement", and "trade facilitation" have the meanings given such terms in section 4301 of title 19.

212.

Retention of Customs revenue functions by Secretary of the Treasury

1Notwithstanding section 203(a)(1) 1 of this title, authority related to Customs revenue functions that was vested in the Secretary of the Treasury by law before the effective date of this chapter under those provisions of law set forth in paragraph (2) shall not be transferred to the Secretary by reason of this chapter, and on and after the effective date of this chapter, the Secretary of the Treasury may delegate any such authority to the Secretary at the discretion of the Secretary of the Treasury. The Secretary of the Treasury shall consult with the Secretary regarding the exercise of any such authority not delegated to the Secretary.

2The provisions of law referred to in paragraph (1) are the following: the Tariff Act of 1930 [19 U.S.C. 1202 et seq.]; section 249 of the Revised Statutes of the United States (19 U.S.C. 3); section 2 of the Act of March 4, 1923 (19 U.S.C. 6); section 13031 of the Consolidated Omnibus Budget Reconciliation Act of 1985 (19 U.S.C. 58c); section 251 of the Revised Statutes of the United States (19 U.S.C. 66); section 1 of the Act of June 26, 1930 (19 U.S.C. 68); the Foreign Trade Zones Act (19 U.S.C. 81a et seq.); section 1 of the Act of March 2, 1911 (19 U.S.C. 198); the Trade Act of 1974 [19 U.S.C. 2101 et seq.]; the Trade Agreements Act of 1979; the North American Free Trade Area Implementation Act; the Uruguay Round Agreements Act; the Caribbean Basin Economic Recovery Act [19 U.S.C. 2701 et seq.]; the Andean Trade Preference Act [19 U.S.C. 3201 et seq.]; the African Growth and Opportunity Act [19 U.S.C. 3701 et seq.]; and any other provision of law vesting customs revenue functions in the Secretary of the Treasury.

3Notwithstanding any other provision of this chapter, the Secretary may not consolidate, discontinue, or diminish those functions described in paragraph (2) performed by U.S. Customs and Border Protection (as established under section 211 of this title) on or after the effective date of this chapter, reduce the staffing level, or reduce the resources attributable to such functions, and the Secretary shall ensure that an appropriate management structure is implemented to carry out such functions.

4The functions referred to in paragraph (1) are those functions performed by the following personnel, and associated support staff, of U.S. Customs and Border Protection on the day before the effective date of this chapter: Import Specialists, Entry Specialists, Drawback Specialists, National Import Specialist, Fines and Penalties Specialists, attorneys of the Office of Regulations and Rulings, Customs Auditors, International Trade Specialists, Financial Systems Specialists.

5The Secretary of the Treasury is authorized to appoint up to 20 new personnel to work with personnel of the Department in performing customs revenue functions.

213.

Preservation of Customs funds

1Notwithstanding any other provision of this chapter, no funds collected under paragraphs (1) through (8) of section 58c(a) of title 19 may be transferred for use by any other agency or office in the Department.

214.

Separate budget request for Customs

1The President shall include in each budget transmitted to Congress under section 1105 of title 31 a separate budget request for U.S. Customs and Border Protection.

215.

Definition

1In this part, the term "customs revenue function" means the following:

2(1) Assessing and collecting customs duties (including antidumping and countervailing duties and duties imposed under safeguard provisions), excise taxes, fees, and penalties due on imported merchandise, including classifying and valuing merchandise for purposes of such assessment.

3(2) Processing and denial of entry of persons, baggage, cargo, and mail, with respect to the assessment and collection of import duties.

4(3) Detecting and apprehending persons engaged in fraudulent practices designed to circumvent the customs laws of the United States.

5(4) Enforcing section 1337 of title 19 and provisions relating to import quotas and the marking of imported merchandise, and providing Customs Recordations for copyrights, patents, and trademarks.

6(5) Collecting accurate import data for compilation of international trade statistics.

7(6) Enforcing reciprocal trade agreements.

8(7) Functions performed by the following personnel, and associated support staff, of the United States Customs Service on the day before the effective date of this chapter, and of U.S. Customs and Border Protection on the day before the effective date of the U.S. Customs and Border Protection Authorization Act: Import Specialists, Entry Specialists, Drawback Specialists, National Import Specialist, Fines and Penalties Specialists, attorneys of the Office of Regulations and Rulings, Customs Auditors, International Trade Specialists, Financial Systems Specialists.

9(8) Functions performed by the following offices, with respect to any function described in any of paragraphs (1) through (7), and associated support staff, of the United States Customs Service on the day before the effective date of this chapter, and of U.S. Customs and Border Protection on the day before the effective date of the U.S. Customs and Border Protection Authorization Act: the Office of Information and Technology, the Office of Laboratory Services, the Office of the Chief Counsel, the Office of Congressional Affairs, the Office of International Affairs, and the Office of Training and Development.

216.

Protection against potential synthetic opioid exposure

1The Commissioner of U.S. Customs and Border Protection shall issue a policy that specifies effective protocols and procedures for the safe handling of potential synthetic opioids, including fentanyl, by U.S. Customs and Border Protection officers, agents, other personnel, and canines, and to reduce the risk of injury or death resulting from accidental exposure and enhance post-exposure management.

2Together with the issuance of the policy described in subsection (a), the Commissioner of U.S. Customs and Border Protection shall require mandatory and recurrent training on the following:

3(A) The potential risk of opioid exposure and safe handling procedures for potential synthetic opioids, including precautionary measures such as the use of personal protective equipment during such handling.

4(B) How to access and administer opioid receptor antagonists, including naloxone, post-exposure to potential synthetic opioids.

5(C) How to use containment devices to prevent potential synthetic opioid exposure.

6The training described in paragraph (1) may be integrated into existing training under section 211(l) of this title for U.S. Customs and Border Protection officers, agents, and other personnel.

7Together with the issuance of the policy described in subsection (a), the Commissioner of U.S. Customs and Border Protection shall ensure the availability of personal protective equipment, opioid receptor antagonists, including naloxone, and containment devices, to all U.S. Customs and Border Protection officers, agents, other personnel, and canines at risk of accidental exposure to synthetic opioids.

8To ensure effectiveness of the policy described in subsection (a)—

9(1) the Commissioner of U.S. Customs and Border Protection shall regularly monitor the efficacy of the implementation of such policy and adjust protocols and procedures, as necessary; and

10(2) the Inspector General of the Department shall audit compliance with the requirements of this section not less than once during the 3-year period after December 27, 2020.

217.

Allocation of resources by the Secretary

1The Secretary shall ensure that adequate staffing is provided to assure that levels of customs revenue services provided on the day before the effective date of this chapter shall continue to be provided.

2The Secretary shall notify the Committee on Ways and Means of the House of Representatives and the Committee on Finance of the Senate at least 90 days prior to taking any action which would—

3(1) result in any significant reduction in customs revenue services, including hours of operation, provided at any office within the Department or any port of entry;

4(2) eliminate or relocate any office of the Department which provides customs revenue services; or

5(3) eliminate any port of entry.

6In this section, the term "customs revenue services" means those customs revenue functions described in paragraphs (1) through (6) and paragraph (8) of section 215 of this title.

218.

Asia-Pacific Economic Cooperation Business Travel Cards

1The Commissioner of U.S. Customs and Border Protection is authorized to issue an Asia-Pacific Economic Cooperation Business Travel Card (referred to in this section as an "ABT Card") to any individual described in subsection (b).

2An individual described in this subsection is an individual who—

3(1) is a citizen of the United States;

4(2) has been approved and is in good standing in an existing international trusted traveler program of the Department; and

5(3) is—

6(A) engaged in business in the Asia-Pacific region, as determined by the Commissioner of U.S. Customs and Border Protection; or

7(B) a United States Government official actively engaged in Asia-Pacific Economic Cooperation business, as determined by the Commissioner of U.S. Customs and Border Protection.

8The Commissioner of U.S. Customs and Border Protection shall integrate application procedures for, and issuance, renewal, and revocation of, ABT Cards with existing international trusted traveler programs of the Department.

9In carrying out this section, the Commissioner of U.S. Customs and Border Protection may consult with appropriate private sector entities and nongovernmental organizations, including academic institutions.

10The Commissioner of U.S. Customs and Border Protection shall—

11(A) prescribe and collect a fee for the issuance and renewal of ABT Cards; and

12(B) adjust such fee to the extent the Commissioner determines necessary to comply with paragraph (2).

13The Commissioner of U.S. Customs and Border Protection shall ensure that the total amount of the fees collected under paragraph (1) during any fiscal year is sufficient to offset the direct and indirect costs associated with carrying out this section during such fiscal year, including the costs associated with operating and maintaining the ABT Card issuance and renewal processes.

14There is established in the Treasury of the United States an "Asia-Pacific Economic Cooperation Business Travel Card Account" into which the fees collected under paragraph (1) shall be deposited as offsetting receipts.

15Amounts deposited into the Asia Pacific 1 Economic Cooperation Business Travel Card Account established under paragraph (3) shall—

16(A) be credited to the appropriate account of the 2 U.S. Customs and Border Protection for expenses incurred in carrying out this section; and

17(B) remain available until expended.

18The Commissioner of U.S. Customs and Border Protection shall notify the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate not later than 60 days after the expenditures of funds to operate and provide ABT Card services beyond the amounts collected under subsection (e)(1).

19In this section, the term "trusted traveler program" means a voluntary program of the Department that allows U.S. Customs and Border Protection to expedite clearance of pre-approved, low-risk travelers arriving in the United States.

220.

Methamphetamine and methamphetamine precursor chemicals

1As part of the annual performance plan required in the budget submission of the United States Customs and Border Protection under section 1115 of title 31, the Commissioner shall establish performance indicators relating to the seizure of methamphetamine and methamphetamine precursor chemicals in order to evaluate the performance goals of the United States Customs and Border Protection with respect to the interdiction of illegal drugs entering the United States.

2The Commissioner shall, on an ongoing basis, analyze the movement of methamphetamine and methamphetamine precursor chemicals into the United States. In conducting the analysis, the Commissioner shall—

3(A) consider the entry of methamphetamine and methamphetamine precursor chemicals through ports of entry, between ports of entry, through international mails, and through international courier services;

4(B) examine the export procedures of each foreign country where the shipments of methamphetamine and methamphetamine precursor chemicals originate and determine if changes in the country's customs over time provisions would alleviate the export of methamphetamine and methamphetamine precursor chemicals; and

5(C) identify emerging trends in smuggling techniques and strategies.

6Not later than September 30, 2007, and each 2-year period thereafter, the Commissioner, in the consultation with the Attorney General, United States Immigration and Customs Enforcement, the United States Drug Enforcement Administration, and the United States Department of State, shall submit a report to the Committee on Finance of the Senate, the Committee on Foreign Relations of the Senate, the Committee on the Judiciary of the Senate, the Committee on Ways and Means of the House of Representatives, the Committee on International Relations of the House of Representatives, and the Committee on the Judiciary of the House of Representatives, that includes—

7(A) a comprehensive summary of the analysis described in paragraph (1); and

8(B) a description of how the Untied 1 States Customs and Border Protection utilized the analysis described in paragraph (1) to target shipments presenting a high risk for smuggling or circumvention of the Combat Methamphetamine Epidemic Act of 2005 (Public Law 109–177).

9The Commissioner shall ensure that the analysis described in paragraph (1) is made available in a timely manner to the Secretary of State to facilitate the Secretary in fulfilling the Secretary's reporting requirements in section 722 of the Combat Methamphetamine Epidemic Act of 2005.

10In this section, the term "methamphetamine precursor chemicals" means the chemicals ephedrine, pseudoephedrine, or phenylpropanolamine, including each of the salts, optical isomers, and salts of optical isomers of such chemicals.

221.

Requirements with respect to administering polygraph examinations to law enforcement personnel of U.S. Customs and Border Protection

1The Secretary of Homeland Security shall ensure that—

2(1) by not later than 2 years after January 4, 2011, all applicants for law enforcement positions with U.S. Customs and Border Protection (except as provided in subsection (b)) receive polygraph examinations before being hired for such a position; and

3(2) by not later than 180 days after January 4, 2011, U.S. Customs and Border Protection initiates all periodic background reinvestigations for all law enforcement personnel of U.S. Customs and Border Protection that should receive periodic background reinvestigations pursuant to relevant policies of U.S. Customs and Border Protection in effect on the day before January 4, 2011.

4The Commissioner of U.S. Customs and Border Protection may waive the polygraph examination requirement under subsection (a)(1) for any applicant who—

5(1) is deemed suitable for employment;

6(2) holds a current, active Top Secret/Sensitive Compartmented Information Clearance;

7(3) has a current Single Scope Background Investigation;

8(4) was not granted any waivers to obtain his or her clearance; and

9(5) is a veteran (as defined in section 2108 of title 5).

222.

Advanced Training Center Revolving Fund

1For fiscal year 2012 and thereafter, U.S. Customs and Border Protection's Advanced Training Center is authorized to charge fees for any service and/or thing of value it provides to Federal Government or non-government entities or individuals, so long as the fees charged do not exceed the full costs associated with the service or thing of value provided: Provided, That notwithstanding section 3302(b) of title 31, fees collected by the Advanced Training Center are to be deposited into a separate account entitled "Advanced Training Center Revolving Fund", and be available, without further appropriations, for necessary expenses of the Advanced Training Center program, and are to remain available until expended.

223.

Border security metrics

1In this section:

2The term "appropriate congressional committees" means—

3(A) the Committee on Homeland Security and Governmental Affairs of the Senate; and

4(B) the Committee on Homeland Security of the House of Representatives.

5The term "Consequence Delivery System" means the series of consequences applied by U.S. Border Patrol in collaboration with other Federal agencies to persons unlawfully entering the United States, in order to prevent unlawful border crossing recidivism.

6The term "got away" means an unlawful border crosser who—

7(A) is directly or indirectly observed making an unlawful entry into the United States;

8(B) is not apprehended; and

9(C) is not a turn back.

10The term "known maritime migrant flow" means the sum of the number of undocumented migrants—

11(A) interdicted in the waters over which the United States has jurisdiction;

12(B) identified at sea either directly or indirectly, but not interdicted;

13(C) if not described in subparagraph (A) or (B), who were otherwise reported, with a significant degree of certainty, as having entered, or attempted to enter, the United States through the maritime border.

14The term "major violator" means a person or entity that has engaged in serious criminal activities at any land, air, or sea port of entry, including the following:

15(A) Possession of illicit drugs.

16(B) Smuggling of prohibited products.

17(C) Human smuggling.

18(D) Possession of illegal weapons.

19(E) Use of fraudulent documents.

20(F) Any other offense that is serious enough to result in an arrest.

21The term "the Secretary" means the Secretary of Homeland Security.

22The term "situational awareness" means knowledge and understanding of current unlawful cross-border activity, including the following:

23(A) Threats and trends concerning illicit trafficking and unlawful crossings.

24(B) The ability to forecast future shifts in such threats and trends.

25(C) The ability to evaluate such threats and trends at a level sufficient to create actionable plans.

26(D) The operational capability to conduct persistent and integrated surveillance of the international borders of the United States.

27The term "transit zone" means the sea corridors of the western Atlantic Ocean, the Gulf of Mexico, the Caribbean Sea, and the eastern Pacific Ocean through which undocumented migrants and illicit drugs transit, either directly or indirectly, to the United States.

28The term "turn back" means an unlawful border crosser who, after making an unlawful entry into the United States, responds to United States enforcement efforts by returning promptly to the country from which such crosser entered.

29The term "unlawful border crossing effectiveness rate" means the percentage that results from dividing the number of apprehensions and turn backs by the sum of the number of apprehensions, estimated undetected unlawful entries, turn backs, and got aways.

30The term "unlawful entry" means an unlawful border crosser who enters the United States and is not apprehended by a border security component of the Department of Homeland Security.

31Not later than 180 days after December 23, 2016, the Secretary shall develop metrics, informed by situational awareness, to measure the effectiveness of security between ports of entry. The Secretary shall annually implement the metrics developed under this subsection, which shall include the following:

32(A) Estimates, using alternative methodologies where appropriate, including recidivism data, survey data, known-flow data, and technologically-measured data, of the following:

33(i) The rate of apprehension of attempted unlawful border crossers.

34(ii) The number of detected unlawful entries.

35(iii) The number of estimated undetected unlawful entries.

36(iv) Turn backs.

37(v) Got aways.

38(B) A measurement of situational awareness achieved in each U.S. Border Patrol sector.

39(C) An unlawful border crossing effectiveness rate in each U.S. Border Patrol sector.

40(D) A probability of detection rate, which compares the estimated total unlawful border crossing attempts not detected by U.S. Border Patrol to the unlawful border crossing effectiveness rate under subparagraph (C), as informed by subparagraph (A).

41(E) The number of apprehensions in each U.S. Border Patrol sector.

42(F) The number of apprehensions of unaccompanied alien children, and the nationality of such children, in each U.S. Border Patrol sector.

43(G) The number of apprehensions of family units, and the nationality of such family units, in each U.S. Border Patrol sector.

44(H) An illicit drugs seizure rate for drugs seized by U.S. Border Patrol between ports of entry, which compares the ratio of the amount and type of illicit drugs seized between ports of entry in any fiscal year to the average of the amount and type of illicit drugs seized between ports of entry in the immediately preceding five fiscal years.

45(I) Estimates of the impact of the Consequence Delivery System on the rate of recidivism of unlawful border crossers over multiple fiscal years.

46(J) An examination of each consequence under the Consequence Delivery System referred to in subparagraph (I), including the following:

47(i) Voluntary return.

48(ii) Warrant of arrest or notice to appear.

49(iii) Expedited removal.

50(iv) Reinstatement of removal.

51(v) Alien transfer exit program.

52(vi) Criminal consequence program.

53(vii) Standard prosecution.

54(viii) Operation Against Smugglers Initiative on Safety and Security.

55To ensure that authoritative data sources are utilized in the development of the metrics described in paragraph (1), the Secretary shall—

56(A) consult with the heads of the appropriate components of the Department of Homeland Security; and

57(B) where appropriate, with the heads of other agencies, including the Office of Refugee Resettlement of the Department of Health and Human Services and the Executive Office for Immigration Review of the Department of Justice.

58The data collected to inform the metrics developed in accordance with paragraph (1) shall be collected and reported in a consistent and standardized manner across all U.S. Border Patrol sectors, informed by situational awareness.

59Not later than 180 days after December 23, 2016, the Secretary shall develop metrics, informed by situational awareness, to measure the effectiveness of security at ports of entry. The Secretary shall annually implement the metrics developed under this subsection, which shall include the following:

60(A) Estimates, using alternative methodologies where appropriate, including recidivism data, survey data, and randomized secondary screening data, of the following:

61(i) Total inadmissible travelers who attempt to, or successfully, enter the United States at a port of entry.

62(ii) The rate of refusals and interdictions for travelers who attempt to, or successfully, enter the United States at a port of entry.

63(iii) The number of unlawful entries at a port of entry.

64(B) The amount and type of illicit drugs seized by the Office of Field Operations of U.S. Customs and Border Protection at ports of entry during the previous fiscal year.

65(C) An illicit drugs seizure rate for drugs seized by the Office of Field Operations, which compares the ratio of the amount and type of illicit drugs seized by the Office of Field Operations in any fiscal year to the average of the amount and type of illicit drugs seized by the Office of Field Operations in the immediately preceding five fiscal years.

66(D) The number of infractions related to travelers and cargo committed by major violators who are interdicted by the Office of Field Operations at ports of entry, and the estimated number of such infractions committed by major violators who are not so interdicted.

67(E) In consultation with the heads of the Office of National Drug Control Policy and the United States Southern Command, a cocaine seizure effectiveness rate, which is the percentage resulting from dividing the amount of cocaine seized by the Office of Field Operations by the total estimated cocaine flow rate at ports of entry along the United States land border with Mexico and Canada.

68(F) A measurement of how border security operations affect crossing times, including the following:

69(i) A wait time ratio that compares the average wait times to total commercial and private vehicular traffic volumes at each land port of entry.

70(ii) An infrastructure capacity utilization rate that measures traffic volume against the physical and staffing capacity at each land port of entry.

71(iii) A secondary examination rate that measures the frequency of secondary examinations at each land port of entry.

72(iv) An enforcement rate that measures the effectiveness of such secondary examinations at detecting major violators.

73(G) A seaport scanning rate that includes the following:

74(i) The number of all cargo containers that are considered potentially "high-risk", as determined by the Executive Assistant Commissioner of the Office of Field Operations.

75(ii) A comparison of the number of potentially high-risk cargo containers scanned by the Office of Field Operations at each sea port of entry during a fiscal year to the total number of high-risk cargo containers entering the United States at each such sea port of entry during the previous fiscal year.

76(iii) The number of potentially high-risk cargo containers scanned upon arrival at a United States sea port of entry.

77(iv) The number of potentially high-risk cargo containers scanned before arrival at a United States sea port of entry.

78To ensure that authoritative data sources are utilized in the development of the metrics described in paragraph (1), the Secretary shall—

79(A) consult with the heads of the appropriate components of the Department of Homeland Security; and

80(B) where appropriate, work with heads of other appropriate agencies, including the Office of Refugee Resettlement of the Department of Health and Human Services and the Executive Office for Immigration Review of the Department of Justice.

81The data collected to inform the metrics developed in accordance with paragraph (1) shall be collected and reported in a consistent and standardized manner across all United States ports of entry, informed by situational awareness.

82Not later than 180 days after December 23, 2016, the Secretary shall develop metrics, informed by situational awareness, to measure the effectiveness of security in the maritime environment. The Secretary shall annually implement the metrics developed under this subsection, which shall include the following:

83(A) Situational awareness achieved in the maritime environment.

84(B) A known maritime migrant flow rate.

85(C) An illicit drugs removal rate for drugs removed inside and outside of a transit zone, which compares the amount and type of illicit drugs removed, including drugs abandoned at sea, by the maritime security components of the Department of Homeland Security in any fiscal year to the average of the amount and type of illicit drugs removed by such maritime components for the immediately preceding five fiscal years.

86(D) In consultation with the heads of the Office of National Drug Control Policy and the United States Southern Command, a cocaine removal effectiveness rate for cocaine removed inside a transit zone and outside a transit zone, which compares the amount of cocaine removed by the maritime security components of the Department of Homeland Security by the total documented cocaine flow rate, as contained in Federal drug databases.

87(E) A response rate, which compares the ability of the maritime security components of the Department of Homeland Security to respond to and resolve known maritime threats, whether inside or outside a transit zone, by placing assets on-scene, to the total number of events with respect to which the Department has known threat information.

88(F) An intergovernmental response rate, which compares the ability of the maritime security components of the Department of Homeland Security or other United States Government entities to respond to and resolve actionable maritime threats, whether inside or outside a transit zone, with the number of such threats detected.

89To ensure that authoritative data sources are utilized in the development of the metrics described in paragraph (1), the Secretary shall—

90(A) consult with the heads of the appropriate components of the Department of Homeland Security; and

91(B) where appropriate, work with the heads of other agencies, including the Drug Enforcement Agency, the Department of Defense, and the Department of Justice.

92The data used by the Secretary shall be collected and reported in a consistent and standardized manner by the maritime security components of the Department of Homeland Security, informed by situational awareness.

93Not later than 180 days after December 23, 2016, the Secretary shall develop metrics, informed by situational awareness, to measure the effectiveness of the aviation assets and operations of Air and Marine Operations of U.S. Customs and Border Protection. The Secretary shall annually implement the metrics developed under this subsection, which shall include the following:

94(A) A flight hour effectiveness rate, which compares Air and Marine Operations flight hours requirements to the number of flight hours flown by Air and Marine Operations.

95(B) A funded flight hour effectiveness rate, which compares the number of funded flight hours appropriated to Air and Marine Operations to the number of actual flight hours flown by Air and Marine Operations.

96(C) A readiness rate, which compares the number of aviation missions flown by Air and Marine Operations to the number of aviation missions cancelled by Air and Marine Operations due to maintenance, operations, or other causes.

97(D) The number of missions cancelled by Air and Marine Operations due to weather compared to the total planned missions.

98(E) The number of individuals detected by Air and Marine Operations through the use of unmanned aerial systems and manned aircraft.

99(F) The number of apprehensions assisted by Air and Marine Operations through the use of unmanned aerial systems and manned aircraft.

100(G) The number and quantity of illicit drug seizures assisted by Air and Marine Operations through the use of unmanned aerial systems and manned aircraft.

101(H) The number of times that actionable intelligence related to border security was obtained through the use of unmanned aerial systems and manned aircraft.

102To ensure that authoritative data sources are utilized in the development of the metrics described in paragraph (1), the Secretary shall—

103(A) consult with the heads of the appropriate components of the Department of Homeland Security; and

104(B) as appropriate, work with the heads of other departments and agencies, including the Department of Justice.

105The data collected to inform the metrics developed in accordance with paragraph (1) shall be collected and reported in a consistent and standardized manner by Air and Marine Operations, informed by situational awareness.

106The Secretary shall—

107(1) in accordance with applicable privacy laws, make data related to apprehensions, inadmissible aliens, drug seizures, and other enforcement actions available to the public, law enforcement communities, and academic research communities; and

108(2) provide the Office of Immigration Statistics of the Department of Homeland Security with unfettered access to the data referred to in paragraph (1).

109The Secretary shall submit to the appropriate congressional committees and the Comptroller General of the United States an annual report containing the metrics required under this section and the data and methodology used to develop such metrics.

110The Secretary, for the purpose of validation and verification, may submit the annual report described in subparagraph (A) to—

111(i) the Center for Borders, Trade, and Immigration Research of the Centers of Excellence network of the Department of Homeland Security;

112(ii) the head of a national laboratory within the Department of Homeland Security laboratory network with prior expertise in border security; and

113(iii) a Federally Funded Research and Development Center.

114Not later than 270 days after receiving the first report under paragraph (1)(A) and biennially thereafter for the following ten years with respect to every other such report, the Comptroller General of the United States shall submit to the appropriate congressional committees a report that—

115(A) analyzes the suitability and statistical validity of the data and methodology contained in each such report; and

116(B) includes recommendations on—

117(i) the feasibility of other suitable metrics that may be used to measure the effectiveness of border security; and

118(ii) improvements that need to be made to the metrics being used to measure the effectiveness of border security.

119Not later than 60 days after the end of each fiscal year through fiscal year 2026, the Secretary shall submit to the appropriate congressional committees a "State of the Border" report that—

120(A) provides trends for each metric under this section for the last ten fiscal years, to the greatest extent possible;

121(B) provides selected analysis into related aspects of illegal flow rates, including undocumented migrant flows and stock estimation techniques;

122(C) provides selected analysis into related aspects of legal flow rates; and

123(D) includes any other information that the Secretary determines appropriate.

124After submitting the tenth report to the Comptroller General under paragraph (1), the Secretary may reevaluate and update any of the metrics developed in accordance with this section to ensure that such metrics are suitable to measure the effectiveness of border security.

125Not later than 30 days before updating the metrics pursuant to subparagraph (A), the Secretary shall notify the appropriate congressional committees of such updates.

224.

Other reporting requirements

1Not later than 1 year after December 31, 2020, and annually thereafter, the Commissioner of U.S. Customs and Border Protection shall submit a report to the appropriate committees of Congress regarding all unidentified remains discovered, during the reporting period, on or near the border between the United States and Mexico, including—

2(A) for each deceased person—

3(i) the cause and manner of death, if known;

4(ii) the sex, age (at time of death), and country of origin (if such information is determinable); and

5(iii) the location of each unidentified remain;

6(B) the total number of deceased people whose unidentified remains were discovered by U.S. Customs and Border Protection during the reporting period;

7(C) to the extent such information is available to U.S. Customs and Border Protection, the total number of deceased people whose unidentified remains were discovered by Federal, State, local or Tribal law enforcement officers, military personnel, or medical examiners offices;

8(D) the efforts of U.S. Customs and Border Protection to engage with nongovernmental organizations, institutions of higher education, medical examiners and coroners, and law enforcement agencies—

9(i) to identify and map the locations at which migrant deaths occur; and

10(ii) to count the number of deaths that occur at such locations; and

11(E) a detailed description of U.S. Customs and Border Protection's Missing Migrant Program, including how the program helps mitigate migrant deaths while maintaining border security.

12Not later than 30 days after each report required under paragraph (1) is submitted, the Commissioner of U.S. Customs and Border Protection shall publish on the website of the agency the information described in subparagraphs (A), (B), and (C) of paragraph (1) during each reporting period.

13Not later than 1 year after December 31, 2020, and annually thereafter, the Commissioner of U.S. Customs and Border Protection shall submit a report to the appropriate committees of Congress regarding the use of rescue beacons along the border between the United States and Mexico, including, for the reporting period—

14(1) the number of rescue beacons in each border patrol sector;

15(2) the specific location of each rescue beacon;

16(3) the frequency with which each rescue beacon was activated by a person in distress;

17(4) a description of the nature of the distress that resulted in each rescue beacon activation (if such information is determinable); and

18(5) an assessment, in consultation with local stakeholders, including elected officials, nongovernmental organizations, and landowners, of necessary additional rescue beacons and recommendations for locations for deployment to reduce migrant deaths.

19Not later than 6 months after the report required under subsection (a) is submitted to the appropriate committees of Congress, the Comptroller General of the United States shall submit a report to the same committees that describes—

20(1) how U.S. Customs and Border Protection collects and records border-crossing death data;

21(2) the differences (if any) in U.S. Customs and Border Protection border-crossing death data collection methodology across its sectors;

22(3) how U.S. Customs and Border Protection's data and statistical analysis on trends in the numbers, locations, causes, and characteristics of border-crossing deaths compare to other sources of data on these deaths, including border county medical examiners and coroners and the Centers for Disease Control and Prevention;

23(4) how U.S. Customs and Border Protection measures the effectiveness of its programs to mitigate migrant deaths; and

24(5) the extent to which U.S. Customs and Border Protection engages Federal, State, local, and Tribal governments, foreign diplomatic and consular posts, and nongovernmental organizations—

25(A) to accurately identify deceased individuals;

26(B) to resolve cases involving unidentified remains;

27(C) to resolve cases involving unidentified persons; and

28(D) to share information on missing persons and unidentified remains, specifically with the National Missing and Unidentified Persons System (NamUs).

225.

Reports, evaluations, and research regarding drug interdiction at and between ports of entry

1Not later than one year after December 23, 2022, the Secretary of Homeland Security, in consultation with the Attorney General, the Secretary of Health and Human Services, and the Director of the Office of National Drug Control Policy, shall research additional technological solutions to—

2(1) target and detect illicit fentanyl, fentanyl analogs, and precursor chemicals, including low-purity fentanyl, especially in counterfeit pressed tablets, and illicit pill press molds; and

3(2) enhance detection of such counterfeit pressed tablets through nonintrusive, noninvasive, and other advanced screening technologies.

4The Secretary of Homeland Security, in consultation with the Attorney General, the Secretary of Health and Human Services, and the Director of the Office of National Drug Control Policy, shall establish a program to collect available data and develop metrics to measure how technologies and strategies used by the Department of Homeland Security, U.S. Customs and Border Protection, U.S. Immigration and Customs Enforcement, and other relevant Federal agencies have helped detect trafficked illicit fentanyl, fentanyl analogs, and precursor chemicals or deter illicit fentanyl, fentanyl analogs, and precursor chemicals from being trafficked into the United States at and between land, air, and sea ports of entry.

5The data and metrics program established pursuant to paragraph (1) may consider—

6(A) the rate of detection of illicit fentanyl, fentanyl analogs, and precursor chemicals at land, air, and sea ports of entry;

7(B) investigations and intelligence sharing into the origins of illicit fentanyl, fentanyl analogs, and precursor chemicals within the United States; and

8(C) other data or metrics considered appropriate by the Secretary of Homeland Security.

9The Secretary of Homeland Security, as appropriate and in the coordination with the officials referred to in paragraph (1), may update the data and metrics program established pursuant to paragraph (1).

10Not later than one year after December 23, 2022, and biennially thereafter, the Secretary of Homeland Security, in consultation with the Attorney General, the Secretary of Health and Human Services, and the Director of the Office of National Drug Control Policy shall, based on the data collected and metrics developed pursuant to the program established pursuant to paragraph (1), submit to the Committee on Homeland Security, the Committee on Energy and Commerce, the Committee on Science, Space, and Technology, and the Committee on the Judiciary of the House of Representatives and the Committee on Homeland Security and Governmental Affairs, the Committee on Commerce, Science, and Transportation, and the Committee on the Judiciary of the Senate a report that—

11(i) examines and analyzes current technologies, including pilot technologies, deployed at land, air, and sea ports of entry to assess how well such technologies detect, deter, and address illicit fentanyl, fentanyl analogs, and precursor chemicals; and

12(ii) examines and analyzes current technologies, including pilot technologies, deployed between land ports of entry to assess how well and accurately such technologies detect, deter, interdict, and address illicit fentanyl, fentanyl analogs, and precursor chemicals; 1

13Not later than one year after the submission of each of the first three reports required under subparagraph (A), the Comptroller General of the United States shall submit to the Committee on Homeland Security, the Committee on Energy and Commerce, the Committee on Science, Space, and Technology, and the Committee on the Judiciary of the House of Representatives and the Committee on Homeland Security and Governmental Affairs, the Committee on Commerce, Science, and Transportation, and the Committee on the Judiciary of the Senate a report that evaluates and, as appropriate, makes recommendations to improve, the collection of data under the program established pursuant to paragraph (1) and metrics used in the subsequent reports required under such subparagraph.

226.

Ensuring timely updates to U.S. Customs and Border Protection field manuals

1Not less frequently than triennially, the Commissioner of U.S. Customs and Border Protection shall review and update, as necessary, the current policies and manuals of the Office of Field Operations related to inspections at ports of entry to ensure the uniform implementation of inspection practices that will effectively respond to technological and methodological changes designed to disguise illegal activity, such as the smuggling of drugs and humans, along the border.

2Shortly after each update required under subsection (a), the Commissioner of U.S. Customs and Border Protection shall submit a report to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives that summarizes the policy and manual changes implemented by such update.

231.

Transfer of certain agricultural inspection functions of the Department of Agriculture

1There shall be transferred to the Secretary the functions of the Secretary of Agriculture relating to agricultural import and entry inspection activities under the laws specified in subsection (b).

2The laws referred to in subsection (a) are the following:

3(1) The Act commonly known as the Virus-Serum-Toxin Act (the eighth paragraph under the heading "Bureau of Animal Industry" in the Act of March 4, 1913; 21 U.S.C. 151 et seq.).

4(2) Section 1 of the Act of August 31, 1922 (commonly known as the Honeybee Act; 7 U.S.C. 281).

5(3) Title III of the Federal Seed Act (7 U.S.C. 1581 et seq.).

6(4) The Plant Protection Act (7 U.S.C. 7701 et seq.).

7(5) The Animal Health Protection Act (subtitle E of title X of Public Law 107–171; 7 U.S.C. 8301 et seq.).

8(6) The Lacey Act Amendments of 1981 (16 U.S.C. 3371 et seq.).

9(7) Section 11 of the Endangered Species Act of 1973 (16 U.S.C. 1540).

10For purposes of this section, the term "functions" does not include any quarantine activities carried out under the laws specified in subsection (b).

11The authority transferred pursuant to subsection (a) shall be exercised by the Secretary in accordance with the regulations, policies, and procedures issued by the Secretary of Agriculture regarding the administration of the laws specified in subsection (b).

12The Secretary of Agriculture shall coordinate with the Secretary whenever the Secretary of Agriculture prescribes regulations, policies, or procedures for administering the functions transferred under subsection (a) under a law specified in subsection (b).

13The Secretary, in consultation with the Secretary of Agriculture, may issue such directives and guidelines as are necessary to ensure the effective use of personnel of the Department of Homeland Security to carry out the functions transferred pursuant to subsection (a).

14Before the end of the transition period, as defined in section 541 of this title, the Secretary of Agriculture and the Secretary shall enter into an agreement to effectuate the transfer of functions required by subsection (a) of this section. The Secretary of Agriculture and the Secretary may jointly revise the agreement as necessary thereafter.

15The agreement required by this subsection shall specifically address the following:

16(A) The supervision by the Secretary of Agriculture of the training of employees of the Secretary to carry out the functions transferred pursuant to subsection (a).

17(B) The transfer of funds to the Secretary under subsection (f).

18The Secretary of Agriculture and the Secretary may include as part of the agreement the following:

19(A) Authority for the Secretary to perform functions delegated to the Animal and Plant Health Inspection Service of the Department of Agriculture regarding the protection of domestic livestock and plants, but not transferred to the Secretary pursuant to subsection (a).

20(B) Authority for the Secretary of Agriculture to use employees of the Department of Homeland Security to carry out authorities delegated to the Animal and Plant Health Inspection Service regarding the protection of domestic livestock and plants.

21Out of funds collected by fees authorized under sections 136 and 136a of title 21, the Secretary of Agriculture shall transfer, from time to time in accordance with the agreement under subsection (e), to the Secretary funds for activities carried out by the Secretary for which such fees were collected.

22The proportion of fees collected pursuant to such sections that are transferred to the Secretary under this subsection may not exceed the proportion of the costs incurred by the Secretary to all costs incurred to carry out activities funded by such fees.

23Not later than the completion of the transition period defined under section 541 of this title, the Secretary of Agriculture shall transfer to the Secretary not more than 3,200 full-time equivalent positions of the Department of Agriculture.

232.

Functions of Administrator of General Services

1Nothing in this chapter may be construed to affect the functions or authorities of the Administrator of General Services with respect to the operation, maintenance, and protection of buildings and grounds owned or occupied by the Federal Government and under the jurisdiction, custody, or control of the Administrator. Except for the law enforcement and related security functions transferred under section 203(3) of this title, the Administrator shall retain all powers, functions, and authorities vested in the Administrator under chapter 1, except section 121(e)(2)(A), and chapters 5 to 11 of title 40 and other provisions of law that are necessary for the operation, maintenance, and protection of such buildings and grounds.

2Nothing in this chapter may be construed—

3(A) to direct the transfer of, or affect, the authority of the Administrator of General Services to collect rents and fees, including fees collected for protective services; or

4(B) to authorize the Secretary or any other official in the Department to obligate amounts in the Federal Buildings Fund established by section 592 of title 40.

5Any amounts transferred by the Administrator of General Services to the Secretary out of rents and fees collected by the Administrator shall be used by the Secretary solely for the protection of buildings or grounds owned or occupied by the Federal Government.

233.

Functions of Transportation Security Administration

1The Secretary and other officials in the Department shall consult with the Administrator of the Federal Aviation Administration before taking any action that might affect aviation safety, air carrier operations, aircraft airworthiness, or the use of airspace. The Secretary shall establish a liaison office within the Department for the purpose of consulting with the Administrator of the Federal Aviation Administration.

2Not later than 60 days after November 25, 2002, the Secretary of Transportation shall transmit to Congress a report containing a plan for complying with the requirements of section 44901(d) of title 49.

3Nothing in this chapter may be construed to vest in the Secretary or any other official in the Department any authority over transportation security that is not vested in the Under Secretary of Transportation for Security, or in the Secretary of Transportation under chapter 449 of title 49 on the day before November 25, 2002.

4Nothing in this chapter may be construed to authorize the Secretary or any other official in the Department to obligate amounts made available under section 48103 of title 49.

234.

Preservation of Transportation Security Administration as a distinct entity

1Notwithstanding any other provision of this chapter, the Transportation Security Administration shall be maintained as a distinct entity within the Department.

235.

Coordination of information and information technology

1In this section, the term "affected agency" means—

2(1) the Department;

3(2) the Department of Agriculture;

4(3) the Department of Health and Human Services; and

5(4) any other department or agency determined to be appropriate by the Secretary.

6The Secretary, in coordination with the Secretary of Agriculture, the Secretary of Health and Human Services, and the head of each other department or agency determined to be appropriate by the Secretary, shall ensure that appropriate information (as determined by the Secretary) concerning inspections of articles that are imported or entered into the United States, and are inspected or regulated by 1 or more affected agencies, is timely and efficiently exchanged between the affected agencies.

7Not later than 18 months after November 25, 2002, the Secretary, in consultation with the Secretary of Agriculture, the Secretary of Health and Human Services, and the head of each other department or agency determined to be appropriate by the Secretary, shall submit to Congress—

8(1) a report on the progress made in implementing this section; and

9(2) a plan to complete implementation of this section.

236.

Visa issuance

1In this subsection,1 the term "consular office" 2 has the meaning given that term under section 101(a)(9) of the Immigration and Nationality Act (8 U.S.C. 1101(a)(9)).

2Notwithstanding section 104(a) of the Immigration and Nationality Act (8 U.S.C. 1104(a)) or any other provision of law, and except as provided in subsection (c) of this section, the Secretary—

3(1) shall be vested exclusively with all authorities to issue regulations with respect to, administer, and enforce the provisions of such Act [8 U.S.C. 1101 et seq.], and of all other immigration and nationality laws, relating to the functions of consular officers of the United States in connection with the granting or refusal of visas, and shall have the authority to refuse visas in accordance with law and to develop programs of homeland security training for consular officers (in addition to consular training provided by the Secretary of State), which authorities shall be exercised through the Secretary of State, except that the Secretary shall not have authority to alter or reverse the decision of a consular officer to refuse a visa to an alien; and

4(2) shall have authority to confer or impose upon any officer or employee of the United States, with the consent of the head of the executive agency under whose jurisdiction such officer or employee is serving, any of the functions specified in paragraph (1).

5Notwithstanding subsection (b), the Secretary of State may direct a consular officer to refuse a visa to an alien if the Secretary of State deems such refusal necessary or advisable in the foreign policy or security interests of the United States.

6Nothing in this section, consistent with the Secretary of Homeland Security's authority to refuse visas in accordance with law, shall be construed as affecting the authorities of the Secretary of State under the following provisions of law:

7(A) Section 101(a)(15)(A) of the Immigration and Nationality Act (8 U.S.C. 1101(a)(15)(A)).

8(B) Section 204(d)(2) of the Immigration and Nationality Act (8 U.S.C. 1154) (as it will take effect upon the entry into force of the Convention on Protection of Children and Cooperation in Respect to Inter-Country adoption).

9(C) Section 212(a)(3)(B)(i)(IV)(bb) of the Immigration and Nationality Act (8 U.S.C. 1182(a)(3)(B)(i)(IV)(bb)).

10(D) Section 212(a)(3)(B)(i)(VI) of the Immigration and Nationality Act (8 U.S.C. 1182(a)(3)(B)(i)(VI)).

11(E) Section 212(a)(3)(B)(vi)(II) of the Immigration and Nationality Act (8 U.S.C. 1182(a)(3)(B)(vi)(II)).

12(F) Section 212(a)(3)(C) of the Immigration and Nationality Act (8 U.S.C. 1182(a)(3)(C)).

13(G) Section 212(a)(10)(C) of the Immigration and Nationality Act (8 U.S.C. 1182(a)(10)(C)).

14(H) Section 212(f) of the Immigration and Nationality Act (8 U.S.C. 1182(f)).

15(I) Section 219(a) of the Immigration and Nationality Act (8 U.S.C. 1189(a)).

16(J) Section 237(a)(4)(C) of the Immigration and Nationality Act (8 U.S.C. 1227(a)(4)(C)).

17(K) Section 401 of the Cuban Liberty and Democratic Solidarity (LIBERTAD) Act of 1996 [22 U.S.C. 6091].

18(L) Section 613 of the Departments of Commerce, Justice, and State, the Judiciary and Related Agencies Appropriations Act, 1999 3 (as contained in section 101(b) of division A of Public Law 105–277) (Omnibus Consolidated and Emergency Supplemental Appropriations Act, 1999); 112 Stat. 2681; H.R. 4328 (originally H.R. 4276) as amended by section 617 of Public Law 106–553.

19(M) Section 103(f) of the Chemical Weapon Convention Implementation Act of 1998 [22 U.S.C. 6713(f)] (112 Stat. 2681–865).

20(N) Section 801 of H.R. 3427, the Admiral James W. Nance and Meg Donovan Foreign Relations Authorization Act, Fiscal Years 2000 and 2001 [8 U.S.C. 1182e], as enacted by reference in Public Law 106–113.

21(O) Section 568 of the Foreign Operations, Export Financing, and Related Programs Appropriations Act, 2002 (Public Law 107–115).

22(P) Section 51 of the State Department Basic Authorities Act of 1956 (22 U.S.C. 2723).

23Nothing in this section may be construed to alter or affect—

24(A) the employment status of consular officers as employees of the Department of State; or

25(B) the authority of a chief of mission under section 207 of the Foreign Service Act of 1980 (22 U.S.C. 3927).

26Nothing in this section shall be construed to affect any delegation of authority to the Secretary of State by the President pursuant to any proclamation issued under section 212(f) of the Immigration and Nationality Act (8 U.S.C. 1182(f)), consistent with the Secretary of Homeland Security's authority to refuse visas in accordance with law.

27The Secretary is authorized to assign employees of the Department to each diplomatic and consular post at which visas are issued, unless the Secretary determines that such an assignment at a particular post would not promote homeland security.

28Employees assigned under paragraph (1) shall perform the following functions:

29(A) Provide expert advice and training to consular officers regarding specific security threats relating to the adjudication of individual visa applications or classes of applications.

30(B) Review any such applications, either on the initiative of the employee of the Department or upon request by a consular officer or other person charged with adjudicating such applications.

31(C) Conduct investigations with respect to consular matters under the jurisdiction of the Secretary.

32The Secretary of State shall evaluate, in consultation with the Secretary, as deemed appropriate by the Secretary, the performance of consular officers with respect to the processing and adjudication of applications for visas in accordance with performance standards developed by the Secretary for these procedures.

33The Secretary shall, on an annual basis, submit a report to Congress that describes the basis for each determination under paragraph (1) that the assignment of an employee of the Department at a particular diplomatic post would not promote homeland security.

34When appropriate, employees of the Department assigned to perform functions described in paragraph (2) may be assigned permanently to overseas diplomatic or consular posts with country-specific or regional responsibility. If the Secretary so directs, any such employee, when present at an overseas post, shall participate in the terrorist lookout committee established under section 304 of the Enhanced Border Security and Visa Entry Reform Act of 2002 (8 U.S.C. 1733).

35The Secretary shall ensure, to the extent possible, that any employees of the Department assigned to perform functions under paragraph (2) and, as appropriate, consular officers, shall be provided the necessary training to enable them to carry out such functions, including training in foreign languages, interview techniques, and fraud detection techniques, in conditions in the particular country where each employee is assigned, and in other appropriate areas of study.

36The Secretary is authorized to use the National Foreign Affairs Training Center, on a reimbursable basis, to obtain the training described in subparagraph (A).

37Not later than 1 year after November 25, 2002, the Secretary and the Secretary of State shall submit to Congress—

38(A) a report on the implementation of this subsection; and

39(B) any legislative proposals necessary to further the objectives of this subsection.

40This subsection shall take effect on the earlier of—

41(A) the date on which the President publishes notice in the Federal Register that the President has submitted a report to Congress setting forth a memorandum of understanding between the Secretary and the Secretary of State governing the implementation of this section; or

42(B) the date occurring 1 year after November 25, 2002.

43Nothing in this section shall be construed to create or authorize a private right of action to challenge a decision of a consular officer or other United States official or employee to grant or deny a visa.

44The Secretary of Homeland Security shall conduct a study of the role of foreign nationals in the granting or refusal of visas and other documents authorizing entry of aliens into the United States. The study shall address the following:

45(A) The proper role, if any, of foreign nationals in the process of rendering decisions on such grants and refusals.

46(B) Any security concerns involving the employment of foreign nationals.

47(C) Whether there are cost-effective alternatives to the use of foreign nationals.

48Not later than 1 year after November 25, 2002, the Secretary shall submit a report containing the findings of the study conducted under paragraph (1) to the Committee on the Judiciary, the Committee on International Relations, and the Committee on Government Reform of the House of Representatives, and the Committee on the Judiciary, the Committee on Foreign Relations, and the Committee on Government 4 Affairs of the Senate.

49Not later than 120 days after November 25, 2002, the Director of the Office of Science and Technology Policy shall submit to Congress a report on how the provisions of this section will affect procedures for the issuance of student visas.

50Notwithstanding any other provision of law, after November 25, 2002, all third party screening programs in Saudi Arabia shall be terminated. On-site personnel of the Department of Homeland Security shall review all visa applications prior to adjudication.

237.

Information on visa denials required to be entered into electronic data system

1Whenever a consular officer of the United States denies a visa to an applicant, the consular officer shall enter the fact and the basis of the denial and the name of the applicant into the interoperable electronic data system implemented under section 1722(a) of title 8.

2In the case of any alien with respect to whom a visa has been denied under subsection (a)—

3(1) no subsequent visa may be issued to the alien unless the consular officer considering the alien's visa application has reviewed the information concerning the alien placed in the interoperable electronic data system, has indicated on the alien's application that the information has been reviewed, and has stated for the record why the visa is being issued or a waiver of visa ineligibility recommended in spite of that information; and

4(2) the alien may not be admitted to the United States without a visa issued in accordance with the procedures described in paragraph (1).

238.

Office for Domestic Preparedness

1There is established in the Department an Office for Domestic Preparedness.

2There shall be a Director of the Office for Domestic Preparedness, who shall be appointed by the President.

3The Office for Domestic Preparedness shall have the primary responsibility within the executive branch of Government for the preparedness of the United States for acts of terrorism, including—

4(1) coordinating preparedness efforts at the Federal level, and working with all State, local, tribal, parish, and private sector emergency response providers on all matters pertaining to combating terrorism, including training, exercises, and equipment support;

5(2) coordinating or, as appropriate, consolidating communications and systems of communications relating to homeland security at all levels of government;

6(3) directing and supervising terrorism preparedness grant programs of the Federal Government (other than those programs administered by the Department of Health and Human Services) for all emergency response providers;

7(4) incorporating the Strategy priorities into planning guidance on an agency level for the preparedness efforts of the Office for Domestic Preparedness;

8(5) providing agency-specific training for agents and analysts within the Department, other agencies, and State and local agencies and international entities;

9(6) as the lead executive branch agency for preparedness of the United States for acts of terrorism, cooperating closely with the Federal Emergency Management Agency, which shall have the primary responsibility within the executive branch to prepare for and mitigate the effects of nonterrorist-related disasters in the United States;

10(7) assisting and supporting the Secretary, in coordination with other Directorates and entities outside the Department, in conducting appropriate risk analysis and risk management activities of State, local, and tribal governments consistent with the mission and functions of the Department;

11(8) those elements of the Office of National Preparedness of the Federal Emergency Management Agency which relate to terrorism, which shall be consolidated within the Department in the Office for Domestic Preparedness established under this section; and

12(9) helping to ensure the acquisition of interoperable communication technology by State and local governments and emergency response providers.

13During fiscal year 2003 and fiscal year 2004, the Director of the Office for Domestic Preparedness established under this section shall manage and carry out those functions of the Office for Domestic Preparedness of the Department of Justice (transferred under this section) before September 11, 2001, under the same terms, conditions, policies, and authorities, and with the required level of personnel, assets, and budget before September 11, 2001.

239.

Office of Cargo Security Policy

1There is established within the Department an Office of Cargo Security Policy (referred to in this section as the "Office").

2The Office shall—

3(1) coordinate all Department policies relating to cargo security; and

4(2) consult with stakeholders and coordinate with other Federal agencies in the establishment of standards and regulations and to promote best practices.

5The Office shall be headed by a Director, who shall—

6(A) be appointed by the Secretary; and

7(B) report to the Assistant Secretary for Policy.

8The Director shall—

9(A) advise the Assistant Secretary for Policy in the development of Department-wide policies regarding cargo security;

10(B) coordinate all policies relating to cargo security among the agencies and offices within the Department relating to cargo security; and

11(C) coordinate the cargo security policies of the Department with the policies of other executive agencies.

240.

Border Enforcement Security Task Force

1There is established within the Department a program to be known as the Border Enforcement Security Task Force (referred to in this section as "BEST").

2The purpose of BEST is to establish units to enhance border security by addressing and reducing border security threats and violence by—

3(1) facilitating collaboration among Federal, State, local, tribal, and foreign law enforcement agencies to execute coordinated activities in furtherance of border security, and homeland security; and

4(2) enhancing information-sharing, including the dissemination of homeland security information among such agencies.

5BEST units may be comprised of personnel from—

6(A) U.S. Immigration and Customs Enforcement;

7(B) U.S. Customs and Border Protection;

8(C) the United States Coast Guard;

9(D) other Department personnel, as appropriate 1

10(E) other Federal agencies, as appropriate;

11(F) appropriate State law enforcement agencies;

12(G) foreign law enforcement agencies, as appropriate;

13(H) local law enforcement agencies from affected border cities and communities; and

14(I) appropriate tribal law enforcement agencies.

15The Secretary is authorized to establish BEST units in jurisdictions in which such units can contribute to BEST missions, as appropriate. Before establishing a BEST unit, the Secretary shall consider—

16(A) whether the area in which the BEST unit would be established is significantly impacted by cross-border threats;

17(B) the availability of Federal, State, local, tribal, and foreign law enforcement resources to participate in the BEST unit;

18(C) the extent to which border security threats are having a significant harmful impact in the jurisdiction in which the BEST unit is to be established, and other jurisdictions in the country; and

19(D) whether or not an Integrated Border Enforcement Team already exists in the area in which the BEST unit would be established.

20In determining whether to establish a new BEST unit or to expand an existing BEST unit in a given jurisdiction, the Secretary shall ensure that the BEST unit under consideration does not duplicate the efforts of other existing interagency task forces or centers within that jurisdiction.

21After determining the jurisdictions in which to establish BEST units under subsection (c)(2), and in order to provide Federal assistance to such jurisdictions, the Secretary may—

22(1) direct the assignment of Federal personnel to BEST, subject to the approval of the head of the department or agency that employs such personnel; and

23(2) take other actions to assist Federal, State, local, and tribal entities to participate in BEST, including providing financial assistance, as appropriate, for operational, administrative, salary reimbursement, and technological costs associated with the participation of Federal, State, local, and tribal law enforcement agencies in BEST.

24Not later than 180 days after the date on which BEST is established under this section, and annually thereafter for the following 5 years, the Secretary shall submit a report to Congress that describes the effectiveness of BEST in enhancing border security and reducing the drug trafficking, arms smuggling, illegal alien trafficking and smuggling, violence, and kidnapping along and across the international borders of the United States, as measured by crime statistics, including violent deaths, incidents of violence, and drug-related arrests.

241.

Prevention of international child abduction

1The Secretary, through the Commissioner of U.S. Customs and Border Protection (referred to in this section as "CBP"), in coordination with the Secretary of State, the Attorney General, and the Director of the Federal Bureau of Investigation, shall establish a program that—

2(1) seeks to prevent a child (as defined in section 1204(b)(1) of title 18) from departing from the territory of the United States if a parent or legal guardian of such child presents a court order from a court of competent jurisdiction prohibiting the removal of such child from the United States to a CBP Officer in sufficient time to prevent such departure for the duration of such court order; and

3(2) leverages other existing authorities and processes to address the wrongful removal and return of a child.

4The Secretary of State shall convene and chair an interagency working group to prevent international parental child abduction. The group shall be composed of presidentially appointed, Senate confirmed officials from—

5(A) the Department of State;

6(B) the Department of Homeland Security, including U.S. Customs and Border Protection and U.S. Immigration and Customs Enforcement; and

7(C) the Department of Justice, including the Federal Bureau of Investigation.

8The Secretary of Defense shall designate an official within the Department of Defense—

9(A) to coordinate with the Department of State on international child abduction issues; and

10(B) to oversee activities designed to prevent or resolve international child abduction cases relating to active duty military service members.

242.

Department of Homeland Security Blue Campaign

1In this section, the term "human trafficking" means an act or practice described in paragraph (9) or (10) 1 of section 7102 of title 22.

2There is established within the Department a program, which shall be known as the "Blue Campaign". The Blue Campaign shall be headed by a Director, who shall be appointed by the Secretary.

3The purpose of the Blue Campaign shall be to unify and coordinate Department efforts to address human trafficking.

4The Secretary, working through the Director, shall, in accordance with subsection (e)—

5(1) issue Department-wide guidance to appropriate Department personnel;

6(2) develop training programs for such personnel;

7(3) coordinate departmental efforts, including training for such personnel; and

8(4) provide guidance and training on trauma-informed practices to ensure that human trafficking victims are afforded prompt access to victim support service providers, in addition to the assistance required under section 7105 of title 22, to address their immediate and long-term needs.

9The Blue Campaign shall provide guidance and training to Department personnel and other Federal, State, tribal, and law enforcement personnel, as appropriate, regarding—

10(1) programs to help identify instances of human trafficking;

11(2) the types of information that should be collected and recorded in information technology systems utilized by the Department to help identify individuals suspected or convicted of human trafficking;

12(3) systematic and routine information sharing within the Department and among Federal, State, tribal, and local law enforcement agencies regarding—

13(A) individuals suspected or convicted of human trafficking; and

14(B) patterns and practices of human trafficking;

15(4) techniques to identify suspected victims of trafficking along the United States border and at airport security checkpoints;

16(5) methods to be used by the Transportation Security Administration and personnel from other appropriate agencies to—

17(A) train employees of the Transportation Security Administration to identify suspected victims of trafficking; and

18(B) serve as a liaison and resource regarding human trafficking prevention to appropriate State, local, and private sector aviation workers and the traveling public;

19(6) developing and utilizing, in consultation with the Blue Campaign Advisory Board established pursuant to subsection (g), resources such as indicator cards, fact sheets, pamphlets, posters, brochures, and radio and television campaigns to—

20(A) educate partners and stakeholders; and

21(B) increase public awareness of human trafficking;

22(7) leveraging partnerships with State and local governmental, nongovernmental, and private sector organizations to raise public awareness of human trafficking; and

23(8) any other activities the Secretary determines necessary to carry out the Blue Campaign.

24To enhance training opportunities, the Director of the Blue Campaign shall develop web-based interactive training videos that utilize a learning management system to provide online training opportunities. During the 10-year period beginning on the date that is 90 days after December 27, 2021, such training opportunities shall be made available to the following individuals:

25(1) Federal, State, local, Tribal, and territorial law enforcement officers.

26(2) Non-Federal correction system personnel.

27(3) Such other individuals as the Director determines appropriate.

28There is established in the Department a Blue Campaign Advisory Board, which shall be comprised of representatives assigned by the Secretary from—

29(A) the Office for Civil Rights and Civil Liberties of the Department;

30(B) the Privacy Office of the Department; and

31(C) not fewer than four other separate components or offices of the Department.

32The Secretary is authorized to issue a charter for the Blue Campaign Advisory Board, and such charter shall specify the following:

33(A) The Board's mission, goals, and scope of its activities.

34(B) The duties of the Board's representatives.

35(C) The frequency of the Board's meetings.

36The Director shall consult the Blue Campaign Advisory Board and, as appropriate, experts from other components and offices of the Center for Countering Human Trafficking of the Department regarding the following:

37(A) Recruitment tactics used by human traffickers to inform the development of training and materials by the Blue Campaign.

38(B) The development of effective awareness tools for distribution to Federal and non-Federal officials to identify and prevent instances of human trafficking.

39(C) Identification of additional persons or entities that may be uniquely positioned to recognize signs of human trafficking and the development of materials for such persons.

40With regard to the development of programs under the Blue Campaign and the implementation of such programs, the Director is authorized to consult with State, local, Tribal, and territorial agencies, non-governmental organizations, private sector organizations, and experts.

242a.

Department of Homeland Security Center for Countering Human Trafficking

1The Secretary of Homeland Security shall operate, within U.S. Immigration and Customs Enforcement's Homeland Security Investigations, the Center for Countering Human Trafficking (referred to in this Act as "CCHT").

2The purpose of CCHT shall be to serve at the forefront of the Department of Homeland Security's unified global efforts to counter human trafficking through law enforcement operations and victim protection, prevention, and awareness programs.

3Homeland Security Investigations shall—

4(A) maintain a concept of operations that identifies CCHT participants, funding, core functions, and personnel; and

5(B) update such concept of operations, as needed, to accommodate its mission and the threats to such mission.

6The Secretary of Homeland Security shall appoint a CCHT Director, who shall—

7(i) be a member of the Senior Executive Service; and

8(ii) serve as the Department of Homeland Security's representative on human trafficking.

9Subject to appropriations, the Secretary of Homeland Security shall ensure that CCHT is staffed with at least 45 employees in order to maintain continuity of effort, subject matter expertise, and necessary support to the Department of Homeland Security, including—

10(i) employees who are responsible for the Continued Presence Program and other victim protection duties;

11(ii) employees who are responsible for training, including curriculum development, and public awareness and education;

12(iii) employees who are responsible for stakeholder engagement, Federal interagency coordination, multilateral partnerships, and policy;

13(iv) employees who are responsible for public relations, human resources, evaluation, data analysis and reporting, and information technology;

14(v) special agents and criminal analysts necessary to accomplish its mission of combating human trafficking and the importation of goods produced with forced labor; and

15(vi) managers.

16The CCHT Director shall operate, within CCHT, an Operations Unit, which shall, at a minimum—

17(1) support criminal investigations of human trafficking (including sex trafficking and forced labor)—

18(A) by developing, tracking, and coordinating leads; and

19(B) by providing subject matter expertise;

20(2) augment the enforcement of the prohibition on the importation of goods produced with forced labor through civil and criminal authorities;

21(3) coordinate a Department-wide effort to conduct procurement audits and enforcement actions, including suspension and debarment, in order to mitigate the risk of human trafficking throughout Department acquisitions and contracts; and

22(4) support all CCHT enforcement efforts with intelligence by conducting lead development, lead validation, case support, strategic analysis, and data analytics.

23The CCHT Director shall operate, within CCHT, a Protection and Awareness Programs Unit, which shall—

24(1) incorporate a victim-centered approach throughout Department of Homeland Security policies, training, and practices;

25(2) operate a comprehensive Continued Presence program;

26(3) conduct, review, and assist with Department of Homeland Security human trafficking training, screening, and identification tools and efforts;

27(4) operate the Blue Campaign's nationwide public awareness effort and any other awareness efforts needed to encourage victim identification and reporting to law enforcement and to prevent human trafficking; and

28(5) coordinate external engagement, including training and events, regarding human trafficking with critical partners, including survivors, nongovernmental organizations, corporations, multilateral entities, law enforcement agencies, and other interested parties.

242b.

Reports

1Each subagency of the Department of Homeland Security shall share with CCHT—

2(1) any information needed by CCHT to develop the strategy and proposal required under section 4(a);1 and

3(2) any additional data analysis to help CCHT better understand the issues surrounding human trafficking.

4Not later than 1 year after December 27, 2022, the CCHT Director shall submit a report to Congress that identifies any legislation that is needed to facilitate the Department of Homeland Security's mission to end human trafficking.

5Not later than 1 year after December 27, 2022, and annually thereafter, the Secretary of Homeland Security shall submit a report to Congress that includes—

6(1) the numbers of screened and identified potential victims of trafficking (as defined in section 7102(17) of title 22) at or near the international border between the United States and Mexico, including a summary of the age ranges of such victims and their countries of origin; and

7(2) an update on the Department of Homeland Security's efforts to establish protocols and methods for personnel to report human trafficking, pursuant to the Department of Homeland Security Strategy to Combat Human Trafficking, the Importation of Goods Produced with Forced Labor, and Child Sexual Exploitation, published in January 2020.

243.

Maritime operations coordination plan

1Not later than 180 days after October 5, 2018, and biennially thereafter, the Secretary shall—

2(1) update the Maritime Operations Coordination Plan, published by the Department on July 7, 2011, to strengthen coordination, planning, information sharing, and intelligence integration for maritime operations of components and offices of the Department with responsibility for maritime security missions; and

3(2) submit each update to the Committee on Commerce, Science, and Transportation and the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Transportation and Infrastructure and the Committee on Homeland Security of the House of Representatives.

4Each update shall address the following:

5(1) Coordinating the planning, integration of maritime operations, and development of joint maritime domain awareness efforts of any component or office of the Department with responsibility for maritime security missions.

6(2) Maintaining effective information sharing and, as appropriate, intelligence integration, with Federal, State, and local officials and the private sector, regarding threats to maritime security.

7(3) Cooperating and coordinating with Federal departments and agencies, and State and local agencies, in the maritime environment, in support of maritime security missions.

8(4) Highlighting the work completed within the context of other national and Department maritime security strategic guidance and how that work fits with the Maritime Operations Coordination Plan.

244.

Maritime security capabilities assessments

1Not later than 180 days after October 5, 2018, and annually thereafter, the Secretary shall submit to the Committee on Commerce, Science, and Transportation and the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Transportation and Infrastructure and the Committee on Homeland Security of the House of Representatives, an assessment of the number and type of maritime assets and the number of personnel required to increase the Department's maritime response rate pursuant to section 223 of this title.

245.

Operational data sharing capability

1Not later than 18 months after December 23, 2022, the Secretary shall, consistent with the ongoing Integrated Multi-Domain Enterprise joint effort by the Department of Homeland Security and the Department of Defense, establish a secure, centralized capability to allow real-time, or near real-time, data and information sharing between Customs and Border Protection and the Coast Guard for purposes of maritime boundary domain awareness and enforcement activities along the maritime boundaries of the United States, including the maritime boundaries in the northern and southern continental United States and Alaska.

2In establishing the capability under subsection (a), the Secretary shall prioritize enforcement areas experiencing the highest levels of enforcement activity.

3The capability established under subsection (a) shall be sufficient for the secure sharing of data, information, and surveillance necessary for operational missions, including data from governmental assets, irrespective of whether an asset located in or around mission operation areas belongs to the Coast Guard, Customs and Border Protection, or any other partner agency.

4The Commissioner of Customs and Border Protection and the Commandant shall jointly—

5(1) assess and delineate the types of data and quality of data sharing needed to meet the respective operational missions of Customs and Border Protection and the Coast Guard, including video surveillance, seismic sensors, infrared detection, space-based remote sensing, and any other data or information necessary;

6(2) develop appropriate requirements and processes for the credentialing of personnel of Customs and Border Protection and personnel of the Coast Guard to access and use the capability established under subsection (a); and

7(3) establish a cost-sharing agreement for the long-term operation and maintenance of the capability and the assets that provide data to the capability.

8Not later than 2 years after December 23, 2022, the Secretary shall submit to the Committee on Commerce, Science, and Transportation and the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Transportation and Infrastructure and the Committee on Homeland Security of the House of Representatives a report on the establishment of the capability under this section.

9Nothing in this section may be construed to authorize the Coast Guard, Customs and Border Protection, or any other partner agency to acquire, share, or transfer personal information relating to an individual in violation of any Federal or State law or regulation.

251.

Transfer of functions

1In accordance with subchapter XII (relating to transition provisions), there shall be transferred from the Commissioner of Immigration and Naturalization to the Secretary all functions performed under the following programs, and all personnel, assets, and liabilities pertaining to such programs, immediately before such transfer occurs:

2(1) The Border Patrol program.

3(2) The detention and removal program.

4(3) The intelligence program.

5(4) The investigations program.

6(5) The inspections program.

252.

U.S. Immigration and Customs Enforcement

1There shall be in the Department of Homeland Security a bureau to be known as the "Bureau of Border Security".

2The head of U.S. Immigration and Customs Enforcement shall be the Assistant Secretary of U.S. Immigration and Customs Enforcement, who—

3(A) shall report directly to the Under Secretary for Border and Transportation Security; and

4(B) shall have a minimum of 5 years professional experience in law enforcement, and a minimum of 5 years of management experience.

5The Assistant Secretary of U.S. Immigration and Customs Enforcement—

6(A) shall establish the policies for performing such functions as are—

7(i) transferred to the Under Secretary for Border and Transportation Security by section 251 of this title and delegated to the Assistant Secretary by the Under Secretary for Border and Transportation Security; or

8(ii) otherwise vested in the Assistant Secretary by law;

9(B) shall oversee the administration of such policies; and

10(C) shall advise the Under Secretary for Border and Transportation Security with respect to any policy or operation of U.S. Immigration and Customs Enforcement affecting U.S. Citizenship and Immigration Services established under part E of this subchapter, including potentially conflicting policies or operations.

11The Assistant Secretary of U.S. Immigration and Customs Enforcement shall be responsible for administering the program to collect information relating to nonimmigrant foreign students and other exchange program participants described in section 1372 of title 8, including the Student and Exchange Visitor Information System established under that section, and shall use such information to carry out the enforcement functions of the agency.

12Not later than 1 year after the date on which the transfer of functions specified under section 251 of this title takes effect, the Assistant Secretary of U.S. Immigration and Customs Enforcement shall design and implement a managerial rotation program under which employees of such agency holding positions involving supervisory or managerial responsibility and classified, in accordance with chapter 51 of title 5, as a GS–14 or above, shall—

13(i) gain some experience in all the major functions performed by such agency; and

14(ii) work in at least one local office of such agency.

15Not later than 2 years after the date on which the transfer of functions specified under section 251 of this title takes effect, the Secretary shall submit a report to the Congress on the implementation of such program.

16There shall be a position of Chief of Policy and Strategy for U.S. Immigration and Customs Enforcement.

17In consultation with U.S. Immigration and Customs Enforcement personnel in local offices, the Chief of Policy and Strategy shall be responsible for—

18(A) making policy recommendations and performing policy research and analysis on immigration enforcement issues; and

19(B) coordinating immigration policy issues with the Chief of Policy and Strategy for U.S. Citizenship and Immigration Services (established under part E of this subchapter), as appropriate.

20There shall be a principal legal advisor to the Assistant Secretary of U.S. Immigration and Customs Enforcement. The legal advisor shall provide specialized legal advice to the Assistant Secretary of U.S. Immigration and Customs Enforcement and shall represent the agency in all exclusion, deportation, and removal proceedings before the Executive Office for Immigration Review.

253.

Professional responsibility and quality review

1The Secretary shall be responsible for—

2(1) conducting investigations of noncriminal allegations of misconduct, corruption, and fraud involving any employee of U.S. Immigration and Customs Enforcement that are not subject to investigation by the Inspector General for the Department;

3(2) inspecting the operations of U.S. Immigration and Customs Enforcement and providing assessments of the quality of the operations of such agency as a whole and each of its components; and

4(3) providing an analysis of the management of U.S. Immigration and Customs Enforcement.

254.

Employee discipline

1Notwithstanding any other provision of law, the Secretary may impose disciplinary action on any employee of U.S. Immigration and Customs Enforcement and U.S. Customs and Border Protection who willfully deceives Congress or agency leadership on any matter.

255.

Report on improving enforcement functions

1The Secretary, not later than 1 year after being sworn into office, shall submit to the Committees on Appropriations and the Judiciary of the House of Representatives and of the Senate a report with a plan detailing how the Bureau of Border Security, after the transfer of functions specified under section 251 of this title takes effect, will enforce comprehensively, effectively, and fairly all the enforcement provisions of the Immigration and Nationality Act (8 U.S.C. 1101 et seq.) relating to such functions.

2In carrying out subsection (a), the Secretary of Homeland Security shall consult with the Attorney General, the Secretary of State, the Director of the Federal Bureau of Investigation, the Secretary of the Treasury, the Secretary of Labor, the Commissioner of Social Security, the Director of the Executive Office for Immigration Review, and the heads of State and local law enforcement agencies to determine how to most effectively conduct enforcement operations.

256.

Sense of Congress regarding construction of fencing near San Diego, California

1It is the sense of the Congress that completing the 14-mile border fence project required to be carried out under section 102(b) of the Illegal Immigration Reform and Immigrant Responsibility Act of 1996 (8 U.S.C. 1103 note) should be a priority for the Secretary.

257.

Report

1The Secretary of Homeland Security shall submit an annual report to the congressional committees set forth in subsection (b) that includes a description of—

2(1) the cross-border tunnels along the border between Mexico and the United States discovered during the preceding fiscal year; and

3(2) the needs of the Department of Homeland Security to effectively prevent, investigate and prosecute border tunnel construction along the border between Mexico and the United States.

4The congressional committees set forth in this subsection are—

5(1) the Committee on Homeland Security and Governmental Affairs of the Senate;

6(2) the Committee on the Judiciary of the Senate;

7(3) the Committee on Appropriations of the Senate;

8(4) the Committee on Homeland Security of the House of Representatives;

9(5) the Committee on the Judiciary of the House of Representatives; and

10(6) the Committee on Appropriations of the House of Representatives.

258.

Homeland Security Investigations Victim Assistance Program

1In this section:

2The term "forensic interview specialist" is an interview professional who has specialized experience and training in conducting trauma-informed forensic interviews with victims of crime.

3The term "victim" has the meaning given such term in section 20141(e)(2) of title 34.

4The term "victim assistance specialist" is a victim assistance professional who—

5(A) has experience working with victims of crime in a service capacity;

6(B) has been trained on the exposure of various forms of trauma and other stressors experienced in working with victims; and

7(C) may have experience working with local government and community-based organizations, including victim advocacy centers, child advocacy centers, child welfare agencies, faith-based organizations, and other social service programs.

8There is established, in Homeland Security Investigations of U.S. Immigration and Customs Enforcement, the Victim Assistance Program.

9The Victim Assistance Program shall—

10(1) provide oversight, guidance, training, travel, equipment, and coordination to Homeland Security Investigations victim assistance personnel throughout the United States;

11(2) recruit not fewer than—

12(A) 1 forensic interview specialist and 1 victim assistance specialist for each Homeland Security Investigations Special Agent in Charge office;

13(B) 1 victim assistance specialist for—

14(i) every Homeland Security Investigations office participating in a human trafficking task force; and

15(ii) every Homeland Security Investigations office participating in a child sexual exploitation task force;

16(3) support Homeland Security Investigations regional attaché offices, to the extent necessary;

17(4) provide training regarding victims' rights, victim-related policies, roles of forensic interviewers and victim assistance specialists, and an approach that is—

18(A) victim-centered;

19(B) trauma-informed; and

20(C) linguistically appropriate, to the extent feasible; and

21(5) purchase emergency items that are needed to assist identified victims in Homeland Security Investigations criminal investigations, including food, clothing, hygiene products, transportation, and temporary shelter that is not otherwise provided by a nongovernmental organization.

271.

Establishment of Bureau of Citizenship and Immigration Services

1There shall be in the Department a bureau to be known as the "Bureau of Citizenship and Immigration Services".

2The head of the Bureau of Citizenship and Immigration Services shall be the Director of the Bureau of Citizenship and Immigration Services, who—

3(A) shall report directly to the Deputy Secretary;

4(B) shall have a minimum of 5 years of management experience; and

5(C) shall be paid at the same level as the Assistant Secretary of the Bureau of Border Security.

6The Director of the Bureau of Citizenship and Immigration Services—

7(A) shall establish the policies for performing such functions as are transferred to the Director by this section or this chapter or otherwise vested in the Director by law;

8(B) shall oversee the administration of such policies;

9(C) shall advise the Deputy Secretary with respect to any policy or operation of the Bureau of Citizenship and Immigration Services that may affect the Bureau of Border Security of the Department, including potentially conflicting policies or operations;

10(D) shall establish national immigration services policies and priorities;

11(E) shall meet regularly with the Ombudsman described in section 272 of this title to correct serious service problems identified by the Ombudsman; and

12(F) shall establish procedures requiring a formal response to any recommendations submitted in the Ombudsman's annual report to Congress within 3 months after its submission to Congress.

13Not later than 1 year after the effective date specified in section 455,1 the Director of the Bureau of Citizenship and Immigration Services shall design and implement a managerial rotation program under which employees of such bureau holding positions involving supervisory or managerial responsibility and classified, in accordance with chapter 51 of title 5, as a GS–14 or above, shall—

14(i) gain some experience in all the major functions performed by such bureau; and

15(ii) work in at least one field office and one service center of such bureau.

16Not later than 2 years after the effective date specified in section 455,1 the Secretary shall submit a report to Congress on the implementation of such program.

17The Director of the Bureau of Citizenship and Immigration Services is authorized to implement innovative pilot initiatives to eliminate any remaining backlog in the processing of immigration benefit applications, and to prevent any backlog in the processing of such applications from recurring, in accordance with section 1573(a) of title 8. Such initiatives may include measures such as increasing personnel, transferring personnel to focus on areas with the largest potential for backlog, and streamlining paperwork.

18In accordance with subchapter XII (relating to transition provisions), there are transferred from the Commissioner of Immigration and Naturalization to the Director of the Bureau of Citizenship and Immigration Services the following functions, and all personnel, infrastructure, and funding provided to the Commissioner in support of such functions immediately before the effective date specified in section 455: 1

19(1) Adjudications of immigrant visa petitions.

20(2) Adjudications of naturalization petitions.

21(3) Adjudications of asylum and refugee applications.

22(4) Adjudications performed at service centers.

23(5) All other adjudications performed by the Immigration and Naturalization Service immediately before the effective date specified in section 455.1

24There shall be a position of Chief of Policy and Strategy for the Bureau of Citizenship and Immigration Services.

25In consultation with Bureau of Citizenship and Immigration Services personnel in field offices, the Chief of Policy and Strategy shall be responsible for—

26(A) making policy recommendations and performing policy research and analysis on immigration services issues; and

27(B) coordinating immigration policy issues with the Chief of Policy and Strategy for the Bureau of Border Security of the Department.

28There shall be a principal legal advisor to the Director of the Bureau of Citizenship and Immigration Services.

29The legal advisor shall be responsible for—

30(A) providing specialized legal advice, opinions, determinations, regulations, and any other assistance to the Director of the Bureau of Citizenship and Immigration Services with respect to legal matters affecting the Bureau of Citizenship and Immigration Services; and

31(B) representing the Bureau of Citizenship and Immigration Services in visa petition appeal proceedings before the Executive Office for Immigration Review.

32There shall be a Budget Officer for the Bureau of Citizenship and Immigration Services.

33The Budget Officer shall be responsible for—

34(i) formulating and executing the budget of the Bureau of Citizenship and Immigration Services;

35(ii) financial management of the Bureau of Citizenship and Immigration Services; and

36(iii) collecting all payments, fines, and other debts for the Bureau of Citizenship and Immigration Services.

37There shall be a position of Chief of the Office of Citizenship for the Bureau of Citizenship and Immigration Services.

38The Chief of the Office of Citizenship for the Bureau of Citizenship and Immigration Services shall be responsible for promoting instruction and training on citizenship responsibilities for aliens interested in becoming naturalized citizens of the United States, including the development of educational materials.

272.

Citizenship and Immigration Services Ombudsman

1Within the Department, there shall be a position of Citizenship and Immigration Services Ombudsman (in this section referred to as the "Ombudsman"). The Ombudsman shall report directly to the Deputy Secretary. The Ombudsman shall have a background in customer service as well as immigration law.

2It shall be the function of the Ombudsman—

3(1) to assist individuals and employers in resolving problems with the Bureau of Citizenship and Immigration Services;

4(2) to identify areas in which individuals and employers have problems in dealing with the Bureau of Citizenship and Immigration Services; and

5(3) to the extent possible, to propose changes in the administrative practices of the Bureau of Citizenship and Immigration Services to mitigate problems identified under paragraph (2).

6Not later than June 30 of each calendar year, the Ombudsman shall report to the Committee on the Judiciary of the House of Representatives and the Senate on the objectives of the Office of the Ombudsman for the fiscal year beginning in such calendar year. Any such report shall contain full and substantive analysis, in addition to statistical information, and—

7(A) shall identify the recommendations the Office of the Ombudsman has made on improving services and responsiveness of the Bureau of Citizenship and Immigration Services;

8(B) shall contain a summary of the most pervasive and serious problems encountered by individuals and employers, including a description of the nature of such problems;

9(C) shall contain an inventory of the items described in subparagraphs (A) and (B) for which action has been taken and the result of such action;

10(D) shall contain an inventory of the items described in subparagraphs (A) and (B) for which action remains to be completed and the period during which each item has remained on such inventory;

11(E) shall contain an inventory of the items described in subparagraphs (A) and (B) for which no action has been taken, the period during which each item has remained on such inventory, the reasons for the inaction, and shall identify any official of the Bureau of Citizenship and Immigration Services who is responsible for such inaction;

12(F) shall contain recommendations for such administrative action as may be appropriate to resolve problems encountered by individuals and employers, including problems created by excessive backlogs in the adjudication and processing of immigration benefit petitions and applications; and

13(G) shall include such other information as the Ombudsman may deem advisable.

14Each report required under this subsection shall be provided directly to the committees described in paragraph (1) without any prior comment or amendment from the Secretary, Deputy Secretary, Director of the Bureau of Citizenship and Immigration Services, or any other officer or employee of the Department or the Office of Management and Budget.

15The Ombudsman—

16(1) shall monitor the coverage and geographic allocation of local offices of the Ombudsman;

17(2) shall develop guidance to be distributed to all officers and employees of the Bureau of Citizenship and Immigration Services outlining the criteria for referral of inquiries to local offices of the Ombudsman;

18(3) shall ensure that the local telephone number for each local office of the Ombudsman is published and available to individuals and employers served by the office; and

19(4) shall meet regularly with the Director of the Bureau of Citizenship and Immigration Services to identify serious service problems and to present recommendations for such administrative action as may be appropriate to resolve problems encountered by individuals and employers.

20The Ombudsman shall have the responsibility and authority—

21(A) to appoint local ombudsmen and make available at least 1 such ombudsman for each State; and

22(B) to evaluate and take personnel actions (including dismissal) with respect to any employee of any local office of the Ombudsman.

23The Ombudsman may consult with the appropriate supervisory personnel of the Bureau of Citizenship and Immigration Services in carrying out the Ombudsman's responsibilities under this subsection.

24The Director of the Bureau of Citizenship and Immigration Services shall establish procedures requiring a formal response to all recommendations submitted to such director by the Ombudsman within 3 months after submission to such director.

25Each local ombudsman—

26(A) shall report to the Ombudsman or the delegate thereof;

27(B) may consult with the appropriate supervisory personnel of the Bureau of Citizenship and Immigration Services regarding the daily operation of the local office of such ombudsman;

28(C) shall, at the initial meeting with any individual or employer seeking the assistance of such local office, notify such individual or employer that the local offices of the Ombudsman operate independently of any other component of the Department and report directly to Congress through the Ombudsman; and

29(D) at the local ombudsman's discretion, may determine not to disclose to the Bureau of Citizenship and Immigration Services contact with, or information provided by, such individual or employer.

30Each local office of the Ombudsman shall maintain a phone, facsimile, and other means of electronic communication access, and a post office address, that is separate from those maintained by the Bureau of Citizenship and Immigration Services, or any component of the Bureau of Citizenship and Immigration Services.

273.

Professional responsibility and quality review

1The Director of the Bureau of Citizenship and Immigration Services shall be responsible for—

2(1) conducting investigations of noncriminal allegations of misconduct, corruption, and fraud involving any employee of the Bureau of Citizenship and Immigration Services that are not subject to investigation by the Inspector General for the Department;

3(2) inspecting the operations of the Bureau of Citizenship and Immigration Services and providing assessments of the quality of the operations of such bureau as a whole and each of its components; and

4(3) providing an analysis of the management of the Bureau of Citizenship and Immigration Services.

5In providing assessments in accordance with subsection (a)(2) with respect to a decision of the Bureau of Citizenship and Immigration Services, or any of its components, consideration shall be given to—

6(1) the accuracy of the findings of fact and conclusions of law used in rendering the decision;

7(2) any fraud or misrepresentation associated with the decision; and

8(3) the efficiency with which the decision was rendered.

274.

Employee discipline

1The Director of the Bureau of Citizenship and Immigration Services may, notwithstanding any other provision of law, impose disciplinary action, including termination of employment, pursuant to policies and procedures applicable to employees of the Federal Bureau of Investigation, on any employee of the Bureau of Citizenship and Immigration Services who willfully deceives Congress or agency leadership on any matter.

275.

Transition

1With respect to any function transferred by this part to, and exercised on or after the effective date specified in section 455 1 by, the Director of the Bureau of Citizenship and Immigration Services, any reference in any other Federal law, Executive order, rule, regulation, or delegation of authority, or any document of or pertaining to a component of government from which such function is transferred—

2(1) to the head of such component is deemed to refer to the Director of the Bureau of Citizenship and Immigration Services; or

3(2) to such component is deemed to refer to the Bureau of Citizenship and Immigration Services.

4Except as otherwise provided by law, a Federal official to whom a function is transferred by this part may, for purposes of performing the function, exercise all authorities under any other provision of law that were available with respect to the performance of that function to the official responsible for the performance of the function immediately before the effective date specified in section 455.1

5The personnel of the Department of Justice employed in connection with the functions transferred by this part (and functions that the Secretary determines are properly related to the functions of the Bureau of Citizenship and Immigration Services), and the assets, liabilities, contracts, property, records, and unexpended balance of appropriations, authorizations, allocations, and other funds employed, held, used, arising from, available to, or to be made available to, the Immigration and Naturalization Service in connection with the functions transferred by this part, subject to section 1531 of title 31, shall be transferred to the Director of the Bureau of Citizenship and Immigration Services for allocation to the appropriate component of the Department. Unexpended funds transferred pursuant to this paragraph shall be used only for the purposes for which the funds were originally authorized and appropriated. The Secretary shall have the right to adjust or realign transfers of funds and personnel effected pursuant to this part for a period of 2 years after the effective date specified in section 455.1

276.

Report on improving immigration services

1The Secretary, not later than 1 year after the effective date of this chapter, shall submit to the Committees on the Judiciary and Appropriations of the House of Representatives and of the Senate a report with a plan detailing how the Bureau of Citizenship and Immigration Services, after the transfer of functions specified in this part takes effect, will complete efficiently, fairly, and within a reasonable time, the adjudications described in paragraphs (1) through (5) of section 271(b) of this title.

2For each type of adjudication to be undertaken by the Director of the Bureau of Citizenship and Immigration Services, the report shall include the following:

3(1) Any potential savings of resources that may be implemented without affecting the quality of the adjudication.

4(2) The goal for processing time with respect to the application.

5(3) Any statutory modifications with respect to the adjudication that the Secretary considers advisable.

6In carrying out subsection (a), the Secretary shall consult with the Secretary of State, the Secretary of Labor, the Assistant Secretary of the Bureau of Border Security of the Department, and the Director of the Executive Office for Immigration Review to determine how to streamline and improve the process for applying for and making adjudications described in section 271(b) of this title and related processes.

277.

Report on responding to fluctuating needs

1Not later than 30 days after November 25, 2002, the Attorney General shall submit to Congress a report on changes in law, including changes in authorizations of appropriations and in appropriations, that are needed to permit the Immigration and Naturalization Service, and, after the transfer of functions specified in this part takes effect, the Bureau of Citizenship and Immigration Services of the Department, to ensure a prompt and timely response to emergent, unforeseen, or impending changes in the number of applications for immigration benefits, and otherwise to ensure the accommodation of changing immigration service needs.

278.

Application of Internet-based technologies

1The Secretary, not later than 1 year after the effective date of this chapter, in consultation with the Technology Advisory Committee established under subsection (c), shall establish an Internet-based system, that will permit a person, employer, immigrant, or nonimmigrant who has filings with the Secretary for any benefit under the Immigration and Nationality Act (8 U.S.C. 1101 et seq.), access to online information about the processing status of the filing involved.

2The Secretary, in consultation with the Technology Advisory Committee established under subsection (c), shall conduct a feasibility study on the online filing of the filings described in subsection (a). The study shall include a review of computerization and technology of the Immigration and Naturalization Service relating to the immigration services and processing of filings related to immigrant services. The study shall also include an estimate of the timeframe and cost and shall consider other factors in implementing such a filing system, including the feasibility of fee payment online.

3A report on the study under this subsection shall be submitted to the Committees on the Judiciary of the House of Representatives and the Senate not later than 1 year after the effective date of this chapter.

4The Secretary shall establish, not later than 60 days after the effective date of this chapter, an advisory committee (in this section referred to as the "Technology Advisory Committee") to assist the Secretary in—

5(A) establishing the tracking system under subsection (a); and

6(B) conducting the study under subsection (b).

7The Technology Advisory Committee shall be established after consultation with the Committees on the Judiciary of the House of Representatives and the Senate.

8The Technology Advisory Committee shall be composed of representatives from high technology companies capable of establishing and implementing the system in an expeditious manner, and representatives of persons who may use the tracking system described in subsection (a) and the online filing system described in subsection (b)(1).

279.

Children's affairs

1There are transferred to the Director of the Office of Refugee Resettlement of the Department of Health and Human Services functions under the immigration laws of the United States with respect to the care of unaccompanied alien children that were vested by statute in, or performed by, the Commissioner of Immigration and Naturalization (or any officer, employee, or component of the Immigration and Naturalization Service) immediately before the effective date specified in subsection (d).

2Pursuant to the transfer made by subsection (a), the Director of the Office of Refugee Resettlement shall be responsible for—

3(A) coordinating and implementing the care and placement of unaccompanied alien children who are in Federal custody by reason of their immigration status, including developing a plan to be submitted to Congress on how to ensure that qualified and independent legal counsel is timely appointed to represent the interests of each such child, consistent with the law regarding appointment of counsel that is in effect on November 25, 2002;

4(B) ensuring that the interests of the child are considered in decisions and actions relating to the care and custody of an unaccompanied alien child;

5(C) making placement determinations for all unaccompanied alien children who are in Federal custody by reason of their immigration status;

6(D) implementing the placement determinations;

7(E) implementing policies with respect to the care and placement of unaccompanied alien children;

8(F) identifying a sufficient number of qualified individuals, entities, and facilities to house unaccompanied alien children;

9(G) overseeing the infrastructure and personnel of facilities in which unaccompanied alien children reside;

10(H) reuniting unaccompanied alien children with a parent abroad in appropriate cases;

11(I) compiling, updating, and publishing at least annually a state-by-state list of professionals or other entities qualified to provide guardian and attorney representation services for unaccompanied alien children;

12(J) maintaining statistical information and other data on unaccompanied alien children for whose care and placement the Director is responsible, which shall include—

13(i) biographical information, such as a child's name, gender, date of birth, country of birth, and country of habitual residence;

14(ii) the date on which the child came into Federal custody by reason of his or her immigration status;

15(iii) information relating to the child's placement, removal, or release from each facility in which the child has resided;

16(iv) in any case in which the child is placed in detention or released, an explanation relating to the detention or release; and

17(v) the disposition of any actions in which the child is the subject;

18(K) collecting and compiling statistical information from the Department of Justice, the Department of Homeland Security, and the Department of State on each department's actions relating to unaccompanied alien children; and

19(L) conducting investigations and inspections of facilities and other entities in which unaccompanied alien children reside, including regular follow-up visits to such facilities, placements, and other entities, to assess the continued suitability of such placements.

20In making determinations described in paragraph (1)(C), the Director of the Office of Refugee Resettlement—

21(A) shall consult with appropriate juvenile justice professionals, the Director of the Bureau of Citizenship and Immigration Services, and the Assistant Secretary of the Bureau of Border Security to ensure that such determinations ensure that unaccompanied alien children described in such subparagraph—

22(i) are likely to appear for all hearings or proceedings in which they are involved;

23(ii) are protected from smugglers, traffickers, or others who might seek to victimize or otherwise engage them in criminal, harmful, or exploitive activity; and

24(iii) are placed in a setting in which they are not likely to pose a danger to themselves or others; and

25(B) shall not release such children upon their own recognizance.

26In carrying out the duties described in paragraph (1), the Director of the Office of Refugee Resettlement is encouraged to use the refugee children foster care system established pursuant to section 412(d) of the Immigration and Nationality Act (8 U.S.C. 1522(d)) for the placement of unaccompanied alien children.

27Nothing in paragraph (2)(B) may be construed to require that a bond be posted for an unaccompanied alien child who is released to a qualified sponsor.

28Nothing in this section may be construed to transfer the responsibility for adjudicating benefit determinations under the Immigration and Nationality Act (8 U.S.C. 1101 et seq.) from the authority of any official of the Department of Justice, the Department of Homeland Security, or the Department of State.

29Notwithstanding section 4,1 this section shall take effect on the date on which the transfer of functions specified under section 251 of this title takes effect.

30With respect to any function transferred by this section, any reference in any other Federal law, Executive order, rule, regulation, or delegation of authority, or any document of or pertaining to a component of government from which such function is transferred—

31(1) to the head of such component is deemed to refer to the Director of the Office of Refugee Resettlement; or

32(2) to such component is deemed to refer to the Office of Refugee Resettlement of the Department of Health and Human Services.

33Except as otherwise provided by law, a Federal official to whom a function is transferred by this section may, for purposes of performing the function, exercise all authorities under any other provision of law that were available with respect to the performance of that function to the official responsible for the performance of the function immediately before the effective date specified in subsection (d).

34Subsections (a), (b), and (c) of section 552 of this title shall apply to a transfer of functions under this section in the same manner as such provisions apply to a transfer of functions under this chapter to the Department of Homeland Security.

35The personnel of the Department of Justice employed in connection with the functions transferred by this section, and the assets, liabilities, contracts, property, records, and unexpended balance of appropriations, authorizations, allocations, and other funds employed, held, used, arising from, available to, or to be made available to, the Immigration and Naturalization Service in connection with the functions transferred by this section, subject to section 1531 of title 31, shall be transferred to the Director of the Office of Refugee Resettlement for allocation to the appropriate component of the Department of Health and Human Services. Unexpended funds transferred pursuant to this paragraph shall be used only for the purposes for which the funds were originally authorized and appropriated.

36As used in this section—

37(1) the term "placement" means the placement of an unaccompanied alien child in either a detention facility or an alternative to such a facility; and

38(2) the term "unaccompanied alien child" means a child who—

39(A) has no lawful immigration status in the United States;

40(B) has not attained 18 years of age; and

41(C) with respect to whom—

42(i) there is no parent or legal guardian in the United States; or

43(ii) no parent or legal guardian in the United States is available to provide care and physical custody.

291.

Abolishment of INS

1Upon completion of all transfers from the Immigration and Naturalization Service as provided for by this chapter, the Immigration and Naturalization Service of the Department of Justice is abolished.

2The authority provided by section 542 of this title may be used to reorganize functions or organizational units within the Bureau of Border Security or the Bureau of Citizenship and Immigration Services, but may not be used to recombine the two bureaus into a single agency or otherwise to combine, join, or consolidate functions or organizational units of the two bureaus with each other.

292.

Voluntary separation incentive payments

1For purposes of this section—

2(1) the term "employee" means an employee (as defined by section 2105 of title 5) who—

3(A) has completed at least 3 years of current continuous service with 1 or more covered entities; and

4(B) is serving under an appointment without time limitation,

5but does not include any person under subparagraphs (A)–(G) of section 663(a)(2) of Public Law 104–208 (5 U.S.C. 5597 note);

6(2) the term "covered entity" means—

7(A) the Immigration and Naturalization Service;

8(B) the Bureau of Border Security of the Department of Homeland Security; and

9(C) the Bureau of Citizenship and Immigration Services of the Department of Homeland Security; and

10(3) the term "transfer date" means the date on which the transfer of functions specified under section 251 of this title takes effect.

11Before the Attorney General or the Secretary obligates any resources for voluntary separation incentive payments under this section, such official shall submit to the appropriate committees of Congress a strategic restructuring plan, which shall include—

12(1) an organizational chart depicting the covered entities after their restructuring pursuant to this chapter;

13(2) a summary description of how the authority under this section will be used to help carry out that restructuring; and

14(3) the information specified in section 663(b)(2) of Public Law 104–208 (5 U.S.C. 5597 note).

15As used in the preceding sentence, the "appropriate committees of Congress" are the Committees on Appropriations, Government Reform, and the Judiciary of the House of Representatives, and the Committees on Appropriations, Governmental Affairs, and the Judiciary of the Senate.

16The Attorney General and the Secretary may, to the extent necessary to help carry out their respective strategic restructuring plan described in subsection (b), make voluntary separation incentive payments to employees. Any such payment—

17(1) shall be paid to the employee, in a lump sum, after the employee has separated from service;

18(2) shall be paid from appropriations or funds available for the payment of basic pay of the employee;

19(3) shall be equal to the lesser of—

20(A) the amount the employee would be entitled to receive under section 5595(c) of title 5; or

21(B) an amount not to exceed $25,000, as determined by the Attorney General or the Secretary;

22(4) may not be made except in the case of any qualifying employee who voluntarily separates (whether by retirement or resignation) before the end of—

23(A) the 3-month period beginning on the date on which such payment is offered or made available to such employee; or

24(B) the 3-year period beginning on November 25, 2002,

25whichever occurs first;

26(5) shall not be a basis for payment, and shall not be included in the computation, of any other type of Government benefit; and

27(6) shall not be taken into account in determining the amount of any severance pay to which the employee may be entitled under section 5595 of title 5, based on any other separation.

28In addition to any payments which it is otherwise required to make, the Department of Justice and the Department of Homeland Security shall, for each fiscal year with respect to which it makes any voluntary separation incentive payments under this section, remit to the Office of Personnel Management for deposit in the Treasury of the United States to the credit of the Civil Service Retirement and Disability Fund the amount required under paragraph (2).

29The amount required under this paragraph shall, for any fiscal year, be the amount under subparagraph (A) or (B), whichever is greater.

30The amount under this subparagraph shall, for any fiscal year, be equal to the minimum amount necessary to offset the additional costs to the retirement systems under title 5 (payable out of the Civil Service Retirement and Disability Fund) resulting from the voluntary separation of the employees described in paragraph (3), as determined under regulations of the Office of Personnel Management.

31The amount under this subparagraph shall, for any fiscal year, be equal to 45 percent of the sum total of the final basic pay of the employees described in paragraph (3).

32The employees described in this paragraph are those employees who receive a voluntary separation incentive payment under this section based on their separating from service during the fiscal year with respect to which the payment under this subsection relates.

33In this subsection, the term "final basic pay" means, with respect to an employee, the total amount of basic pay which would be payable for a year of service by such employee, computed using the employee's final rate of basic pay, and, if last serving on other than a full-time basis, with appropriate adjustment therefor.

34An individual who receives a voluntary separation incentive payment under this section and who, within 5 years after the date of the separation on which the payment is based, accepts any compensated employment with the Government or works for any agency of the Government through a personal services contract, shall be required to pay, prior to the individual's first day of employment, the entire amount of the incentive payment. Such payment shall be made to the covered entity from which the individual separated or, if made on or after the transfer date, to the Deputy Secretary or the Under Secretary for Border and Transportation Security (for transfer to the appropriate component of the Department of Homeland Security, if necessary).

35Voluntary separations under this section are not intended to necessarily reduce the total number of full-time equivalent positions in any covered entity.

36A covered entity may redeploy or use the full-time equivalent positions vacated by voluntary separations under this section to make other positions available to more critical locations or more critical occupations.

293.

Authority to conduct a demonstration project relating to disciplinary action

1The Attorney General and the Secretary may each, during a period ending not later than 5 years after November 25, 2002, conduct a demonstration project for the purpose of determining whether one or more changes in the policies or procedures relating to methods for disciplining employees would result in improved personnel management.

2A demonstration project under this section—

3(1) may not cover any employees apart from those employed in or under a covered entity; and

4(2) shall not be limited by any provision of chapter 43, 75, or 77 of title 5.

5Under the demonstration project—

6(1) the use of alternative means of dispute resolution (as defined in section 571 of title 5) shall be encouraged, whenever appropriate; and

7(2) each covered entity under the jurisdiction of the official conducting the project shall be required to provide for the expeditious, fair, and independent review of any action to which section 4303 or subchapter II of chapter 75 of such title 5 would otherwise apply (except an action described in section 7512(5) of such title 5).

8Notwithstanding any other provision of this section, if, in the case of any matter described in section 7702(a)(1)(B) of title 5, there is no judicially reviewable action under the demonstration project within 120 days after the filing of an appeal or other formal request for review (referred to in subsection (c)(2)), an employee shall be entitled to file a civil action to the same extent and in the same manner as provided in section 7702(e)(1) of such title 5 (in the matter following subparagraph (C) thereof).

9Employees shall not be included within any project under this section if such employees are—

10(1) neither managers nor supervisors; and

11(2) within a unit with respect to which a labor organization is accorded exclusive recognition under chapter 71 of title 5.

12Notwithstanding the preceding sentence, an aggrieved employee within a unit (referred to in paragraph (2)) may elect to participate in a complaint procedure developed under the demonstration project in lieu of any negotiated grievance procedure and any statutory procedure (as such term is used in section 7121 of such title 5).

13The Government Accountability Office shall prepare and submit to the Committees on Government Reform and the Judiciary of the House of Representatives and the Committees on Governmental Affairs and the Judiciary of the Senate periodic reports on any demonstration project conducted under this section, such reports to be submitted after the second and fourth years of its operation. Upon request, the Attorney General or the Secretary shall furnish such information as the Government Accountability Office may require to carry out this subsection.

14In this section, the term "covered entity" has the meaning given such term in section 292(a)(2) of this title.

294.

Sense of Congress

1It is the sense of Congress that—

2(1) the missions of the Bureau of Border Security and the Bureau of Citizenship and Immigration Services are equally important and, accordingly, they each should be adequately funded; and

3(2) the functions transferred under this part should not, after such transfers take effect, operate at levels below those in effect prior to November 25, 2002.

295.

Director of Shared Services

1Within the Office of Deputy Secretary, there shall be a Director of Shared Services.

2The Director of Shared Services shall be responsible for the coordination of resources for the Bureau of Border Security and the Bureau of Citizenship and Immigration Services, including—

3(1) information resources management, including computer databases and information technology;

4(2) records and file management; and

5(3) forms management.

296.

Separation of funding

1There shall be established separate accounts in the Treasury of the United States for appropriated funds and other deposits available for the Bureau of Citizenship and Immigration Services and the Bureau of Border Security.

2To ensure that the Bureau of Citizenship and Immigration Services and the Bureau of Border Security are funded to the extent necessary to fully carry out their respective functions, the Director of the Office of Management and Budget shall separate the budget requests for each such entity.

3Fees imposed for a particular service, application, or benefit shall be deposited into the account established under subsection (a) that is for the bureau with jurisdiction over the function to which the fee relates.

4No fee may be transferred between the Bureau of Citizenship and Immigration Services and the Bureau of Border Security for purposes not authorized by section 1356 of title 8.

297.

Reports and implementation plans

1The Secretary, not later than 120 days after the effective date of this chapter, shall submit to the Committees on Appropriations and the Judiciary of the House of Representatives and of the Senate a report on the proposed division and transfer of funds, including unexpended funds, appropriations, and fees, between the Bureau of Citizenship and Immigration Services and the Bureau of Border Security.

2The Secretary, not later than 120 days after the effective date of this chapter, shall submit to the Committees on Appropriations and the Judiciary of the House of Representatives and of the Senate a report on the proposed division of personnel between the Bureau of Citizenship and Immigration Services and the Bureau of Border Security.

3The Secretary, not later than 120 days after the effective date of this chapter, and every 6 months thereafter until the termination of fiscal year 2005, shall submit to the Committees on Appropriations and the Judiciary of the House of Representatives and of the Senate an implementation plan to carry out this chapter.

4The implementation plan should include details concerning the separation of the Bureau of Citizenship and Immigration Services and the Bureau of Border Security, including the following:

5(A) Organizational structure, including the field structure.

6(B) Chain of command.

7(C) Procedures for interaction among such bureaus.

8(D) Fraud detection and investigation.

9(E) The processing and handling of removal proceedings, including expedited removal and applications for relief from removal.

10(F) Recommendations for conforming amendments to the Immigration and Nationality Act (8 U.S.C. 1101 et seq.).

11(G) Establishment of a transition team.

12(H) Methods to phase in the costs of separating the administrative support systems of the Immigration and Naturalization Service in order to provide for separate administrative support systems for the Bureau of Citizenship and Immigration Services and the Bureau of Border Security.

13Not later than 18 months after the date on which the transfer of functions specified under section 251 of this title takes effect, and every 6 months thereafter, until full implementation of this part has been completed, the Comptroller General of the United States shall submit to the Committees on Appropriations and on the Judiciary of the House of Representatives and the Senate a report containing the following:

14(A) A determination of whether the transfers of functions made by parts D and E of this subchapter have been completed, and if a transfer of functions has not taken place, identifying the reasons why the transfer has not taken place.

15(B) If the transfers of functions made by parts D and E of this subchapter have been completed, an identification of any issues that have arisen due to the completed transfers.

16(C) An identification of any issues that may arise due to any future transfer of functions.

17Not later than 4 years after the date on which the transfer of functions specified under section 251 of this title takes effect, the Comptroller General of the United States shall submit to the Committees on Appropriations and on the Judiciary of the House of Representatives and the Senate a report, following a study, containing the following:

18(A) Determinations of whether the transfer of functions from the Immigration and Naturalization Service to the Bureau of Citizenship and Immigration Services and the Bureau of Border Security have improved, with respect to each function transferred, the following:

19(i) Operations.

20(ii) Management, including accountability and communication.

21(iii) Financial administration.

22(iv) Recordkeeping, including information management and technology.

23(B) A statement of the reasons for the determinations under subparagraph (A).

24(C) Any recommendations for further improvements to the Bureau of Citizenship and Immigration Services and the Bureau of Border Security.

25Not later than 1 year after November 25, 2002, the Comptroller General of the United States shall submit to the Committees on the Judiciary of the House of Representatives and of the Senate a report examining whether the Bureau of Citizenship and Immigration Services is likely to derive sufficient funds from fees to carry out its functions in the absence of appropriated funds.

298.

Immigration functions

1One year after November 25, 2002, and each year thereafter, the Secretary shall submit a report to the President, to the Committees on the Judiciary and Government Reform of the House of Representatives, and to the Committees on the Judiciary and Government Affairs of the Senate, on the impact the transfers made by this part has had on immigration functions.

2The report shall address the following with respect to the period covered by the report:

3(A) The aggregate number of all immigration applications and petitions received, and processed, by the Department.

4(B) Region-by-region statistics on the aggregate number of immigration applications and petitions filed by an alien (or filed on behalf of an alien) and denied, disaggregated by category of denial and application or petition type.

5(C) The quantity of backlogged immigration applications and petitions that have been processed, the aggregate number awaiting processing, and a detailed plan for eliminating the backlog.

6(D) The average processing period for immigration applications and petitions, disaggregated by application or petition type.

7(E) The number and types of immigration-related grievances filed with any official of the Department of Justice, and if those grievances were resolved.

8(F) Plans to address grievances and improve immigration services.

9(G) Whether immigration-related fees were used consistent with legal requirements regarding such use.

10(H) Whether immigration-related questions conveyed by customers to the Department (whether conveyed in person, by telephone, or by means of the Internet) were answered effectively and efficiently.

11It is the sense of Congress that—

12(1) the quality and efficiency of immigration services rendered by the Federal Government should be improved after the transfers made by this part take effect; and

13(2) the Secretary should undertake efforts to guarantee that concerns regarding the quality and efficiency of immigration services are addressed after such effective date.

301.

Fee agreements for certain services at ports of entry

1Notwithstanding section 58c(e) of title 19 and section 1451 of title 19, the Commissioner of U.S. Customs and Border Protection, upon the request of any entity, may enter into a fee agreement with such entity under which—

2(1) U.S. Customs and Border Protection shall provide services described in subsection (b) at a United States port of entry or any other facility at which U.S. Customs and Border Protection provides or will provide such services;

3(2) such entity shall remit to U.S. Customs and Border Protection a fee imposed under subsection (h) in an amount equal to the full costs that are incurred or will be incurred in providing such services; and

4(3) if space is provided by such entity, each facility at which U.S. Customs and Border Protection services are performed shall be maintained and equipped by such entity, without cost to the Federal Government, in accordance with U.S. Customs and Border Protection specifications.

5The services described in this subsection are any activities of any employee or Office of Field Operations contractor of U.S. Customs and Border Protection (except employees of the U.S. Border Patrol, as established under section 211(e) of this title) pertaining to, or in support of, customs, agricultural processing, border security, or immigration inspection-related matters at a port of entry or any other facility at which U.S. Customs and Border Protection provides or will provide services.

6The Commissioner of U.S. Customs and Border Protection, at the request of an entity who has previously entered into an agreement with U.S. Customs and Border Protection for the reimbursement of fees in effect on December 16, 2016, may modify such agreement to implement any provisions of this section.

7The Commissioner of U.S. Customs and Border Protection—

8(A) may enter into fee agreements under this section only for services that—

9(i) will increase or enhance the operational capacity of U.S. Customs and Border Protection based on available staffing and workload; and

10(ii) will not shift the cost of services funded in any appropriations Act, or provided from any account in the Treasury of the United States derived by the collection of fees, to entities under this chapter; and

11(B) may not enter into a fee agreement under this section if such agreement would unduly and permanently impact services funded in any appropriations Act, or provided from any account in the Treasury of the United States, derived by the collection of fees.

12There shall be no limit to the number of fee agreements that the Commissioner of U.S. Customs and Border Protection may enter into under this section.

13Except as otherwise provided in this subsection, a fee agreement for U.S. Customs and Border Protection services at an air port of entry may only provide for the payment of overtime costs of U.S. Customs and Border Protection officers and salaries and expenses of U.S. Customs and Border Protection employees to support U.S. Customs and Border Protection officers in performing services described in subsection (b).

14Notwithstanding paragraph (1), U.S. Customs and Border Protection may receive reimbursement in addition to overtime costs if the fee agreement is for services at an air port of entry that has fewer than 100,000 arriving international passengers annually.

15In addition to costs described in paragraph (1), a fee agreement for U.S. Customs and Border Protection services at an air port of entry referred to in paragraph (2) may provide for the reimbursement of—

16(A) salaries and expenses of not more than five full-time equivalent U.S. Customs and Border Protection Officers beyond the number of such officers assigned to the port of entry on the date on which the fee agreement was signed;

17(B) salaries and expenses of employees of U.S. Customs and Border Protection, other than the officers referred to in subparagraph (A), to support U.S. Customs and Border Protection officers in performing law enforcement functions; and

18(C) other costs incurred by U.S. Customs and Border Protection relating to services described in subparagraph (B), such as temporary placement or permanent relocation of employees, including incentive pay for relocation, as appropriate.

19The Commissioner of U.S. Customs and Border Protection shall ensure that each fee agreement proposal is given equal consideration regardless of the size of the port of entry.

20If the Commissioner of U.S. Customs and Border Protection denies a proposal for a fee agreement under this section, the Commissioner shall provide the entity submitting such proposal with the reason for the denial unless—

21(A) the reason for the denial is law enforcement sensitive; or

22(B) withholding the reason for the denial is in the national security interests of the United States.

23Decisions of the Commissioner of U.S. Customs and Border Protection under paragraph (1) are in the discretion of the Commissioner and are not subject to judicial review.

24The amount of the fee to be charged under an agreement authorized under subsection (a) shall be paid by each entity requesting U.S. Customs and Border Protection services, and shall be for the full cost of providing such services, including the salaries and expenses of employees and contractors of U.S. Customs and Border Protection, to provide such services and other costs incurred by U.S. Customs and Border Protection relating to such services, such as temporary placement or permanent relocation of such employees and contractors.

25The Commissioner of U.S. Customs and Border Protection may require that the fee referred to in paragraph (1) be paid by each entity that has entered into a fee agreement under subsection (a) with U.S. Customs and Border Protection in advance of the performance of U.S. Customs and Border Protection services.

26The Commissioner of U.S. Customs and Border Protection shall develop a process to oversee the services for which fees are charged pursuant to an agreement under subsection (a), including—

27(A) a determination and report on the full costs of providing such services, and a process for increasing such fees, as necessary;

28(B) the establishment of a periodic remittance schedule to replenish appropriations, accounts, or funds, as necessary; and

29(C) the identification of costs paid by such fees.

30Funds collected pursuant to any agreement entered into pursuant to subsection (a)—

31(A) shall be deposited as offsetting collections;

32(B) shall remain available until expended without fiscal year limitation; and

33(C) shall be credited to the applicable appropriation, account, or fund for the amount paid out of such appropriation, account, or fund for any expenses incurred or to be incurred by U.S. Customs and Border Protection in providing U.S. Customs and Border Protection services under any such agreement and any other costs incurred or to be incurred by U.S. Customs and Border Protection relating to such services.

34The Commissioner of U.S. Customs and Border Protection shall return any unused funds collected and deposited into the account described in paragraph (1) if a fee agreement entered into pursuant to subsection (a) is terminated for any reason or the terms of such fee agreement change by mutual agreement to cause a reduction of U.S. Customs and Border Protections 1 services. No interest shall be owed upon the return of any such unused funds.

35The Commissioner of U.S. Customs and Border Protection shall terminate the services provided pursuant to a fee agreement entered into under subsection (a) with an entity that, after receiving notice from the Commissioner that a fee under subsection (h) is due, fails to pay such fee in a timely manner. If such services are terminated, all costs incurred by U.S. Customs and Border Protection that have not been paid shall become immediately due and payable. Interest on unpaid fees shall accrue based on the rate and amount established under sections 6621 and 6622 of title 26.

36Any entity that, after notice and demand for payment of any fee under subsection (h), fails to pay such fee in a timely manner shall be liable for a penalty or liquidated damage equal to two times the amount of such fee. Any such amount collected under this paragraph shall be deposited into the appropriate account specified under subsection (i) and shall be available as described in such subsection.

37Any entity who has previously entered into an agreement with U.S. Customs and Border Protection for the reimbursement of fees in effect on December 16, 2016, or under the provisions of this section, may request that such agreement be amended to provide for termination upon advance notice, length, and terms that are negotiated between such entity and U.S. Customs and Border Protection.

38The Commissioner of U.S. Customs and Border Protection shall—

39(1) submit an annual report identifying the activities undertaken and the agreements entered into pursuant to this section to—

40(A) the Committee on Appropriations of the Senate;

41(B) the Committee on Finance of the Senate;

42(C) the Committee on Homeland Security and Governmental Affairs of the Senate;

43(D) the Committee on the Judiciary of the Senate;

44(E) the Committee on Appropriations of the House of Representatives;

45(F) the Committee on Homeland Security of the House of Representatives;

46(G) the Committee on the Judiciary of the House of Representatives; and

47(H) the Committee on Ways and Means of the House of Representatives; and

48(2) not later than 15 days before entering into a fee agreement, notify the members of Congress that represent the State or Congressional District in which the affected port of entry or facility is located of such agreement.

49Nothing in this section may be construed as imposing on U.S. Customs and Border Protection any responsibilities, duties, or authorities relating to real property.

301a.

Port of entry donation authority

1The Commissioner of U.S. Customs and Border Protection, in consultation with the Administrator of General Services, may enter into an agreement with any entity to accept a donation of personal property, money, or nonpersonal services for the uses described in paragraph (3) only with respect to the following locations at which U.S. Customs and Border Protection performs or will be performing inspection services:

2(A) A new or existing sea or air port of entry.

3(B) An existing Federal Government-owned or -leased land port of entry.

4(C) A new Federal Government-owned or -leased land port of entry if—

5(i) the fair market value of the donation is $75,000,000 or less; and

6(ii) the fair market value of donations with respect to the land port of entry total $75,000,000 or less over the preceding five years.

7Any monetary donation accepted pursuant to this subsection may not be used to pay the salaries of U.S. Customs and Border Protection employees performing inspection services.

8Donations accepted pursuant to this subsection may be used for activities of the Office of Field Operations set forth in subparagraphs (A) through (F) of section 211(g)(3) of this title, which are related to a new or existing sea or air port of entry or a new or existing Federal Government-owned or -leased land port of entry described in paragraph (1), including expenses related to—

9(A) furniture, fixtures, equipment, or technology, including the installation or deployment of such items; and

10(B) the operation and maintenance of such furniture, fixtures, equipment, or technology.

11Subject to paragraph (3), the Commissioner of U.S. Customs and Border Protection, and the Administrator of General Services, as applicable, may enter into an agreement with any entity to accept a donation of real property or money for uses described in paragraph (2) only with respect to the following locations at which U.S. Customs and Border Protection performs or will be performing inspection services:

12(A) A new or existing sea or air port of entry.

13(B) An existing Federal Government-owned land port of entry.

14(C) A new Federal Government-owned land port of entry if—

15(i) the fair market value of the donation is $75,000,000 or less; and

16(ii) the fair market value of donations with respect to the land port of entry total $75,000,000 or less over the preceding five years.

17Donations accepted pursuant to this subsection may be used for activities of the Office of Field Operations set forth in section 211(g) of this title, which are related to the construction, alteration, operation, or maintenance of a new or existing sea or air port of entry or a new or existing a 1 Federal Government-owned land port of entry described in paragraph (1), including expenses related to—

18(A) land acquisition, design, construction, repair, or alteration; and

19(B) operation and maintenance of such port of entry facility.

20A donation of real property under this subsection at an existing land port of entry owned by the General Services Administration may only be accepted by the Administrator of General Services.

21The authority to enter into an agreement under this subsection shall terminate on December 31, 2026.

22The termination date referred to in subparagraph (A) shall not apply to a proposal accepted for consideration by U.S. Customs and Border Protection or the General Services Administration pursuant to this section or a prior pilot program prior to such termination date.

23An agreement entered into under subsection (a) or (b) (and, in the case of such subsection (b), in accordance with paragraph (4) of such subsection) may last as long as required to meet the terms of such agreement.

24In carrying out an agreement entered into under subsection (a) or (b), the Commissioner of U.S. Customs and Border Protection, in consultation with the Administrator of General Services, shall establish criteria regarding—

25(A) the selection and evaluation of donors;

26(B) the identification of roles and responsibilities between U.S. Customs and Border Protection, the General Services Administration, and donors;

27(C) the identification, allocation, and management of explicit and implicit risks of partnering between the Federal Government and donors;

28(D) decision-making and dispute resolution processes; and

29(E) processes for U.S. Customs and Border Protection, and the General Services Administration, as applicable, to terminate agreements if selected donors are not meeting the terms of any such agreement, including the security standards established by U.S. Customs and Border Protection.

30The Commissioner of U.S. Customs and Border Protection, in consultation with the Administrator of General Services, as applicable, shall—

31(i) establish criteria for evaluating a proposal to enter into an agreement under subsection (a) or (b); and

32(ii) make such criteria publicly available.

33Criteria established pursuant to subparagraph (A) shall consider—

34(i) the impact of a proposal referred to in such subparagraph on the land, sea, or air port of entry at issue and other ports of entry or similar facilities or other infrastructure near the location of the proposed donation;

35(ii) such proposal's potential to increase trade and travel efficiency through added capacity;

36(iii) such proposal's potential to enhance the security of the port of entry at issue;

37(iv) the impact of the proposal on reducing wait times at that port of entry or facility and other ports of entry on the same border;

38(v) for a donation under subsection (b)—

39(I) whether such donation satisfies the requirements of such proposal, or whether additional real property would be required; and

40(II) how such donation was acquired, including if eminent domain was used;

41(vi) the funding available to complete the intended use of such donation;

42(vii) the costs of maintaining and operating such donation;

43(viii) the impact of such proposal on U.S. Customs and Border Protection staffing requirements; and

44(ix) other factors that the Commissioner or Administrator determines to be relevant.

45Not later than 60 days after receiving the proposals for a donation agreement from an entity, the Commissioner of U.S. Customs and Border Protection shall notify such entity as to whether such proposal is complete or incomplete.

46If the Commissioner of U.S. Customs and Border Protection determines that a proposal is incomplete, the Commissioner shall—

47(aa) notify the appropriate entity and provide such entity with a description of all information or material that is needed to complete review of the proposal; and

48(bb) allow the entity to resubmit the proposal with additional information and material described in item (aa) to complete the proposal.

49Not later than 180 days after receiving a completed proposal to enter into an agreement under subsection (a) or (b), the Commissioner of U.S. Customs and Border Protection, with the concurrence of the Administrator of General Services, as applicable, shall—

50(I) determine whether to approve or deny such proposal; and

51(II) notify the entity that submitted such proposal of such determination.

52Except as required under section 3307 of title 40, real property donations to the Administrator of General Services made pursuant to subsection 1 (a) and 1 (b) at a GSA-owned land port of entry may be used in addition to any other funding for such purpose, including appropriated funds, property, or services.

53The Commissioner of U.S. Customs and Border Protection, or the Administrator of General Services, as applicable, may return any donation made pursuant to subsection (a) or (b). No interest shall be owed to the donor with respect to any donation provided under such subsections that is returned pursuant to this subsection.

54Except as provided in subsections (a) and (b) regarding the acceptance of donations, the Commissioner of U.S. Customs and Border Protection and the Administrator of General Services, as applicable, may not, with respect to an agreement entered into under either of such subsections, obligate or expend amounts in excess of amounts that have been appropriated pursuant to any appropriations Act for purposes specified in either of such subsections or otherwise made available for any of such purposes.

55Before accepting any donations pursuant to an agreement under subsection (a) or (b), the Commissioner of U.S. Customs and Border Protection shall certify to the congressional committees set forth in paragraph (7) that 2

56(i) the donation will not be used for the construction of a detention facility or a border fence or wall; and

57(ii) the donor will be notified in the Donations Acceptance Agreement that the donor shall be financially responsible for all costs and operating expenses related to the operation, maintenance, and repair of the donated real property until such time as U.S. Customs and Border Protection provides the donor written notice otherwise.

58The Commissioner of U.S. Customs and Border Protection, in collaboration with the Administrator of General Services, as applicable, shall submit an annual report identifying the activities undertaken and agreements entered into pursuant to subsections (a) and (b) to—

59(A) the Committee on Appropriations of the Senate;

60(B) the Committee on Environment and Public Works of the Senate;

61(C) the Committee on Finance of the Senate;

62(D) the Committee on Homeland Security and Governmental Affairs of the Senate;

63(E) the Committee on the Judiciary of the Senate;

64(F) the Committee on Appropriations of the House of Representatives;

65(G) the Committee on Homeland Security of the House of Representatives;

66(H) the Committee on the Judiciary of the House of Representatives;

67(I) the Committee on Transportation and Infrastructure of the House of Representatives; and

68(J) the Committee on Ways and Means of the House of Representatives.

69The Comptroller General of the United States shall submit an 3 biennial report to the congressional committees referred to in subsection (c)(7) that evaluates—

70(1) fee agreements entered into pursuant to section 301 of this title;

71(2) donation agreements entered into pursuant to subsections (a) and (b); and

72(3) the fees and donations received by U.S. Customs and Border Protection pursuant to such agreements.

73Decisions of the Commissioner of U.S. Customs and Border Protection and the Administrator of General Services under this section regarding the acceptance of real or personal property are in the discretion of the Commissioner and the Administrator and are not subject to judicial review.

74Except as otherwise provided in this section, nothing in this section may be construed as affecting in any manner the responsibilities, duties, or authorities of U.S. Customs and Border Protection or the General Services Administration.

301b.

Current and proposed agreements

1Nothing in this part or in section 4 of the Cross-Border Trade Enhancement Act of 2016 may be construed as affecting—

2(1) any agreement entered into pursuant to section 560 of division D of the Consolidated and Further Continuing Appropriations Act, 2013 (Public Law 113–6) or section 559 of title V of division F of the Consolidated Appropriations Act, 2014 (6 U.S.C. 211 note; Public Law 113–76), as in existence on the day before December 16, 2016, and any such agreement shall continue to have full force and effect on and after such date; or

3(2) a proposal accepted for consideration by U.S. Customs and Border Protection pursuant to such section 559, as in existence on the day before December 16, 2016.

301c.

Definitions

1In this part:

2The term "donor" means any entity that is proposing to make a donation under this chapter.

3The term "entity" means any—

4(A) person;

5(B) partnership, corporation, trust, estate, cooperative, association, or any other organized group of persons;

6(C) Federal, State or local government (including any subdivision, agency or instrumentality thereof); or

7(D) any other private or governmental entity.

311.

Definitions

1In this subchapter—

2(1) the term "Administrator" means the Administrator of the Agency;

3(2) the term "Agency" means the Federal Emergency Management Agency;

4(3) the term "catastrophic incident" means any natural disaster, act of terrorism, or other man-made disaster that results in extraordinary levels of casualties or damage or disruption severely affecting the population (including mass evacuations), infrastructure, environment, economy, national morale, or government functions in an area;

5(4) the terms "credentialed" and "credentialing" mean having provided, or providing, respectively, documentation that identifies personnel and authenticates and verifies the qualifications of such personnel by ensuring that such personnel possess a minimum common level of training, experience, physical and medical fitness, and capability appropriate for a particular position in accordance with standards created under section 320 of this title;

6(5) the term "Federal coordinating officer" means a Federal coordinating officer as described in section 5143 of title 42;

7(6) the term "interoperable" has the meaning given the term "interoperable communications" under section 194(g)(1) of this title;

8(7) the term "National Incident Management System" means a system to enable effective, efficient, and collaborative incident management;

9(8) the term "National Response Plan" means the National Response Plan or any successor plan prepared under section 314(a)(6) 1 of this title;

10(9) the term "Regional Administrator" means a Regional Administrator appointed under section 317 of this title;

11(10) the term "Regional Office" means a Regional Office established under section 317 of this title;

12(11) the term "resources" means personnel and major items of equipment, supplies, and facilities available or potentially available for responding to a natural disaster, act of terrorism, or other man-made disaster;

13(12) the term "surge capacity" means the ability to rapidly and substantially increase the provision of search and rescue capabilities, food, water, medicine, shelter and housing, medical care, evacuation capacity, staffing (including disaster assistance employees), and other resources necessary to save lives and protect property during a catastrophic incident;

14(13) the term "tribal government" means the government of any entity described in section 101(13)(B) of this title; and

15(14) the terms "typed" and "typing" mean having evaluated, or evaluating, respectively, a resource in accordance with standards created under section 320 of this title.

312.

Definition

1In this subchapter, the term "Nuclear Incident Response Team" means a resource that includes—

2(1) those entities of the Department of Energy that perform nuclear or radiological emergency support functions (including accident response, search response, advisory, and technical operations functions), radiation exposure functions at the medical assistance facility known as the Radiation Emergency Assistance Center/Training Site (REAC/TS), radiological assistance functions, and related functions; and

3(2) those entities of the Environmental Protection Agency that perform such support functions (including radiological emergency response functions) and related functions.

313.

Federal Emergency Management Agency

1There is in the Department the Federal Emergency Management Agency, headed by an Administrator.

2The primary mission of the Agency is to reduce the loss of life and property and protect the Nation from all hazards, including natural disasters, acts of terrorism, and other man-made disasters, by leading and supporting the Nation in a risk-based, comprehensive emergency management system of preparedness, protection, response, recovery, and mitigation.

3In support of the primary mission of the Agency, the Administrator shall—

4(A) lead the Nation's efforts to prepare for, protect against, respond to, recover from, and mitigate against the risk of natural disasters, acts of terrorism, and other man-made disasters, including catastrophic incidents;

5(B) partner with State, local, and tribal governments and emergency response providers, with other Federal agencies, with the private sector, and with nongovernmental organizations to build a national system of emergency management that can effectively and efficiently utilize the full measure of the Nation's resources to respond to natural disasters, acts of terrorism, and other man-made disasters, including catastrophic incidents;

6(C) develop a Federal response capability that, when necessary and appropriate, can act effectively and rapidly to deliver assistance essential to saving lives or protecting or preserving property or public health and safety in a natural disaster, act of terrorism, or other man-made disaster;

7(D) integrate the Agency's emergency preparedness, protection, response, recovery, and mitigation responsibilities to confront effectively the challenges of a natural disaster, act of terrorism, or other man-made disaster;

8(E) develop and maintain robust Regional Offices that will work with State, local, and tribal governments, emergency response providers, and other appropriate entities to identify and address regional priorities;

9(F) under the leadership of the Secretary, coordinate with the Commandant of the Coast Guard, the Director of Customs and Border Protection, the Director of Immigration and Customs Enforcement, the National Operations Center, and other agencies and offices in the Department to take full advantage of the substantial range of resources in the Department;

10(G) provide funding, training, exercises, technical assistance, planning, and other assistance to build tribal, local, State, regional, and national capabilities (including communications capabilities), necessary to respond to a natural disaster, act of terrorism, or other man-made disaster;

11(H) develop and coordinate the implementation of a risk-based, all-hazards strategy for preparedness that builds those common capabilities necessary to respond to natural disasters, acts of terrorism, and other man-made disasters while also building the unique capabilities necessary to respond to specific types of incidents that pose the greatest risk to our Nation; and

12(I) identify, integrate, and implement the needs of children, including children within under-served communities, into activities to prepare for, protect against, respond to, recover from, and mitigate against the risk of natural disasters, acts of terrorism, and other disasters, including catastrophic incidents, including by appointing a technical expert, who may consult with relevant outside organizations and experts, as necessary, to coordinate such integration, as necessary.

13The Administrator shall be appointed by the President, by and with the advice and consent of the Senate.

14The Administrator shall be appointed from among individuals who have—

15(A) a demonstrated ability in and knowledge of emergency management and homeland security; and

16(B) not less than 5 years of executive leadership and management experience in the public or private sector.

17The Administrator shall report to the Secretary, without being required to report through any other official of the Department.

18The Administrator is the principal advisor to the President, the Homeland Security Council, and the Secretary for all matters relating to emergency management in the United States.

19In presenting advice with respect to any matter to the President, the Homeland Security Council, or the Secretary, the Administrator shall, as the Administrator considers appropriate, inform the President, the Homeland Security Council, or the Secretary, as the case may be, of the range of emergency preparedness, protection, response, recovery, and mitigation options with respect to that matter.

20The Administrator, as the principal advisor on emergency management, shall provide advice to the President, the Homeland Security Council, or the Secretary on a particular matter when the President, the Homeland Security Council, or the Secretary requests such advice.

21After informing the Secretary, the Administrator may make such recommendations to Congress relating to emergency management as the Administrator considers appropriate.

22The President may designate the Administrator to serve as a member of the Cabinet in the event of natural disasters, acts of terrorism, or other man-made disasters.

23Nothing in this paragraph shall be construed as affecting the authority of the Secretary under this chapter.

314.

Authority and responsibilities

1The Administrator shall provide Federal leadership necessary to prepare for, protect against, respond to, recover from, or mitigate against a natural disaster, act of terrorism, or other man-made disaster, including—

2(1) helping to ensure the effectiveness of emergency response providers to terrorist attacks, major disasters, and other emergencies;

3(2) with respect to the Nuclear Incident Response Team (regardless of whether it is operating as an organizational unit of the Department pursuant to this subchapter)—

4(A) establishing standards and certifying when those standards have been met;

5(B) conducting joint and other exercises and training and evaluating performance; and

6(C) providing funds to the Department of Energy and the Environmental Protection Agency, as appropriate, for homeland security planning, exercises and training, and equipment;

7(3) providing the Federal Government's response to terrorist attacks and major disasters, including—

8(A) managing such response;

9(B) directing the Domestic Emergency Support Team and (when operating as an organizational unit of the Department pursuant to this subchapter) the Nuclear Incident Response Team;

10(C) overseeing the Metropolitan Medical Response System; and

11(D) coordinating other Federal response resources, including requiring deployment of the Strategic National Stockpile, in the event of a terrorist attack or major disaster;

12(4) aiding the recovery from terrorist attacks and major disasters;

13(5) building a comprehensive national incident management system with Federal, State, and local government personnel, agencies, and authorities, to respond to such attacks and disasters;

14(6) consolidating existing Federal Government emergency response plans into a single, coordinated national response plan;

15(7) helping ensure the acquisition of operable and interoperable communications capabilities by Federal, State, local, and tribal governments and emergency response providers;

16(8) assisting the President in carrying out the functions under the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.) and carrying out all functions and authorities given to the Administrator under that Act;

17(9) carrying out the mission of the Agency to reduce the loss of life and property and protect the Nation from all hazards by leading and supporting the Nation in a risk-based, comprehensive emergency management system of—

18(A) mitigation, by taking sustained actions to reduce or eliminate long-term risks to people and property from hazards and their effects;

19(B) preparedness, by planning, training, and building the emergency management profession to prepare effectively for, mitigate against, respond to, and recover from any hazard;

20(C) response, by conducting emergency operations to save lives and property through positioning emergency equipment, personnel, and supplies, through evacuating potential victims, through providing food, water, shelter, and medical care to those in need, and through restoring critical public services; and

21(D) recovery, by rebuilding communities so individuals, businesses, and governments can function on their own, return to normal life, and protect against future hazards;

22(10) increasing efficiencies, by coordinating efforts relating to preparedness, protection, response, recovery, and mitigation;

23(11) helping to ensure the effectiveness of emergency response providers in responding to a natural disaster, act of terrorism, or other man-made disaster;

24(12) supervising grant programs administered by the Agency;

25(13) administering and ensuring the implementation of the National Response Plan, including coordinating and ensuring the readiness of each emergency support function under the National Response Plan;

26(14) coordinating with the National Advisory Council established under section 318 of this title;

27(15) preparing and implementing the plans and programs of the Federal Government for—

28(A) continuity of operations;

29(B) continuity of government; and

30(C) continuity of plans;

31(16) minimizing, to the extent practicable, overlapping planning and reporting requirements applicable to State, local, and tribal governments and the private sector;

32(17) maintaining and operating within the Agency the National Response Coordination Center or its successor;

33(18) developing a national emergency management system that is capable of preparing for, protecting against, responding to, recovering from, and mitigating against catastrophic incidents;

34(19) assisting the President in carrying out the functions under the national preparedness goal and the national preparedness system and carrying out all functions and authorities of the Administrator under the national preparedness System;

35(20) carrying out all authorities of the Federal Emergency Management Agency and the Directorate of Preparedness of the Department as transferred under section 315 of this title; and

36(21) otherwise carrying out the mission of the Agency as described in section 313(b) of this title.

37In carrying out the responsibilities under this section, the Administrator shall coordinate the implementation of a risk-based, all-hazards strategy that builds those common capabilities necessary to prepare for, protect against, respond to, recover from, or mitigate against natural disasters, acts of terrorism, and other man-made disasters, while also building the unique capabilities necessary to prepare for, protect against, respond to, recover from, or mitigate against the risks of specific types of incidents that pose the greatest risk to the Nation.

314a.

FEMA programs

1Notwithstanding any other provision of Federal law, as of April 1, 2007, the Director of the Federal Emergency Management Agency shall be responsible for the radiological emergency preparedness program and the chemical stockpile emergency preparedness program.

315.

Functions transferred

1Except as provided in subsection (b), there are transferred to the Agency the following:

2(1) All functions of the Federal Emergency Management Agency, including existing responsibilities for emergency alert systems and continuity of operations and continuity of government plans and programs as constituted on June 1, 2006, including all of its personnel, assets, components, authorities, grant programs, and liabilities, and including the functions of the Under Secretary for Federal Emergency Management relating thereto.

3(2) The Directorate of Preparedness, as constituted on June 1, 2006, including all of its functions, personnel, assets, components, authorities, grant programs, and liabilities, and including the functions of the Under Secretary for Preparedness relating thereto.

4The following within the Preparedness Directorate shall not be transferred:

5(1) The Office of Infrastructure Protection.

6(2) The National Communications System.

7(3) The National Cybersecurity Division.

8(4) The functions, personnel, assets, components, authorities, and liabilities of each component described under paragraphs (1) through (3).

316.

Preserving the Federal Emergency Management Agency

1The Agency shall be maintained as a distinct entity within the Department.

2Section 452 of this title shall not apply to the Agency, including any function or organizational unit of the Agency.

3The Secretary may not substantially or significantly reduce, including through a Joint Task Force established under section 348 of this title, the authorities, responsibilities, or functions of the Agency or the capability of the Agency to perform those missions, authorities, responsibilities,1 except as otherwise specifically provided in an Act enacted after October 4, 2006.

4No asset, function, or mission of the Agency may be diverted to the principal and continuing use of any other organization, unit, or entity of the Department, including a Joint Task Force established under section 348 of this title, except for details or assignments that do not reduce the capability of the Agency to perform its missions.

5In reprogramming or transferring funds, the Secretary shall comply with any applicable provisions of any Act making appropriations for the Department for fiscal year 2007, or any succeeding fiscal year, relating to the reprogramming or transfer of funds.

317.

Regional offices

1There are in the Agency 10 regional offices, as identified by the Administrator.

2Each Regional Office shall be headed by a Regional Administrator who shall be appointed by the Administrator, after consulting with State, local, and tribal government officials in the region. Each Regional Administrator shall report directly to the Administrator and be in the Senior Executive Service.

3Each Regional Administrator shall be appointed from among individuals who have a demonstrated ability in and knowledge of emergency management and homeland security.

4In selecting a Regional Administrator for a Regional Office, the Administrator shall consider the familiarity of an individual with the geographical area and demographic characteristics of the population served by such Regional Office.

5The Regional Administrator shall work in partnership with State, local, and tribal governments, emergency managers, emergency response providers, medical providers, the private sector, nongovernmental organizations, multijurisdictional councils of governments, and regional planning commissions and organizations in the geographical area served by the Regional Office to carry out the responsibilities of a Regional Administrator under this section.

6The responsibilities of a Regional Administrator include—

7(A) ensuring effective, coordinated, and integrated regional preparedness, protection, response, recovery, and mitigation activities and programs for natural disasters, acts of terrorism, and other man-made disasters (including planning, training, exercises, and professional development);

8(B) assisting in the development of regional capabilities needed for a national catastrophic response system;

9(C) coordinating the establishment of effective regional operable and interoperable emergency communications capabilities;

10(D) staffing and overseeing 1 or more strike teams within the region under subsection (f), to serve as the focal point of the Federal Government's initial response efforts for natural disasters, acts of terrorism, and other man-made disasters within that region, and otherwise building Federal response capabilities to respond to natural disasters, acts of terrorism, and other man-made disasters within that region;

11(E) designating an individual responsible for the development of strategic and operational regional plans in support of the National Response Plan;

12(F) fostering the development of mutual aid and other cooperative agreements;

13(G) identifying critical gaps in regional capabilities to respond to populations with special needs;

14(H) maintaining and operating a Regional Response Coordination Center or its successor;

15(I) coordinating with the private sector to help ensure private sector preparedness for natural disasters, acts of terrorism, and other man-made disasters;

16(J) assisting State, local, and tribal governments, where appropriate, to preidentify and evaluate suitable sites where a multijurisdictional incident command system may quickly be established and operated from, if the need for such a system arises; and

17(K) performing such other duties relating to such responsibilities as the Administrator may require.

18The Administrator shall require each Regional Administrator to undergo specific training periodically to complement the qualifications of the Regional Administrator. Such training, as appropriate, shall include training with respect to the National Incident Management System, the National Response Plan, and such other subjects as determined by the Administrator.

19The Administrator shall require each Regional Administrator to participate as appropriate in regional and national exercises.

20There is an Area Office for the Pacific and an Area Office for the Caribbean, as components in the appropriate Regional Offices.

21The Administrator shall establish an Area Office in Alaska, as a component in the appropriate Regional Office.

22Each Regional Administrator shall establish a Regional Advisory Council.

23A State, local, or tribal government located within the geographic area served by the Regional Office may nominate officials, including Adjutants General and emergency managers, to serve as members of the Regional Advisory Council for that region.

24Each Regional Advisory Council shall—

25(A) advise the Regional Administrator on emergency management issues specific to that region;

26(B) identify any geographic, demographic, or other characteristics peculiar to any State, local, or tribal government within the region that might make preparedness, protection, response, recovery, or mitigation more complicated or difficult; and

27(C) advise the Regional Administrator of any weaknesses or deficiencies in preparedness, protection, response, recovery, and mitigation for any State, local, and tribal government within the region of which the Regional Advisory Council is aware.

28In coordination with other relevant Federal agencies, each Regional Administrator shall oversee multi-agency strike teams authorized under section 5144 of title 42 that shall consist of—

29(A) a designated Federal coordinating officer;

30(B) personnel trained in incident management;

31(C) public affairs, response and recovery, and communications support personnel;

32(D) a defense coordinating officer;

33(E) liaisons to other Federal agencies;

34(F) such other personnel as the Administrator or Regional Administrator determines appropriate; and

35(G) individuals from the agencies with primary responsibility for each of the emergency support functions in the National Response Plan.

36The duties of an individual assigned to a Regional Office strike team from another relevant agency when such individual is not functioning as a member of the strike team shall be consistent with the emergency preparedness activities of the agency that employs such individual.

37The members of each Regional Office strike team, including representatives from agencies other than the Department, shall be based primarily within the region that corresponds to that strike team.

38Each Regional Office strike team shall coordinate the training and exercises of that strike team with the State, local, and tribal governments and private sector and nongovernmental entities which the strike team shall support when a natural disaster, act of terrorism, or other man-made disaster occurs.

39Each Regional Office strike team shall be trained as a unit on a regular basis and equipped and staffed to be well prepared to respond to natural disasters, acts of terrorism, and other man-made disasters, including catastrophic incidents.

40If the Administrator determines that statutory authority is inadequate for the preparedness and deployment of individuals in strike teams under this subsection, the Administrator shall report to Congress regarding the additional statutory authorities that the Administrator determines are necessary.

318.

National Advisory Council

1Not later than 60 days after October 4, 2006, the Secretary shall establish an advisory body under section 451(a) of this title to ensure effective and ongoing coordination of Federal preparedness, protection, response, recovery, and mitigation for natural disasters, acts of terrorism, and other man-made disasters, to be known as the National Advisory Council.

2The National Advisory Council shall advise the Administrator on all aspects of emergency management. The National Advisory Council shall incorporate State, local, and tribal government and private sector input in the development and revision of the national preparedness goal, the national preparedness system, the National Incident Management System, the National Response Plan, and other related plans and strategies.

3To ensure input from and coordination with State, local, and tribal governments and emergency response providers, the Administrator shall regularly consult and work with the National Advisory Council on the administration and assessment of grant programs administered by the Department, including with respect to the development of program guidance and the development and evaluation of risk-assessment methodologies, as appropriate.

4The members of the National Advisory Council shall be appointed by the Administrator, and shall, to the extent practicable, represent a geographic (including urban and rural) and substantive cross section of officials, emergency managers, and emergency response providers from State, local, and tribal governments, the private sector, and nongovernmental organizations, including as appropriate—

5(A) members selected from the emergency management field and emergency response providers, including fire service, law enforcement, hazardous materials response, emergency medical services, and emergency management personnel, or organizations representing such individuals;

6(B) health scientists, emergency and inpatient medical providers, and public health professionals;

7(C) experts from Federal, State, local, and tribal governments, and the private sector, representing standards-setting and accrediting organizations, including representatives from the voluntary consensus codes and standards development community, particularly those with expertise in the emergency preparedness and response field;

8(D) State, local, and tribal government officials with expertise in preparedness, protection, response, recovery, and mitigation, including Adjutants General;

9(E) elected State, local, and tribal government executives;

10(F) experts in public and private sector infrastructure protection, cybersecurity, and communications;

11(G) representatives of individuals with disabilities and other populations with special needs; and

12(H) such other individuals as the Administrator determines to be appropriate.

13In the selection of members of the National Advisory Council who are health or emergency medical services professionals, the Administrator shall work with the Secretary of Health and Human Services and the Secretary of Transportation.

14The Administrator shall designate 1 or more officers of the Federal Government to serve as ex officio members of the National Advisory Council.

15Except as provided in subparagraph (B), the term of office of each member of the National Advisory Council shall be 3 years.

16Of the members initially appointed to the National Advisory Council—

17(i) one-third shall be appointed for a term of 1 year; and

18(ii) one-third shall be appointed for a term of 2 years.

19Not later than 30 days after December 16, 2016, the Administrator shall establish, as a subcommittee of the National Advisory Council, the Railroad Emergency Services Preparedness, Operational Needs, and Safety Evaluation Subcommittee (referred to in this subsection as the "RESPONSE Subcommittee").

20Notwithstanding subsection (c), the RESPONSE Subcommittee shall be composed of the following:

21(A) The Deputy Administrator, Protection and National Preparedness of the Federal Emergency Management Agency, or designee.

22(B) The Chief Safety Officer of the Pipeline and Hazardous Materials Safety Administration, or designee.

23(C) The Associate Administrator for Hazardous Materials Safety of the Pipeline and Hazardous Materials Safety Administration, or designee.

24(D) The Assistant Director for Emergency Communications, or designee.

25(E) The Director for the Office of Railroad, Pipeline and Hazardous Materials Investigations of the National Transportation Safety Board, or designee.

26(F) The Chief Safety Officer and Associate Administrator for Railroad Safety of the Federal Railroad Administration, or designee.

27(G) The Assistant Administrator for Security Policy and Industry Engagement of the Transportation Security Administration, or designee.

28(H) The Assistant Commandant for Response Policy of the Coast Guard, or designee.

29(I) The Assistant Administrator for the Office of Solid Waste and Emergency Response of the Environmental Protection Agency, or designee.

30(J) Such other qualified individuals as the co-chairpersons shall jointly appoint as soon as practicable after December 16, 2016, from among the following:

31(i) Members of the National Advisory Council that have the requisite technical knowledge and expertise to address rail emergency response issues, including members from the following disciplines:

32(I) Emergency management and emergency response providers, including fire service, law enforcement, hazardous materials response, and emergency medical services.

33(II) State, local, and tribal government officials.

34(ii) Individuals who have the requisite technical knowledge and expertise to serve on the RESPONSE Subcommittee, including at least 1 representative from each of the following:

35(I) The rail industry.

36(II) Rail labor.

37(III) Persons who offer oil for transportation by rail.

38(IV) The communications industry.

39(V) Emergency response providers, including individuals nominated by national organizations representing State and local governments and emergency responders.

40(VI) Emergency response training providers.

41(VII) Representatives from tribal organizations.

42(VIII) Technical experts.

43(IX) Vendors, developers, and manufacturers of systems, facilities, equipment, and capabilities for emergency responder services.

44(iii) Representatives of such other stakeholders and interested and affected parties as the co-chairpersons consider appropriate.

45The members described in subparagraphs (A) and (B) of paragraph (2) shall serve as the co-chairpersons of the RESPONSE Subcommittee.

46The initial meeting of the RESPONSE Subcommittee shall take place not later than 90 days after December 16, 2016.

47The RESPONSE Subcommittee and the program offices for emergency responder training and resources shall consult with other relevant agencies and groups, including entities engaged in federally funded research and academic institutions engaged in relevant work and research, which are not represented on the RESPONSE Subcommittee to consider new and developing technologies and methods that may be beneficial to preparedness and response to rail hazardous materials incidents.

48The RESPONSE Subcommittee shall develop recommendations, as appropriate, for improving emergency responder training and resource allocation for hazardous materials incidents involving railroads after evaluating the following topics:

49(A) The quality and application of training for State and local emergency responders related to rail hazardous materials incidents, including training for emergency responders serving small communities near railroads, including the following:

50(i) Ease of access to relevant training for State and local emergency responders, including an analysis of—

51(I) the number of individuals being trained;

52(II) the number of individuals who are applying;

53(III) whether current demand is being met;

54(IV) current challenges; and

55(V) projected needs.

56(ii) Modernization of training course content related to rail hazardous materials incidents, with a particular focus on fluctuations in oil shipments by rail, including regular and ongoing evaluation of course opportunities, adaptation to emerging trends, agency and private sector outreach, effectiveness and ease of access for State and local emergency responders.

57(iii) Identification of overlap in training content and identification of opportunities to develop complementary courses and materials among governmental and nongovernmental entities.

58(iv) Online training platforms, train-the-trainer, and mobile training options.

59(B) The availability and effectiveness of Federal, State, local, and nongovernmental funding levels related to training emergency responders for rail hazardous materials incidents, including emergency responders serving small communities near railroads, including—

60(i) identifying overlap in resource allocations;

61(ii) identifying cost savings measures that can be implemented to increase training opportunities;

62(iii) leveraging government funding with nongovernmental funding to enhance training opportunities and fill existing training gaps;

63(iv) adaptation of priority settings for agency funding allocations in response to emerging trends;

64(v) historic levels of funding across Federal agencies for rail hazardous materials incident response and training, including funding provided by the private sector to public entities or in conjunction with Federal programs; and

65(vi) current funding resources across agencies.

66(C) The strategy for integrating commodity flow studies, mapping, and rail and hazardous materials databases for State and local emergency responders and increasing the rate of access to the individual responder in existing or emerging communications technology.

67Not later than 1 year after December 16, 2016, the RESPONSE Subcommittee shall submit a report to the National Advisory Council that—

68(i) includes the recommendations developed under paragraph (6);

69(ii) specifies the timeframes for implementing any such recommendations that do not require congressional action; and

70(iii) identifies any such recommendations that do require congressional action.

71Not later than 30 days after receiving the report under subparagraph (A), the National Advisory Council shall begin a review of the report. The National Advisory Council may ask for additional clarification, changes, or other information from the RESPONSE Subcommittee to assist in the approval of the recommendations.

72Once the National Advisory Council approves the recommendations of the RESPONSE Subcommittee, the National Advisory Council shall submit the report to—

73(i) the co-chairpersons of the RESPONSE Subcommittee;

74(ii) the head of each other agency represented on the RESPONSE Subcommittee;

75(iii) the Committee on Homeland Security and Governmental Affairs of the Senate;

76(iv) the Committee on Commerce, Science, and Transportation of the Senate;

77(v) the Committee on Homeland Security of the House of Representatives; and

78(vi) the Committee on Transportation and Infrastructure of the House of Representatives.

79After the submission of the report by the National Advisory Council under paragraph (7), the Administrator shall—

80(i) provide annual updates to the congressional committees referred to in paragraph (7)(C) regarding the status of the implementation of the recommendations developed under paragraph (6); and

81(ii) coordinate the implementation of the recommendations described in paragraph (6)(G)(i), as appropriate.

82The requirements of subparagraph (A) shall terminate on the date that is 2 years after the date of the submission of the report required under paragraph (7)(A).

83The RESPONSE Subcommittee shall terminate not later than 90 days after the submission of the report required under paragraph (7)(C).

84Notwithstanding section 451(a) of this title and subject to paragraph (2), chapter 10 of title 5, including subsections (a), (b), and (d) of section 1009 of title 5, and section 552b(c) of title 5 shall apply to the National Advisory Council.

85Section 1013(a)(2) of title 5 shall not apply to the National Advisory Council.

319.

National Integration Center

1There is established in the Agency a National Integration Center.

2The Administrator, through the National Integration Center, and in consultation with other Federal departments and agencies and the National Advisory Council, shall ensure ongoing management and maintenance of the National Incident Management System, the National Response Plan, and any successor to such system or plan.

3The National Integration Center shall periodically review, and revise as appropriate, the National Incident Management System and the National Response Plan, including—

4(A) establishing, in consultation with the Director of the Corporation for National and Community Service, a process to better use volunteers and donations;

5(B) improving the use of Federal, State, local, and tribal resources and ensuring the effective use of emergency response providers at emergency scenes; and

6(C) revising the Catastrophic Incident Annex, finalizing and releasing the Catastrophic Incident Supplement to the National Response Plan, and ensuring that both effectively address response requirements in the event of a catastrophic incident.

7The Secretary, acting through the Administrator, shall ensure that the National Response Plan provides for a clear chain of command to lead and coordinate the Federal response to any natural disaster, act of terrorism, or other man-made disaster.

8The chain of the command specified in the National Response Plan shall—

9(i) provide for a role for the Administrator consistent with the role of the Administrator as the principal emergency management advisor to the President, the Homeland Security Council, and the Secretary under section 313(c)(4) of this title and the responsibility of the Administrator under the Post-Katrina Emergency Management Reform Act of 2006, and the amendments made by that Act, relating to natural disasters, acts of terrorism, and other man-made disasters; and

10(ii) provide for a role for the Federal Coordinating Officer consistent with the responsibilities under section 5143(b) of title 42.

11The Principal Federal Official (or the successor thereto) or Director of a Joint Task Force established under section 348 of this title shall not—

12(A) direct or replace the incident command structure established at the incident; or

13(B) have directive authority over the Senior Federal Law Enforcement Official, Federal Coordinating Officer, or other Federal and State officials.

320.

Credentialing and typing

1The Administrator shall enter into a memorandum of understanding with the administrators of the Emergency Management Assistance Compact, State, local, and tribal governments, and organizations that represent emergency response providers, to collaborate on developing standards for deployment capabilities, including for credentialing and typing of incident management personnel, emergency response providers, and other personnel (including temporary personnel) and resources likely needed to respond to natural disasters, acts of terrorism, and other man-made disasters.

2Not later than 1 year after August 3, 2007, the Administrator shall provide the standards developed under subsection (a), including detailed written guidance, to—

3(A) each Federal agency that has responsibilities under the National Response Plan to aid that agency with credentialing and typing incident management personnel, emergency response providers, and other personnel (including temporary personnel) and resources likely needed to respond to a natural disaster, act of terrorism, or other man-made disaster; and

4(B) State, local, and tribal governments, to aid such governments with credentialing and typing of State, local, and tribal incident management personnel, emergency response providers, and other personnel (including temporary personnel) and resources likely needed to respond to a natural disaster, act of terrorism, or other man-made disaster.

5The Administrator shall provide expertise and technical assistance to aid Federal, State, local, and tribal government agencies with credentialing and typing incident management personnel, emergency response providers, and other personnel (including temporary personnel) and resources likely needed to respond to a natural disaster, act of terrorism, or other man-made disaster.

6Not later than 6 months after receiving the standards provided under subsection (b), each Federal agency with responsibilities under the National Response Plan shall ensure that incident management personnel, emergency response providers, and other personnel (including temporary personnel) and resources likely needed to respond to a natural disaster, act of terrorism, or other manmade disaster are credentialed and typed in accordance with this section.

7In developing standards for credentialing health care professionals under this section, the Administrator shall consult with the Secretary of Health and Human Services.

321.

The National Infrastructure Simulation and Analysis Center

1In this section, the term "National Infrastructure Simulation and Analysis Center" means the National Infrastructure Simulation and Analysis Center established under section 5195c(d) of title 42.

2There is in the Department the National Infrastructure Simulation and Analysis Center which shall serve as a source of national expertise to address critical infrastructure protection and continuity through support for activities related to—

3(A) counterterrorism, threat assessment, and risk mitigation; and

4(B) a natural disaster, act of terrorism, or other man-made disaster.

5The support provided under paragraph (1) shall include modeling, simulation, and analysis of the systems and assets comprising critical infrastructure, in order to enhance preparedness, protection, response, recovery, and mitigation activities.

6Each Federal agency and department with critical infrastructure responsibilities under Homeland Security Presidential Directive 7, or any successor to such directive, shall establish a formal relationship, including an agreement regarding information sharing, between the elements of such agency or department and the National Infrastructure Simulation and Analysis Center, through the Department.

7The purpose of the relationship under subparagraph (B) shall be to permit each Federal agency and department described in subparagraph (B) to take full advantage of the capabilities of the National Infrastructure Simulation and Analysis Center (particularly vulnerability and consequence analysis), consistent with its work load capacity and priorities, for real-time response to reported and projected natural disasters, acts of terrorism, and other man-made disasters.

8Modeling, simulation, and analysis provided under this subsection shall be provided to relevant Federal agencies and departments, including Federal agencies and departments with critical infrastructure responsibilities under Homeland Security Presidential Directive 7, or any successor to such directive.

321a.

Evacuation plans and exercises

1Notwithstanding any other provision of law, and subject to subsection (d), grants made to States or local or tribal governments by the Department through the State Homeland Security Grant Program or the Urban Area Security Initiative may be used to—

2(1) establish programs for the development and maintenance of mass evacuation plans under subsection (b) in the event of a natural disaster, act of terrorism, or other man-made disaster;

3(2) prepare for the execution of such plans, including the development of evacuation routes and the purchase and stockpiling of necessary supplies and shelters; and

4(3) conduct exercises of such plans.

5In developing the mass evacuation plans authorized under subsection (a), each State, local, or tribal government shall, to the maximum extent practicable—

6(1) establish incident command and decision making processes;

7(2) ensure that State, local, and tribal government plans, including evacuation routes, are coordinated and integrated;

8(3) identify primary and alternative evacuation routes and methods to increase evacuation capabilities along such routes such as conversion of two-way traffic to one-way evacuation routes;

9(4) identify evacuation transportation modes and capabilities, including the use of mass and public transit capabilities, and coordinating and integrating evacuation plans for all populations including for those individuals located in hospitals, nursing homes, and other institutional living facilities;

10(5) develop procedures for informing the public of evacuation plans before and during an evacuation, including individuals—

11(A) with disabilities or other special needs, including the elderly;

12(B) with limited English proficiency; or

13(C) who might otherwise have difficulty in obtaining such information; and

14(6) identify shelter locations and capabilities.

15The Administrator may establish any guidelines, standards, or requirements determined appropriate to administer this section and to ensure effective mass evacuation planning for State, local, and tribal areas.

16The Administrator shall make assistance available upon request of a State, local, or tribal government to assist hospitals, nursing homes, and other institutions that house individuals with special needs to establish, maintain, and exercise mass evacuation plans that are coordinated and integrated into the plans developed by that State, local, or tribal government under this section.

17Nothing in this section may be construed to preclude a State, local, or tribal government from using grant funds in a manner that enhances preparedness for a natural or man-made disaster unrelated to an act of terrorism, if such use assists such government in building capabilities for terrorism preparedness.

321b.

Disability Coordinator

1After consultation with organizations representing individuals with disabilities, the National Council on Disabilities, and the Interagency Coordinating Council on Preparedness and Individuals with Disabilities, established under Executive Order No. 13347, the Administrator shall appoint a Disability Coordinator. The Disability Coordinator shall report directly to the Administrator, in order to ensure that the needs of individuals with disabilities are being properly addressed in emergency preparedness and disaster relief.

2The Disability Coordinator shall be responsible for—

3(1) providing guidance and coordination on matters related to individuals with disabilities in emergency planning requirements and relief efforts in the event of a natural disaster, act of terrorism, or other man-made disaster;

4(2) interacting with the staff of the Agency, the National Council on Disabilities, the Interagency Coordinating Council on Preparedness and Individuals with Disabilities established under Executive Order No. 13347, other agencies of the Federal Government, and State, local, and tribal government authorities regarding the needs of individuals with disabilities in emergency planning requirements and relief efforts in the event of a natural disaster, act of terrorism, or other man-made disaster;

5(3) consulting with organizations that represent the interests and rights of individuals with disabilities about the needs of individuals with disabilities in emergency planning requirements and relief efforts in the event of a natural disaster, act of terrorism, or other man-made disaster;

6(4) ensuring the coordination and dissemination of best practices and model evacuation plans for individuals with disabilities;

7(5) ensuring the development of training materials and a curriculum for training of emergency response providers, State, local, and tribal government officials, and others on the needs of individuals with disabilities;

8(6) promoting the accessibility of telephone hotlines and websites regarding emergency preparedness, evacuations, and disaster relief;

9(7) working to ensure that video programming distributors, including broadcasters, cable operators, and satellite television services, make emergency information accessible to individuals with hearing and vision disabilities;

10(8) ensuring the availability of accessible transportation options for individuals with disabilities in the event of an evacuation;

11(9) providing guidance and implementing policies to ensure that the rights and wishes of individuals with disabilities regarding post-evacuation residency and relocation are respected;

12(10) ensuring that meeting the needs of individuals with disabilities are included in the components of the national preparedness system established under section 744 of this title; and

13(11) any other duties as assigned by the Administrator.

321c.

Department and Agency officials

1The President may appoint, by and with the advice and consent of the Senate, not more than 4 Deputy Administrators to assist the Administrator in carrying out this subchapter.

2The Administrator of the United States Fire Administration shall have a rank equivalent to an assistant secretary of the Department.

321d.

National Operations Center

1In this section, the term "situational awareness" means information gathered from a variety of sources that, when communicated to emergency managers, decision makers, and other appropriate officials, can form the basis for incident management decisionmaking and steady-state activity.

2The National Operations Center is the principal operations center for the Department and shall—

3(1) provide situational awareness and a common operating picture for the entire Federal Government, and for State, local, tribal, and territorial governments, the private sector, and international partners as appropriate, for events, threats, and incidents involving a natural disaster, act of terrorism, or other man-made disaster;

4(2) ensure that critical terrorism and disaster-related information reaches government decision-makers; and

5(3) enter into agreements with other Federal operations centers and other homeland security partners, as appropriate, to facilitate the sharing of information.

6The Secretary shall establish a position, on a rotating basis, for a representative of State and local emergency responders at the National Operations Center established under subsection (b) to ensure the effective sharing of information between the Federal Government and State and local emergency response services.

7The Secretary shall manage the position established pursuant to paragraph (1) in accordance with such rules, regulations, and practices as govern other similar rotating positions at the National Operations Center.

321e.

Repealed. Pub. L. 115–387, §2(c)(1), Dec. 21, 2018, 132 Stat. 5166

321f.

Nuclear incident response

1At the direction of the Secretary (in connection with an actual or threatened terrorist attack, major disaster, or other emergency in the United States), the Nuclear Incident Response Team shall operate as an organizational unit of the Department. While so operating, the Nuclear Incident Response Team shall be subject to the direction, authority, and control of the Secretary.

2Nothing in this subchapter shall be construed to limit the ordinary responsibility of the Secretary of Energy and the Administrator of the Environmental Protection Agency for organizing, training, equipping, and utilizing their respective entities in the Nuclear Incident Response Team, or (subject to the provisions of this subchapter) from exercising direction, authority, and control over them when they are not operating as a unit of the Department.

321g.

Conduct of certain public health-related activities

1With respect to all public health-related activities to improve State, local, and hospital preparedness and response to chemical, biological, radiological, and nuclear and other emerging terrorist threats carried out by the Department of Health and Human Services (including the Public Health Service), the Secretary of Health and Human Services shall set priorities and preparedness goals and further develop a coordinated strategy for such activities in collaboration with the Secretary.

2In carrying out subsection (a), the Secretary of Health and Human Services shall collaborate with the Secretary in developing specific benchmarks and outcome measurements for evaluating progress toward achieving the priorities and goals described in such subsection.

321h.

Use of national private sector networks in emergency response

1To the maximum extent practicable, the Secretary shall use national private sector networks and infrastructure for emergency response to chemical, biological, radiological, nuclear, or explosive disasters, and other major disasters.

321i.

Use of commercially available technology, goods, and services

1It is the sense of Congress that—

2(1) the Secretary should, to the maximum extent possible, use off-the-shelf commercially developed technologies to ensure that the Department's information technology systems allow the Department to collect, manage, share, analyze, and disseminate information securely over multiple channels of communication; and

3(2) in order to further the policy of the United States to avoid competing commercially with the private sector, the Secretary should rely on commercial sources to supply the goods and services needed by the Department.

321j.

Procurement of security countermeasures for Strategic National Stockpile

1For the procurement of security countermeasures under section 247d–6b(c) of title 42 (referred to in this section as the "security countermeasures program"), there is authorized to be appropriated up to $5,593,000,000 for the fiscal years 2004 through 2013. Of the amounts appropriated under the preceding sentence, not to exceed $3,418,000,000 may be obligated during the fiscal years 2004 through 2008, of which not to exceed $890,000,000 may be obligated during fiscal year 2004. None of the funds made available under this subsection shall be used to procure countermeasures to diagnose, mitigate, prevent, or treat harm resulting from any naturally occurring infectious disease or other public health threat that are not security countermeasures under section 247d–6b(c)(1)(B) of title 42.1

2For purposes of the security countermeasures program, the term "special reserve fund" means the "Biodefense Countermeasures" appropriations account or any other appropriation made under subsection (a).

3Amounts appropriated under subsection (a) become available for a procurement under the security countermeasures program only upon the approval by the President of such availability for the procurement in accordance with paragraph (6)(B) of such program.

4For the purpose of carrying out the responsibilities of the Secretary for terror threat assessment under the security countermeasures program, there are authorized to be appropriated such sums as may be necessary for each of the fiscal years 2004 through 2006, for the hiring of professional personnel within the Office of Intelligence and Analysis, who shall be analysts responsible for chemical, biological, radiological, and nuclear threat assessment (including but not limited to analysis of chemical, biological, radiological, and nuclear agents, the means by which such agents could be weaponized or used in a terrorist attack, and the capabilities, plans, and intentions of terrorists and other non-state actors who may have or acquire such agents). All such analysts shall meet the applicable standards and qualifications for the performance of intelligence activities promulgated by the Director of Central Intelligence pursuant to section 403–4 1 of title 50.

5For the purpose of carrying out the acquisition and deployment of secure facilities (including information technology and physical infrastructure, whether mobile and temporary, or permanent) sufficient to permit the Secretary to receive, not later than 180 days after July 21, 2004, all classified information and products to which the Under Secretary for Intelligence and Analysis is entitled under part A of subchapter II, there are authorized to be appropriated such sums as may be necessary for each of the fiscal years 2004 through 2006.

321k.

Model standards and guidelines for critical infrastructure workers

1Not later than 12 months after August 3, 2007, and in coordination with appropriate national professional organizations, Federal, State, local, and tribal government agencies, and private-sector and nongovernmental entities, the Administrator shall establish model standards and guidelines for credentialing critical infrastructure workers that may be used by a State to credential critical infrastructure workers that may respond to a natural disaster, act of terrorism, or other man-made disaster.

2The Administrator shall provide the standards developed under subsection (a), including detailed written guidance, to State, local, and tribal governments, and provide expertise and technical assistance to aid such governments with credentialing critical infrastructure workers that may respond to a natural disaster, act of terrorism, or other manmade disaster.

321l.

Guidance and recommendations

1Consistent with their responsibilities and authorities under law, as of the day before August 3, 2007, the Administrator and the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the private sector, may develop guidance or recommendations and identify best practices to assist or foster action by the private sector in—

2(1) identifying potential hazards and assessing risks and impacts;

3(2) mitigating the impact of a wide variety of hazards, including weapons of mass destruction;

4(3) managing necessary emergency preparedness and response resources;

5(4) developing mutual aid agreements;

6(5) developing and maintaining emergency preparedness and response plans, and associated operational procedures;

7(6) developing and conducting training and exercises to support and evaluate emergency preparedness and response plans and operational procedures;

8(7) developing and conducting training programs for security guards to implement emergency preparedness and response plans and operations procedures; and

9(8) developing procedures to respond to requests for information from the media or the public.

10Any guidance or recommendations developed or best practices identified under subsection (a) shall be—

11(1) issued through the Administrator; and

12(2) promoted by the Secretary to the private sector.

13In developing guidance or recommendations or identifying best practices under subsection (a), the Administrator and the Director of the Cybersecurity and Infrastructure Security Agency shall take into consideration small business concerns (under the meaning given that term in section 632 of title 15), including any need for separate guidance or recommendations or best practices, as necessary and appropriate.

14Nothing in this section may be construed to supersede any requirement established under any other provision of law.

321m.

Voluntary private sector preparedness accreditation and certification program

1The Secretary, acting through the officer designated under paragraph (2), shall establish and implement the voluntary private sector preparedness accreditation and certification program in accordance with this section.

2The Secretary shall designate an officer responsible for the accreditation and certification program under this section. Such officer (hereinafter referred to in this section as the "designated officer") shall be one of the following:

3(A) The Administrator, based on consideration of—

4(i) the expertise of the Administrator in emergency management and preparedness in the United States; and

5(ii) the responsibilities of the Administrator as the principal advisor to the President for all matters relating to emergency management in the United States.

6(B) The Assistant Secretary for Infrastructure Protection,1 based on consideration of the expertise of the Assistant Secretary in, and responsibilities for—

7(i) protection of critical infrastructure;

8(ii) risk assessment methodologies; and

9(iii) interacting with the private sector on the issues described in clauses (i) and (ii).

10(C) The Under Secretary for Science and Technology, based on consideration of the expertise of the Under Secretary in, and responsibilities associated with, standards.

11In carrying out the accreditation and certification program under this section, the designated officer shall coordinate with—

12(A) the other officers of the Department referred to in paragraph (2), using the expertise and responsibilities of such officers; and

13(B) the Special Assistant to the Secretary for the Private Sector, based on consideration of the expertise of the Special Assistant in, and responsibilities for, interacting with the private sector.

14Not later than 210 days after August 3, 2007, the designated officer shall—

15(A) begin supporting the development and updating, as necessary, of voluntary preparedness standards through appropriate organizations that coordinate or facilitate the development and use of voluntary consensus standards and voluntary consensus standards development organizations; and

16(B) in consultation with representatives of appropriate organizations that coordinate or facilitate the development and use of voluntary consensus standards, appropriate voluntary consensus standards development organizations, each private sector advisory council created under section 112(f)(4) of this title, appropriate representatives of State and local governments, including emergency management officials, and appropriate private sector advisory groups, such as sector coordinating councils and information sharing and analysis centers—

17(i) develop and promote a program to certify the preparedness of private sector entities that voluntarily choose to seek certification under the program; and

18(ii) implement the program under this subsection through any entity with which the designated officer enters into an agreement under paragraph (3)(A), which shall accredit third parties to carry out the certification process under this section.

19The program developed and implemented under this subsection shall assess whether a private sector entity complies with voluntary preparedness standards.

20In developing the program under this subsection, the designated officer shall develop guidelines for the accreditation and certification processes established under this subsection.

21The designated officer, in consultation with representatives of appropriate organizations that coordinate or facilitate the development and use of voluntary consensus standards, representatives of appropriate voluntary consensus standards development organizations, each private sector advisory council created under section 112(f)(4) of this title, appropriate representatives of State and local governments, including emergency management officials, and appropriate private sector advisory groups such as sector coordinating councils and information sharing and analysis centers—

22(i) shall adopt one or more appropriate voluntary preparedness standards that promote preparedness, which may be tailored to address the unique nature of various sectors within the private sector, as necessary and appropriate, that shall be used in the accreditation and certification program under this subsection; and

23(ii) after the adoption of one or more standards under clause (i), may adopt additional voluntary preparedness standards or modify or discontinue the use of voluntary preparedness standards for the accreditation and certification program, as necessary and appropriate to promote preparedness.

24In adopting one or more standards under subparagraph (B), the designated officer may receive recommendations from any entity described in that subparagraph relating to appropriate voluntary preparedness standards, including appropriate sector specific standards, for adoption in the program.

25The designated officer and any entity with which the designated officer enters into an agreement under paragraph (3)(A) shall establish separate classifications and methods of certification for small business concerns (under the meaning given that term in section 632 of title 15) for the program under this subsection.

26In developing and implementing the program under this subsection, the designated officer shall—

27(i) consider the unique nature of various sectors within the private sector, including preparedness standards, business continuity standards, or best practices, established—

28(I) under any other provision of Federal law; or

29(II) by any Sector Risk Management Agency, as defined under Homeland Security Presidential Directive–7; and

30(ii) coordinate the program, as appropriate, with—

31(I) other Department private sector related programs; and

32(II) preparedness and business continuity programs in other Federal agencies.

33Not later than 210 days after August 3, 2007, the designated officer shall enter into one or more agreements with a highly qualified nongovernmental entity with experience or expertise in coordinating and facilitating the development and use of voluntary consensus standards and in managing or implementing accreditation and certification programs for voluntary consensus standards, or a similarly qualified private sector entity, to carry out accreditations and oversee the certification process under this subsection. An entity entering into an agreement with the designated officer under this clause (hereinafter referred to in this section as a "selected entity") shall not perform certifications under this subsection.

34A selected entity shall manage the accreditation process and oversee the certification process in accordance with the program established under this subsection and accredit qualified third parties to carry out the certification program established under this subsection.

35Any selected entity shall collaborate to develop procedures and requirements for the accreditation and certification processes under this subsection, in accordance with the program established under this subsection and guidelines developed under paragraph (2)(A)(ii).

36The procedures and requirements developed under clause (i) shall—

37(I) ensure reasonable uniformity in any accreditation and certification processes if there is more than one selected entity; and

38(II) be used by any selected entity in conducting accreditations and overseeing the certification process under this subsection.

39Any disagreement among selected entities in developing procedures under clause (i) shall be resolved by the designated officer.

40A selected entity may accredit any qualified third party to carry out the certification process under this subsection.

41In accrediting qualified third parties to carry out the certification process under this subsection, a selected entity shall ensure, to the extent practicable, that the third parties include qualified small, minority, women-owned, or disadvantaged business concerns when appropriate. The term "disadvantaged business concern" means a small business that is owned and controlled by socially and economically disadvantaged individuals, as defined in section 124 of title 13, United States Code of Federal Regulations.

42At the request of any entity seeking certification, any selected entity may consider, as appropriate, other relevant certifications acquired by the entity seeking certification. If the selected entity determines that such other certifications are sufficient to meet the certification requirement or aspects of the certification requirement under this section, the selected entity may give credit to the entity seeking certification, as appropriate, to avoid unnecessarily duplicative certification requirements.

43To be accredited under subparagraph (C), a third party shall—

44(i) demonstrate that the third party has the ability to certify private sector entities in accordance with the procedures and requirements developed under subparagraph (B);

45(ii) agree to perform certifications in accordance with such procedures and requirements;

46(iii) agree not to have any beneficial interest in or any direct or indirect control over—

47(I) a private sector entity for which that third party conducts a certification under this subsection; or

48(II) any organization that provides preparedness consulting services to private sector entities;

49(iv) agree not to have any other conflict of interest with respect to any private sector entity for which that third party conducts a certification under this subsection;

50(v) maintain liability insurance coverage at policy limits in accordance with the requirements developed under subparagraph (B); and

51(vi) enter into an agreement with the selected entity accrediting that third party to protect any proprietary information of a private sector entity obtained under this subsection.

52The designated officer and any selected entity shall regularly monitor and inspect the operations of any third party conducting certifications under this subsection to ensure that the third party is complying with the procedures and requirements established under subparagraph (B) and all other applicable requirements.

53If the designated officer or any selected entity determines that a third party is not meeting the procedures or requirements established under subparagraph (B), the selected entity shall—

54(I) revoke the accreditation of that third party to conduct certifications under this subsection; and

55(II) review any certification conducted by that third party, as necessary and appropriate.

56The designated officer, in consultation with representatives of appropriate organizations that coordinate or facilitate the development and use of voluntary consensus standards, appropriate voluntary consensus standards development organizations, appropriate representatives of State and local governments, including emergency management officials, and each private sector advisory council created under section 112(f)(4) of this title, shall annually review the voluntary accreditation and certification program established under this subsection to ensure the effectiveness of such program (including the operations and management of such program by any selected entity and the selected entity's inclusion of qualified disadvantaged business concerns under paragraph (3)(D)) and make improvements and adjustments to the program as necessary and appropriate.

57Each review under subparagraph (A) shall include an assessment of the voluntary preparedness standard or standards used in the program under this subsection.

58Certification under this subsection shall be voluntary for any private sector entity.

59The designated officer shall maintain and make public a listing of any private sector entity certified as being in compliance with the program established under this subsection, if that private sector entity consents to such listing.

60Nothing in this section may be construed as—

61(1) a requirement to replace any preparedness, emergency response, or business continuity standards, requirements, or best practices established—

62(A) under any other provision of federal law; or

63(B) by any Sector Risk Management Agency, as those agencies are defined under Homeland Security Presidential Directive–7; or

64(2) exempting any private sector entity seeking certification or meeting certification requirements under subsection (b) from compliance with all applicable statutes, regulations, directives, policies, and industry codes of practice.

321n.

Acceptance of gifts

1The Secretary may accept and use gifts of property, both real and personal, and may accept gifts of services, including from guest lecturers, for otherwise authorized activities of the Center for Domestic Preparedness that are related to efforts to prevent, prepare for, protect against, or respond to a natural disaster, act of terrorism, or other man-made disaster, including the use of a weapon of mass destruction.

2The Secretary may not accept a gift under this section if the Secretary determines that the use of the property or services would compromise the integrity or appearance of integrity of—

3(1) a program of the Department; or

4(2) an individual involved in a program of the Department.

5The Secretary shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate an annual report disclosing—

6(A) any gifts that were accepted under this section during the year covered by the report;

7(B) how the gifts contribute to the mission of the Center for Domestic Preparedness; and

8(C) the amount of Federal savings that were generated from the acceptance of the gifts.

9Each report required under paragraph (1) shall be made publically available.

321o.

Integrated public alert and warning system modernization

1To provide timely and effective warnings regarding natural disasters, acts of terrorism, and other man-made disasters or threats to public safety, the Administrator shall—

2(1) modernize the integrated public alert and warning system of the United States (in this section referred to as the "public alert and warning system") to help ensure that under all conditions the President and, except to the extent the public alert and warning system is in use by the President, Federal agencies and State, tribal, and local governments can alert and warn the civilian population in areas endangered by natural disasters, acts of terrorism, and other man-made disasters or threats to public safety; and

3(2) implement the public alert and warning system to disseminate timely and effective warnings regarding natural disasters, acts of terrorism, and other man-made disasters or threats to public safety.

4In carrying out subsection (a), the Administrator shall—

5(1) establish or adopt, as appropriate, common alerting and warning protocols, standards, terminology, and operating procedures for the public alert and warning system;

6(2) include in the public alert and warning system the capability to adapt the distribution and content of communications on the basis of geographic location, risks, and multiple communication systems and technologies, as appropriate and to the extent technically feasible;

7(3) include in the public alert and warning system the capability to alert, warn, and provide equivalent information to individuals with disabilities, individuals with access and functional needs, and individuals with limited-English proficiency, to the extent technically feasible;

8(4) ensure that training, tests, and exercises are conducted for the public alert and warning system, including by—

9(A) incorporating the public alert and warning system into other training and exercise programs of the Department, as appropriate;

10(B) establishing and integrating into the National Incident Management System a comprehensive and periodic training program to instruct and educate Federal, State, tribal, and local government officials in the use of the Common Alerting Protocol enabled Emergency Alert System; and

11(C) conducting, not less than once every 3 years, periodic nationwide tests of the public alert and warning system;

12(5) to the extent practicable, ensure that the public alert and warning system is resilient and secure and can withstand acts of terrorism and other external attacks;

13(6) conduct public education efforts so that State, tribal, and local governments, private entities, and the people of the United States reasonably understand the functions of the public alert and warning system and how to access, use, and respond to information from the public alert and warning system through a general market awareness campaign;

14(7) consult, coordinate, and cooperate with the appropriate private sector entities and Federal, State, tribal, and local governmental authorities, including the Regional Administrators and emergency response providers;

15(8) consult and coordinate with the Federal Communications Commission, taking into account rules and regulations promulgated by the Federal Communications Commission; and

16(9) coordinate with and consider the recommendations of the Integrated Public Alert and Warning System Subcommittee established under section 2(b) of the Integrated Public Alert and Warning System Modernization Act of 2015.

17The public alert and warning system shall—

18(1) to the extent determined appropriate by the Administrator, incorporate multiple communications technologies;

19(2) be designed to adapt to, and incorporate, future technologies for communicating directly with the public;

20(3) to the extent technically feasible, be designed—

21(A) to provide alerts to the largest portion of the affected population feasible, including nonresident visitors and tourists, individuals with disabilities, individuals with access and functional needs, and individuals with limited-English proficiency; and

22(B) to improve the ability of remote areas to receive alerts;

23(4) promote local and regional public and private partnerships to enhance community preparedness and response;

24(5) provide redundant alert mechanisms where practicable so as to reach the greatest number of people; and

25(6) to the extent feasible, include a mechanism to ensure the protection of individual privacy.

26Except to the extent necessary for testing the public alert and warning system, the public alert and warning system shall not be used to transmit a message that does not relate to a natural disaster, act of terrorism, or other man-made disaster or threat to public safety.

27Not later than 1 year after April 11, 2016, and annually thereafter through 2018, the Administrator shall make available on the public website of the Agency a performance report, which shall—

28(A) establish performance goals for the implementation of the public alert and warning system by the Agency;

29(B) describe the performance of the public alert and warning system, including—

30(i) the type of technology used for alerts and warnings issued under the system;

31(ii) the measures taken to alert, warn, and provide equivalent information to individuals with disabilities, individuals with access and function 1 needs, and individuals with limited-English proficiency; and

32(iii) the training, tests, and exercises performed and the outcomes obtained by the Agency;

33(C) identify significant challenges to the effective operation of the public alert and warning system and any plans to address these challenges;

34(D) identify other necessary improvements to the system; and

35(E) provide an analysis comparing the performance of the public alert and warning system with the performance goals established under subparagraph (A).

36The Administrator shall submit to the Committee on Homeland Security and Governmental Affairs and the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Transportation and Infrastructure and the Committee on Homeland Security of the House of Representatives each report required under paragraph (1).

321o

–1. Integrated public alert and warning system

1In this section—

2(1) the term "Administrator" means the Administrator of the Agency;

3(2) the term "Agency" means the Federal Emergency Management Agency;

4(3) the term "appropriate congressional committees" means—

5(A) the Committee on Homeland Security and Governmental Affairs of the Senate;

6(B) the Committee on Transportation and Infrastructure of the House of Representatives; and

7(C) the Committee on Homeland Security of the House of Representatives;

8(4) the term "public alert and warning system" means the integrated public alert and warning system of the United States described in section 321o of this title;

9(5) the term "Secretary" means the Secretary of Homeland Security; and

10(6) the term "State" means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Virgin Islands, Guam, American Samoa, the Commonwealth of the Northern Mariana Islands, and any possession of the United States.

11Not later than 1 year after December 20, 2019, the Administrator shall develop minimum requirements for State, Tribal, and local governments to participate in the public alert and warning system and that are necessary to maintain the integrity of the public alert and warning system, including—

12(A) guidance on the categories of public emergencies and appropriate circumstances that warrant an alert and warning from State, Tribal, and local governments using the public alert and warning system;

13(B) the procedures for State, Tribal, and local government officials to authenticate civil emergencies and initiate, modify, and cancel alerts transmitted through the public alert and warning system, including protocols and technology capabilities for—

14(i) the initiation, or prohibition on the initiation, of alerts by a single authorized or unauthorized individual;

15(ii) testing a State, Tribal, or local government incident management and warning tool without accidentally initiating an alert through the public alert and warning system; and

16(iii) steps a State, Tribal, or local government official should take to mitigate the possibility of the issuance of a false alert through the public alert and warning system;

17(C) the standardization, functionality, and interoperability of incident management and warning tools used by State, Tribal, and local governments to notify the public of an emergency through the public alert and warning system;

18(D) the annual training and recertification of emergency management personnel on requirements for originating and transmitting an alert through the public alert and warning system;

19(E) the procedures, protocols, and guidance concerning the protective action plans that State, Tribal, and local governments shall issue to the public following an alert issued under the public alert and warning system;

20(F) the procedures, protocols, and guidance concerning the communications that State, Tribal, and local governments shall issue to the public following a false alert issued under the public alert and warning system;

21(G) a plan by which State, Tribal, and local government officials may, during an emergency, contact each other as well as Federal officials and participants in the Emergency Alert System and the Wireless Emergency Alert System, when appropriate and necessary, by telephone, text message, or other means of communication regarding an alert that has been distributed to the public; and

22(H) any other procedure the Administrator considers appropriate for maintaining the integrity of and providing for public confidence in the public alert and warning system.

23The Administrator shall ensure that the minimum requirements developed under paragraph (1) do not conflict with recommendations made for improving the public alert and warning system provided in the report submitted by the National Advisory Council under section 2(b)(7)(B) of the Integrated Public Alert and Warning System Modernization Act of 2015 (Public Law 114–143; 130 Stat. 332).

24In developing the minimum requirements under paragraph (1), the Administrator shall ensure appropriate public consultation and, to the extent practicable, coordinate the development of the requirements with stakeholders of the public alert and warning system, including—

25(A) appropriate personnel from Federal agencies, including the National Institute of Standards and Technology, the Agency, and the Federal Communications Commission;

26(B) representatives of State and local governments and emergency services personnel, who shall be selected from among individuals nominated by national organizations representing those governments and personnel;

27(C) representatives of Federally recognized Indian tribes and national Indian organizations;

28(D) communications service providers;

29(E) vendors, developers, and manufacturers of systems, facilities, equipment, and capabilities for the provision of communications services;

30(F) third-party service bureaus;

31(G) the national organization representing the licensees and permittees of noncommercial broadcast television stations;

32(H) technical experts from the broadcasting industry;

33(I) educators from the Emergency Management Institute; and

34(J) other individuals with technical expertise as the Administrator determines appropriate.

35In accordance with the Federal Advisory Committee Act (5 U.S.C. App.),1 the Administrator may obtain advice from a single individual or non-consensus advice from each of the several members of a group without invoking that Act.

36The Administrator shall establish a process to ensure that an incident management and warning tool used by a State, Tribal, or local government to originate and transmit an alert through the public alert and warning system meets the requirements developed by the Administrator under subsection (b)(1).

37The process required to be established under paragraph (1) shall include—

38(A) the ability to test an incident management and warning tool in the public alert and warning system lab;

39(B) the ability to certify that an incident management and warning tool complies with the applicable cyber frameworks of the Department of Homeland Security and the National Institute of Standards and Technology;

40(C) a process to certify developers of emergency management software; and

41(D) requiring developers to provide the Administrator with a copy of and rights of use for ongoing testing of each version of incident management and warning tool software before the software is first used by a State, Tribal, or local government.

42The Administrator shall review the memoranda of understanding between the Agency and State, Tribal, and local governments with respect to the public alert and warning system to ensure that all agreements ensure compliance with the requirements developed by the Administrator under subsection (b)(1).

43On and after the date that is 60 days after the date on which the Administrator issues the requirements developed under subsection (b)(1), any new memorandum of understanding entered into between the Agency and a State, Tribal, or local government with respect to the public alert and warning system shall comply with those requirements.

44On and after the date that is 120 days after December 20, 2019, the authority to originate an alert warning the public of a missile launch directed against a State using the public alert and warning system shall reside primarily with the Federal Government.

45The Secretary may delegate the authority described in subparagraph (A) to a State, Tribal, or local entity if, not later than 180 days after December 20, 2019, the Secretary submits a report to the appropriate congressional committees that—

46(i) it is not feasible for the Federal Government to alert the public of a missile threat against a State; or

47(ii) it is not in the national security interest of the United States for the Federal Government to alert the public of a missile threat against a State.

48Upon verification of a missile threat, the President, utilizing established authorities, protocols and procedures, may activate the public alert and warning system.

49Nothing in this paragraph shall be construed to change the command and control relationship between entities of the Federal Government with respect to the identification, dissemination, notification, or alerting of information of missile threats against the United States that was in effect on the day before December 20, 2019.

50The Secretary, acting through the Administrator, shall establish a process to promptly notify a State warning point, and any State entities that the Administrator determines appropriate, following the issuance of an alert described in paragraph (1)(A) so the State may take appropriate action to protect the health, safety, and welfare of the residents of the State.

51The Secretary, acting through the Administrator, shall work with the Governor of a State warning point to develop and implement appropriate protective action plans to respond to an alert described in paragraph (1)(A) for that State.

52Not later than 1 year after December 20, 2019, the Secretary shall—

53(A) examine the feasibility of establishing an alert designation under the public alert and warning system that would be used to alert and warn the public of a missile threat while concurrently alerting a State warning point so that a State may activate related protective action plans; and

54(B) submit a report of the findings under subparagraph (A), including of the costs and timeline for taking action to implement an alert designation described in subparagraph (A), to—

55(i) the Subcommittee on Homeland Security of the Committee on Appropriations of the Senate;

56(ii) the Committee on Homeland Security and Governmental Affairs of the Senate;

57(iii) the Subcommittee on Homeland Security of the Committee on Appropriations of the House of Representatives;

58(iv) the Committee on Transportation and Infrastructure of the House of Representatives; and

59(v) the Committee on Homeland Security of the House of Representatives.

60Not later than 1 year after December 20, 2019, the Administrator shall—

61(1) develop a program to increase the utilization of the public alert and warning system lab of the Agency by State, Tribal, and local governments to test incident management and warning tools and train emergency management professionals on alert origination protocols and procedures; and

62(2) submit to the appropriate congressional committees a report describing—

63(A) the impact on utilization of the public alert and warning system lab by State, Tribal, and local governments, with particular attention given to the impact on utilization in rural areas, resulting from the program developed under paragraph (1); and

64(B) any further recommendations that the Administrator would make for additional statutory or appropriations authority necessary to increase the utilization of the public alert and warning system lab by State, Tribal, and local governments.

65Not later than 1 year after December 20, 2019, the Administrator shall—

66(1) conduct a review of the National Watch Center and each Regional Watch Center of the Agency; and

67(2) submit to the appropriate congressional committees a report on the review conducted under paragraph (1), which shall include—

68(A) an assessment of the technical capability of the National and Regional Watch Centers described in paragraph (1) to be notified of alerts and warnings issued by a State through the public alert and warning system;

69(B) a determination of which State alerts and warnings the National and Regional Watch Centers described in paragraph (1) should be aware of; and

70(C) recommendations for improving the ability of the National and Regional Watch Centers described in paragraph (1) to receive any State alerts and warnings that the Administrator determines are appropriate.

71Not later than 15 days after the date on which a State, Tribal, or local government official transmits a false alert under the public alert and warning system, the Administrator shall report to the appropriate congressional committees on—

72(1) the circumstances surrounding the false alert;

73(2) the content, cause, and population impacted by the false alert; and

74(3) any efforts to mitigate any negative impacts of the false alert.

75The Administrator shall, on an annual basis, report to the appropriate congressional committees on—

76(1) participation rates in the public alert and warning system; and

77(2) any efforts to expand alert, warning, and interoperable communications to rural and underserved areas.

78Each State shall be given a reasonable amount of time to comply with any new rules, regulations, or requirements imposed under this section.

321p.

National planning and education

1The Secretary shall, to the extent practicable—

2(1) include in national planning frameworks the threat of an EMP or GMD event; and

3(2) conduct outreach to educate owners and operators of critical infrastructure, emergency planners, and emergency response providers at all levels of government regarding threats of EMP and GMD.

321q.

Coordination of Department of Homeland Security efforts related to food, agriculture, and veterinary defense against terrorism

1The Secretary, acting through the Assistant Secretary for the Countering Weapons of Mass Destruction Office, shall carry out a program to coordinate the Department's efforts related to defending the food, agriculture, and veterinary systems of the United States against terrorism and other high-consequence events that pose a high risk to homeland security.

2The coordination program required by subsection (a) shall include, at a minimum, the following:

3(1) Providing oversight and management of the Department's responsibilities pursuant to Homeland Security Presidential Directive 9–Defense of United States Agriculture and Food.

4(2) Providing oversight and integration of the Department's activities related to veterinary public health, food defense, and agricultural security.

5(3) Leading the Department's policy initiatives relating to food, animal, and agricultural incidents, and the impact of such incidents on animal and public health.

6(4) Leading the Department's policy initiatives relating to overall domestic preparedness for and collective response to agricultural terrorism.

7(5) Coordinating with other Department components, including U.S. Customs and Border Protection, as appropriate, on activities related to food and agriculture security and screening procedures for domestic and imported products.

8(6) Coordinating with appropriate Federal departments and agencies.

9(7) Other activities as determined necessary by the Secretary.

10Nothing in this section may be construed as altering or superseding the authority of the Secretary of Agriculture or the Secretary of Health and Human Services.

321r.

Transfer of equipment during a public health emergency

1During a public health emergency declared by the Secretary of Health and Human Services under section 247d(a) of title 42, the Secretary, at the request of the Secretary of Health and Human Services, may transfer to the Department of Health and Human Services, on a reimbursable basis, excess personal protective equipment or medically necessary equipment in the possession of the Department.

2In carrying out this section—

3(A) before requesting a transfer under subsection (a), the Secretary of Health and Human Services shall determine whether the personal protective equipment or medically necessary equipment is otherwise available; and

4(B) before initiating a transfer under subsection (a), the Secretary, in consultation with the heads of each component within the Department, shall—

5(i) determine whether the personal protective equipment or medically necessary equipment requested to be transferred under subsection (a) is excess equipment; and

6(ii) certify that the transfer of the personal protective equipment or medically necessary equipment will not adversely impact the health or safety of officers, employees, or contractors of the Department.

7The Secretary of Health and Human Services and the Secretary shall each submit to Congress a notification explaining the determination made under subparagraphs (A) and (B), respectively, of paragraph (1).

8The Secretary shall—

9(i) acting through the Chief Medical Officer of the Department, maintain an inventory of all personal protective equipment and medically necessary equipment in the possession of the Department; and

10(ii) make the inventory required under clause (i) available, on a continual basis, to—

11(I) the Secretary of Health and Human Services; and

12(II) the Committee on Appropriations and the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Appropriations and the Committee on Homeland Security of the House of Representatives.

13Each inventory required to be made available under subparagraph (A) shall be submitted in unclassified form, but may include a classified annex.

322.

Continuity of the economy plan

1The President shall develop and maintain a plan to maintain and restore the economy of the United States in response to a significant event.

2The plan required under paragraph (1) shall—

3(A) be consistent with—

4(i) a free market economy; and

5(ii) the rule of law; and

6(B) respect private property rights.

7The plan required under paragraph (1) shall—

8(A) examine the distribution of goods and services across the United States necessary for the reliable functioning of the United States during a significant event;

9(B) identify the economic functions of relevant actors, the disruption, corruption, or dysfunction of which would have a debilitating effect in the United States on—

10(i) security;

11(ii) economic security;

12(iii) defense readiness; or

13(iv) public health or safety;

14(C) identify the critical distribution mechanisms for each economic sector that should be prioritized for operation during a significant event, including—

15(i) bulk power and electric transmission systems;

16(ii) national and international financial systems, including wholesale payments, stocks, and currency exchanges;

17(iii) national and international communications networks, data-hosting services, and cloud services;

18(iv) interstate oil and natural gas pipelines; and

19(v) mechanisms for the interstate and international trade and distribution of materials, food, and medical supplies, including road, rail, air, and maritime shipping;

20(D) identify economic functions of relevant actors, the disruption, corruption, or dysfunction of which would cause—

21(i) catastrophic economic loss;

22(ii) the loss of public confidence; or

23(iii) the widespread imperilment of human life;

24(E) identify the economic functions of relevant actors that are so vital to the economy of the United States that the disruption, corruption, or dysfunction of those economic functions would undermine response, recovery, or mobilization efforts during a significant event;

25(F) incorporate, to the greatest extent practicable, the principles and practices contained within Federal plans for the continuity of Government and continuity of operations;

26(G) identify—

27(i) industrial control networks for which a loss of internet connectivity, a loss of network integrity or availability, an exploitation of a system connected to the network, or another failure, disruption, corruption, or dysfunction would have a debilitating effect in the United States on—

28(I) security;

29(II) economic security;

30(III) defense readiness; or

31(IV) public health or safety; and

32(ii) for each industrial control network identified under clause (i), risk mitigation measures, including—

33(I) the installation of parallel services;

34(II) the use of stand-alone analog services; or

35(III) the significant hardening of the industrial control network against failure, disruption, corruption, or dysfunction;

36(H) identify critical economic sectors for which the preservation of data in a protected, verified, and uncorrupted status would be required for the quick recovery of the economy of the United States in the face of a significant disruption following a significant event;

37(I) include a list of raw materials, industrial goods, and other items, the absence of which would significantly undermine the ability of the United States to sustain the functions described in subparagraphs (B), (D), and (E);

38(J) provide an analysis of supply chain diversification for the items described in subparagraph (I) in the event of a disruption caused by a significant event;

39(K) include—

40(i) a recommendation as to whether the United States should maintain a strategic reserve of 1 or more of the items described in subparagraph (I); and

41(ii) for each item described in subparagraph (I) for which the President recommends maintaining a strategic reserve under clause (i), an identification of mechanisms for tracking inventory and availability of the item in the strategic reserve;

42(L) identify mechanisms in existence on January 1, 2021 and mechanisms that can be developed to ensure that the swift transport and delivery of the items described in subparagraph (I) is feasible in the event of a distribution network disturbance or degradation, including a distribution network disturbance or degradation caused by a significant event;

43(M) include guidance for determining the prioritization for the distribution of the items described in subparagraph (I), including distribution to States and Indian Tribes;

44(N) consider the advisability and feasibility of mechanisms for extending the credit of the United States or providing other financial support authorized by law to key participants in the economy of the United States if the extension or provision of other financial support—

45(i) is necessary to avoid severe economic degradation; or

46(ii) allows for the recovery from a significant event;

47(O) include guidance for determining categories of employees that should be prioritized to continue to work in order to sustain the functions described in subparagraphs (B), (D), and (E) in the event that there are limitations on the ability of individuals to travel to workplaces or to work remotely, including considerations for defense readiness;

48(P) identify critical economic sectors necessary to provide material and operational support to the defense of the United States;

49(Q) determine whether the Secretary of Homeland Security, the National Guard, and the Secretary of Defense have adequate authority to assist the United States in a recovery from a severe economic degradation caused by a significant event;

50(R) review and assess the authority and capability of heads of other agencies that the President determines necessary to assist the United States in a recovery from a severe economic degradation caused by a significant event; and

51(S) consider any other matter that would aid in protecting and increasing the resilience of the economy of the United States from a significant event.

52In developing the plan required under subsection (a)(1), the President shall—

53(1) receive advice from—

54(A) the Secretary of Homeland Security;

55(B) the Secretary of Defense;

56(C) the Secretary of the Treasury;

57(D) the Secretary of Health and Human Services;

58(E) the Secretary of Commerce;

59(F) the Secretary of Transportation;

60(G) the Secretary of Energy;

61(H) the Administrator of the Small Business Administration; and

62(I) the head of any other agency that the President determines necessary to complete the plan;

63(2) consult with economic sectors relating to critical infrastructure through sector-coordinated councils, as appropriate;

64(3) consult with relevant State, Tribal, and local governments and organizations that represent those governments; and

65(4) consult with any other non-Federal entity that the President determines necessary to complete the plan.

66Not later than 2 years after January 1, 2021, and not less frequently than every 3 years thereafter, the President shall submit the plan required under subsection (a)(1) and the information described in paragraph (2) to—

67(A) the majority and minority leaders of the Senate;

68(B) the Speaker and the minority leader of the House of Representatives;

69(C) the Committee on Armed Services of the Senate;

70(D) the Committee on Armed Services of the House of Representatives;

71(E) the Committee on Homeland Security and Governmental Affairs of the Senate;

72(F) the Committee on Homeland Security of the House of Representatives;

73(G) the Committee on Health, Education, Labor, and Pensions of the Senate;

74(H) the Committee on Commerce, Science, and Transportation of the Senate;

75(I) the Committee on Energy and Commerce of the House of Representatives;

76(J) the Committee on Banking, Housing, and Urban Affairs of the Senate;

77(K) the Committee on Finance of the Senate;

78(L) the Committee on Financial Services of the House of Representatives;

79(M) the Committee on Small Business and Entrepreneurship of the Senate;

80(N) the Committee on Small Business of the House of Representatives;

81(O) the Committee on Energy and Natural Resources of the Senate;

82(P) the Committee on Environment and Public Works of the Senate;

83(Q) the Committee on Indian Affairs of the Senate;

84(R) the Committee on Oversight and Reform of the House of Representatives;

85(S) Committee on the Budget of the House of Representatives; and

86(T) any other committee of the Senate or the House of Representatives that has jurisdiction over the subject of the plan.

87The information described in this paragraph is—

88(A) any change to Federal law that would be necessary to carry out the plan required under subsection (a)(1); and

89(B) any proposed changes to the funding levels provided in appropriation Acts for the most recent fiscal year that can be implemented in future appropriation Acts or additional resources necessary to—

90(i) implement the plan required under subsection (a)(1); or

91(ii) maintain any program offices and personnel necessary to—

92(I) maintain the plan required under subsection (a)(1) and the plans described in subsection (a)(3)(F); and

93(II) conduct exercises, assessments, and updates to the plans described in subclause (I) over time.

94The President may include the information described in paragraph (2)(B) in the budget required to be submitted by the President under section 1105(a) of title 31.

95In this section:

96(1) The term "agency" has the meaning given the term in section 551 of title 5.

97(2) The term "economic sector" means a sector of the economy of the United States.

98(3) The term "relevant actor" means—

99(A) the Federal Government;

100(B) a State, local, or Tribal government; or

101(C) the private sector.

102(4) The term "significant event" means an event that causes severe degradation to economic activity in the United States due to—

103(A) a cyber attack; or

104(B) another significant event that is natural or human-caused.

105(5) The term "State" means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Virgin Islands, Guam, American Samoa, the Commonwealth of the Northern Mariana Islands, and any possession of the United States.

323.

Guidance on how to prevent exposure to and release of PFAS

1Not later than 1 year after December 20, 2022, the Secretary of Homeland Security, in consultation with the Administrator of the United States Fire Administration, the Administrator of the Environmental Protection Agency, the Director of the National Institute for Occupational Safety and Health, and the heads of any other relevant agencies, shall—

2(1) develop and publish guidance for firefighters and other emergency response personnel on training, education programs, and best practices;

3(2) make available a curriculum designed to—

4(A) reduce and eliminate exposure to per- and polyfluoroalkyl substances (commonly referred to as "PFAS") from firefighting foam and personal protective equipment;

5(B) prevent the release of PFAS from firefighting foam into the environment; and

6(C) educate firefighters and other emergency response personnel on foams and non-foam alternatives, personal protective equipment, and other firefighting tools and equipment that do not contain PFAS; and

7(3) create an online public repository, which shall be updated on a regular basis, on tools and best practices for firefighters and other emergency response personnel to reduce, limit, and prevent the release of and exposure to PFAS.

8For the purpose of developing the curriculum required under subsection (a)(2), the Administrator of the United States Fire Administration shall make recommendations to the Secretary of Homeland Security as to the content of the curriculum.

9For the purpose of making recommendations under paragraph (1), the Administrator of the United States Fire Administration shall consult with interested entities, as appropriate, including—

10(A) firefighters and other emergency response personnel, including national fire service and emergency response organizations;

11(B) impacted communities dealing with PFAS contamination;

12(C) scientists, including public and occupational health and safety experts, who are studying PFAS and PFAS alternatives in firefighting foam;

13(D) voluntary standards organizations engaged in developing standards for firefighter and firefighting equipment;

14(E) State fire training academies;

15(F) State fire marshals;

16(G) manufacturers of firefighting tools and equipment; and

17(H) any other relevant entities, as determined by the Secretary of Homeland Security and the Administrator of the United States Fire Administration.

18Not later than 3 years after the date on which the guidance and curriculum required under subsection (a) is issued, and not less frequently than once every 3 years thereafter, the Secretary of Homeland Security, in consultation with the Administrator of the United States Fire Administration, the Administrator of the Environmental Protection Agency, and the Director of the National Institute for Occupational Safety and Health, shall review the guidance and curriculum and, as appropriate, issue updates to the guidance and curriculum.

19The Federal Advisory Committee Act (5 U.S.C. App.) 1 shall not apply to this Act.

20Nothing in this Act shall be construed to require the Secretary of Homeland Security to promulgate or enforce regulations under subchapter II of chapter 5 of title 5 (commonly known as the "Administrative Procedure Act").

331.

Treatment of charitable trusts for members of the Armed Forces of the United States and other governmental organizations

1Congress finds the following:

2(1) Members of the Armed Forces of the United States defend the freedom and security of our Nation.

3(2) Members of the Armed Forces of the United States have lost their lives while battling the evils of terrorism around the world.

4(3) Personnel of the Central Intelligence Agency (CIA) charged with the responsibility of covert observation of terrorists around the world are often put in harm's way during their service to the United States.

5(4) Personnel of the Central Intelligence Agency have also lost their lives while battling the evils of terrorism around the world.

6(5) Employees of the Federal Bureau of Investigation (FBI) and other Federal agencies charged with domestic protection of the United States put their lives at risk on a daily basis for the freedom and security of our Nation.

7(6) United States military personnel, CIA personnel, FBI personnel, and other Federal agents in the service of the United States are patriots of the highest order.

8(7) CIA officer Johnny Micheal Spann became the first American to give his life for his country in the War on Terrorism declared by President George W. Bush following the terrorist attacks of September 11, 2001.

9(8) Johnny Micheal Spann left behind a wife and children who are very proud of the heroic actions of their patriot father.

10(9) Surviving dependents of members of the Armed Forces of the United States who lose their lives as a result of terrorist attacks or military operations abroad receive a $6,000 death benefit, plus a small monthly benefit.

11(10) The current system of compensating spouses and children of American patriots is inequitable and needs improvement.

12Any charitable corporation, fund, foundation, or trust (or separate fund or account thereof) which otherwise meets all applicable requirements under law with respect to charitable entities and meets the requirements described in subsection (c) shall be eligible to characterize itself as a "Johnny Micheal Spann Patriot Trust".

13The requirements described in this subsection are as follows:

14(1) Not taking into account funds or donations reasonably necessary to establish a trust, at least 85 percent of all funds or donations (including any earnings on the investment of such funds or donations) received or collected by any Johnny Micheal Spann Patriot Trust must be distributed to (or, if placed in a private foundation, held in trust for) surviving spouses, children, or dependent parents, grandparents, or siblings of 1 or more of the following:

15(A) members of the Armed Forces of the United States;

16(B) personnel, including contractors, of elements of the intelligence community, as defined in section 3003(4) of title 50;

17(C) employees of the Federal Bureau of Investigation; and

18(D) officers, employees, or contract employees of the United States Government,

19whose deaths occur in the line of duty and arise out of terrorist attacks, military operations, intelligence operations, or law enforcement operations or accidents connected with activities occurring after September 11, 2001, and related to domestic or foreign efforts to curb international terrorism, including the Authorization for Use of Military Force (Public Law 107–40; 115 Stat. 224).

20(2) Other than funds or donations reasonably necessary to establish a trust, not more than 15 percent of all funds or donations (or 15 percent of annual earnings on funds invested in a private foundation) may be used for administrative purposes.

21(3) No part of the net earnings of any Johnny Micheal Spann Patriot Trust may inure to the benefit of any individual based solely on the position of such individual as a shareholder, an officer or employee of such Trust.

22(4) None of the activities of any Johnny Micheal Spann Patriot Trust shall be conducted in a manner inconsistent with any law that prohibits attempting to influence legislation.

23(5) No Johnny Micheal Spann Patriot Trust may participate in or intervene in any political campaign on behalf of (or in opposition to) any candidate for public office, including by publication or distribution of statements.

24(6) Each Johnny Micheal Spann Patriot Trust shall comply with the instructions and directions of the Director of Central Intelligence, the Attorney General, or the Secretary of Defense relating to the protection of intelligence sources and methods, sensitive law enforcement information, or other sensitive national security information, including methods for confidentially disbursing funds.

25(7) Each Johnny Micheal Spann Patriot Trust that receives annual contributions totaling more than $1,000,000 must be audited annually by an independent certified public accounting firm. Such audits shall be filed with the Internal Revenue Service, and shall be open to public inspection, except that the conduct, filing, and availability of the audit shall be consistent with the protection of intelligence sources and methods, of sensitive law enforcement information, and of other sensitive national security information.

26(8) Each Johnny Micheal Spann Patriot Trust shall make distributions to beneficiaries described in paragraph (1) at least once every calendar year, beginning not later than 12 months after the formation of such Trust, and all funds and donations received and earnings not placed in a private foundation dedicated to such beneficiaries must be distributed within 36 months after the end of the fiscal year in which such funds, donations, and earnings are received.

27(9)(A) When determining the amount of a distribution to any beneficiary described in paragraph (1), a Johnny Micheal Spann Patriot Trust should take into account the amount of any collateral source compensation that the beneficiary has received or is entitled to receive as a result of the death of an individual described in paragraph (1).

28(B) Collateral source compensation includes all compensation from collateral sources, including life insurance, pension funds, death benefit programs, and payments by Federal, State, or local governments related to the death of an individual described in paragraph (1).

29Each Johnny Micheal Spann Patriot Trust shall refrain from conducting the activities described in clauses (i) and (ii) of section 30101(20)(A) of title 52 so that a general solicitation of funds by an individual described in paragraph (1) of section 30125(e) of title 52 will be permissible if such solicitation meets the requirements of paragraph (4)(A) of such section.

30Notwithstanding any other provision of law, and in a manner consistent with the protection of intelligence sources and methods and sensitive law enforcement information, and other sensitive national security information, the Secretary of Defense, the Director of the Federal Bureau of Investigation, or the Director of Central Intelligence, or their designees, as applicable, may forward information received from an executor, administrator, or other legal representative of the estate of a decedent described in subparagraph (A), (B), (C), or (D) of subsection (c)(1), to a Johnny Micheal Spann Patriot Trust on how to contact individuals eligible for a distribution under subsection (c)(1) for the purpose of providing assistance from such Trust: Provided, That, neither forwarding nor failing to forward any information under this subsection shall create any cause of action against any Federal department, agency, officer, agent, or employee.

31Not later than 90 days after November 25, 2002, the Secretary of Defense, in coordination with the Attorney General, the Director of the Federal Bureau of Investigation, and the Director of Central Intelligence, shall prescribe regulations to carry out this section.

341.

Under Secretary for Management

1The Under Secretary for Management shall serve as the Chief Management Officer and principal advisor to the Secretary on matters related to the management of the Department, including management integration and transformation in support of homeland security operations and programs. The Secretary, acting through the Under Secretary for Management, shall be responsible for the management and administration of the Department, including the following:

2(1) The budget, appropriations, expenditures of funds, accounting, and finance.

3(2) Procurement.

4(3) Human resources and personnel.

5(4) Information technology and communications systems, including policies and directives to achieve and maintain interoperable communications among the components of the Department.

6(5) Facilities, property, equipment, vehicle fleets (under subsection (c)), and other material resources.

7(6) Security for personnel, information technology and communications systems, facilities, property, equipment, and other material resources.

8(7) Strategic management planning and annual performance planning and identification and tracking of performance measures relating to the responsibilities of the Department.

9(8) Grants and other assistance management programs.

10(9) The management integration and transformation within each functional management discipline of the Department, including information technology, financial management, acquisition management, and human capital management, to ensure an efficient and orderly consolidation of functions and personnel in the Department, including—

11(A) the development of centralized data sources and connectivity of information systems to the greatest extent practicable to enhance program visibility, transparency, and operational effectiveness and coordination;

12(B) the development of standardized and automated management information to manage and oversee programs and make informed decisions to improve the efficiency of the Department;

13(C) the development of effective program management and regular oversight mechanisms, including clear roles and processes for program governance, sharing of best practices, and access to timely, reliable, and evaluated data on all acquisitions and investments; and

14(D) the overall supervision, including the conduct of internal audits and management analyses, of the programs and activities of the Department, including establishment of oversight procedures to ensure a full and effective review of the efforts by components of the Department to implement policies and procedures of the Department for management integration and transformation.

15(10) The development of a transition and succession plan, before December 1 of each year in which a Presidential election is held, to guide the transition of Department functions to a new Presidential administration, and making such plan available to the next Secretary and Under Secretary for Management and to the congressional homeland security committees.

16(11) Reporting to the Government Accountability Office every six months to demonstrate measurable, sustainable progress made in implementing the corrective action plans of the Department to address the designation of the management functions of the Department on the bi-annual high risk list of the Government Accountability Office, until the Comptroller General of the United States submits to the appropriate congressional committees written notification of removal of the high-risk designation.

17(12) The conduct of internal audits and management analyses of the programs and activities of the Department.

18(13) Any other management duties that the Secretary may designate.

19Not later than five days after the date on which the Chief Procurement Officer or Chief Financial Officer of the Department issues a waiver of the requirement that an agency not engage in business with a contractor or other recipient of funds listed as a party suspended or debarred from receiving contracts, grants, or other types of Federal assistance in the System for Award Management maintained by the General Services Administration, or any successor thereto, the Under Secretary for Management shall submit to the congressional homeland security committees and the Inspector General of the Department notice of the waiver and an explanation of the finding by the Under Secretary that a compelling reason exists for the waiver.

20In carrying out responsibilities regarding vehicle fleets pursuant to subsection (a)(5), the Under Secretary for Management shall be responsible for overseeing and managing vehicle fleets throughout the Department. The Under Secretary shall also be responsible for the following:

21(A) Ensuring that components are in compliance with Federal law, Federal regulations, executive branch guidance, and Department policy (including associated guidance) relating to fleet management and use of vehicles from home to work.

22(B) Developing and distributing a standardized vehicle allocation methodology and fleet management plan for components to use to determine optimal fleet size in accordance with paragraph (4).

23(C) Ensuring that components formally document fleet management decisions.

24(D) Approving component fleet management plans, vehicle leases, and vehicle acquisitions.

25Component heads—

26(i) shall—

27(I) comply with Federal law, Federal regulations, executive branch guidance, and Department policy (including associated guidance) relating to fleet management and use of vehicles from home to work;

28(II) ensure that data related to fleet management is accurate and reliable;

29(III) use such data to develop a vehicle allocation tool derived by using the standardized vehicle allocation methodology provided by the Under Secretary for Management to determine the optimal fleet size for the next fiscal year and a fleet management plan; and

30(IV) use vehicle allocation methodologies and fleet management plans to develop annual requests for funding to support vehicle fleets pursuant to paragraph (6); and

31(ii) may not, except as provided in subparagraph (B), lease or acquire new vehicles or replace existing vehicles without prior approval from the Under Secretary for Management pursuant to paragraph (5)(B).

32If exigent circumstances warrant such, a component head may lease or acquire a new vehicle or replace an existing vehicle without prior approval from the Under Secretary for Management. If under such exigent circumstances a component head so leases, acquires, or replaces a vehicle, such component head shall provide to the Under Secretary an explanation of such circumstances.

33In accordance with paragraph (4), the Under Secretary for Management shall collect, on a quarterly basis, information regarding component vehicle fleets, including information on fleet size, composition, cost, and vehicle utilization.

34The Under Secretary for Management shall seek to achieve a capability to collect, on a quarterly basis, automated information regarding component vehicle fleets, including the number of trips, miles driven, hours and days used, and the associated costs of such mileage for leased vehicles.

35The Under Secretary for Management shall track and monitor component information provided pursuant to subparagraph (A) and, as appropriate, subparagraph (B), to ensure that component vehicle fleets are the optimal fleet size and cost effective. The Under Secretary shall use such information to inform the annual component fleet analyses referred to in paragraph (4).

36To determine the optimal fleet size and associated resources needed for each fiscal year beginning with fiscal year 2018, component heads shall annually submit to the Under Secretary for Management a vehicle allocation tool and fleet management plan using information described in paragraph (3)(A). Such tools and plans may be submitted in classified form if a component head determines that such is necessary to protect operations or mission requirements.

37Component heads shall develop a vehicle allocation tool in accordance with subclause (III) of paragraph (2)(A)(i) that includes an analysis of the following:

38(i) Vehicle utilization data, including the number of trips, miles driven, hours and days used, and the associated costs of such mileage for leased vehicles, in accordance with such paragraph.

39(ii) The role of vehicle fleets in supporting mission requirements for each component.

40(iii) Any other information determined relevant by such component heads.

41Component heads shall use information described in subparagraph (B) to develop a fleet management plan for each such component. Such fleet management plans shall include the following:

42(i) A plan for how each such component may achieve optimal fleet size determined by the vehicle allocation tool required under such subparagraph, including the elimination of excess vehicles in accordance with paragraph (5), if applicable.

43(ii) A cost benefit analysis supporting such plan.

44(iii) A schedule each such component will follow to obtain optimal fleet size.

45(iv) Any other information determined relevant by component heads.

46The Under Secretary for Management shall review and make a determination on the results of each component's vehicle allocation tool and fleet management plan under this paragraph to ensure each such component's vehicle fleets are the optimal fleet size and that components are in compliance with applicable Federal law, Federal regulations, executive branch guidance, and Department policy (including associated guidance) pursuant to paragraph (2) relating to fleet management and use of vehicles from home to work. The Under Secretary shall use such tools and plans when reviewing annual component requests for vehicle fleet funding in accordance with paragraph (6).

47The Under Secretary for Management shall provide guidance, pursuant to paragraph (1)(B) on how component heads may achieve optimal fleet size in accordance with paragraph (4), including processes for the following:

48(A) Leasing or acquiring additional vehicles or replacing existing vehicles, if determined necessary.

49(B) Disposing of excess vehicles that the Under Secretary determines should not be reallocated under subparagraph (C).

50(C) Reallocating excess vehicles to other components that may need temporary or long-term use of additional vehicles.

51As part of the annual budget process, the Under Secretary for Management shall review and make determinations regarding annual component requests for funding for vehicle fleets. If component heads have not taken steps in furtherance of achieving optimal fleet size in the prior fiscal year pursuant to paragraphs (4) and (5), the Under Secretary shall provide rescission recommendations to the Committee on Appropriations and the Committee on Homeland Security of the House of Representatives and the Committee on Appropriations and the Committee on Homeland Security and Governmental Affairs of the Senate regarding such component vehicle fleets.

52The Under Secretary for Management and component heads may not approve in any fiscal year beginning with fiscal year 2019 a vehicle lease, acquisition, or replacement request if such component heads did not comply in the prior fiscal year with paragraph (4).

53No Department official with vehicle fleet management responsibilities may receive annual performance compensation in pay in any fiscal year beginning with fiscal year 2019 if such official did not comply in the prior fiscal year with paragraph (4).

54Notwithstanding any other provision of law, no senior executive service official of the Department whose office has a vehicle fleet may receive access to a car service in any fiscal year beginning with fiscal year 2019 if such official did not comply in the prior fiscal year with paragraph (4).

55The Under Secretary for Management may determine the feasibility of operating a vehicle motor pool to permit components to share vehicles as necessary to support mission requirements to reduce the number of excess vehicles in the Department.

56The determination of feasibility of operating a vehicle motor pool under subparagraph (A) shall—

57(i) include—

58(I) regions in the United States in which multiple components with vehicle fleets are located in proximity to one another, or a significant number of employees with authorization to use vehicles are located; and

59(II) law enforcement vehicles;

60(ii) cover the National Capital Region; and

61(iii) take into account different mission requirements.

62The Secretary shall include in the Department's next annual performance report required under current law the results of the determination under this paragraph.

63In this subsection:

64The term "component head" means the head of any component of the Department with a vehicle fleet.

65The term "excess vehicle" means any vehicle that is not essential to support mission requirements of a component.

66The term "optimal fleet size" means, with respect to a particular component, the appropriate number of vehicles to support mission requirements of such component.

67The term "vehicle fleet" means all owned, commercially leased, or Government-leased vehicles of the Department or of a component of the Department, as the case may be, including vehicles used for law enforcement and other purposes.

68The Under Secretary for Management shall—

69(1) be appointed by the President, by and with the advice and consent of the Senate, from among persons who have—

70(A) extensive executive level leadership and management experience in the public or private sector;

71(B) strong leadership skills;

72(C) a demonstrated ability to manage large and complex organizations; and

73(D) a proven record in achieving positive operational results;

74(2) enter into an annual performance agreement with the Secretary that shall set forth measurable individual and organizational goals; and

75(3) be subject to an annual performance evaluation by the Secretary, who shall determine as part of each such evaluation whether the Under Secretary for Management has made satisfactory progress toward achieving the goals set out in the performance agreement required under paragraph (2).

76The Under Secretary for Management shall require that all Department contracting and grant officials consult the System for Award Management (or successor system) as maintained by the General Services Administration prior to awarding a contract or grant or entering into other transactions to ascertain whether the selected contractor is excluded from receiving Federal contracts, certain subcontracts, and certain types of Federal financial and non-financial assistance and benefits.

77In this section, the term "interoperable communications" has the meaning given that term in section 194(g) of this title.

342.

Chief Financial Officer

1The Chief Financial Officer shall perform functions as specified in chapter 9 of title 31 and, with respect to all such functions and other responsibilities that may be assigned to the Chief Financial Officer from time to time, shall also report to the Under Secretary for Management.

2Not later than 90 days after October 16, 2004, the Secretary shall establish an Office of Program Analysis and Evaluation within the Department (in this section referred to as the "Office").

3The Office shall perform the following functions:

4(A) Analyze and evaluate plans, programs, and budgets of the Department in relation to United States homeland security objectives, projected threats, vulnerability assessments, estimated costs, resource constraints, and the most recent homeland security strategy developed pursuant to section 454(b)(2) of this title.

5(B) Develop and perform analyses and evaluations of alternative plans, programs, personnel levels, and budget submissions for the Department in relation to United States homeland security objectives, projected threats, vulnerability assessments, estimated costs, resource constraints, and the most recent homeland security strategy developed pursuant to section 454(b)(2) of this title.

6(C) Establish policies for, and oversee the integration of, the planning, programming, and budgeting system of the Department.

7(D) Review and ensure that the Department meets performance-based budget requirements established by the Office of Management and Budget.

8(E) Provide guidance for, and oversee the development of, the Future Years Homeland Security Program of the Department, as specified under section 454 of this title.

9(F) Ensure that the costs of Department programs, including classified programs, are presented accurately and completely.

10(G) Oversee the preparation of the annual performance plan for the Department and the program and performance section of the annual report on program performance for the Department, consistent with sections 1115 and 1116, respectively, of title 31.

11(H) Provide leadership in developing and promoting improved analytical tools and methods for analyzing homeland security planning and the allocation of resources.

12(I) Any other responsibilities delegated by the Secretary consistent with an effective program analysis and evaluation function.

13There shall be a Director of Program Analysis and Evaluation, who—

14(A) shall be a principal staff assistant to the Chief Financial Officer of the Department for program analysis and evaluation; and

15(B) shall report to an official no lower than the Chief Financial Officer.

16The Secretary may allocate or reallocate the functions of the Office, or discontinue the Office, in accordance with section 452(a) of this title.

17Section 452(b) of this title shall not apply to any action by the Secretary under this paragraph.

18In any case in which appropriations available to the Department or any officer of the Department are transferred or reprogrammed and notice of such transfer or reprogramming is submitted to the Congress (including any officer, office, or Committee of the Congress), the Chief Financial Officer of the Department shall simultaneously submit such notice to the Select Committee on Homeland Security (or any successor to the jurisdiction of that committee) and the Committee on Government Reform of the House of Representatives, and to the Committee on Governmental Affairs of the Senate.

343.

Chief Information Officer

1The Chief Information Officer shall report to the Secretary, or to another official of the Department, as the Secretary may direct.

2As used in this subsection:

3The term "geospatial information" means graphical or digital data depicting natural or manmade physical features, phenomena, or boundaries of the earth and any information related thereto, including surveys, maps, charts, remote sensing data, and images.

4The term "geospatial technology" means any technology utilized by analysts, specialists, surveyors, photogrammetrists, hydrographers, geodesists, cartographers, architects, or engineers for the collection, storage, retrieval, or dissemination of geospatial information, including—

5(i) global satellite surveillance systems;

6(ii) global position systems;

7(iii) geographic information systems;

8(iv) mapping equipment;

9(v) geocoding technology; and

10(vi) remote sensing devices.

11The Office of Geospatial Management is established within the Office of the Chief Information Officer.

12The Office of Geospatial Management shall be administered by the Geospatial Information Officer, who shall be appointed by the Secretary and serve under the direction of the Chief Information Officer.

13The Geospatial Information Officer shall assist the Chief Information Officer in carrying out all functions under this section and in coordinating the geospatial information needs of the Department.

14The Chief Information Officer shall establish and carry out a program to provide for the efficient use of geospatial information, which shall include—

15(i) providing such geospatial information as may be necessary to implement the critical infrastructure protection programs;

16(ii) providing leadership and coordination in meeting the geospatial information requirements of those responsible for planning, prevention, mitigation, assessment and response to emergencies, critical infrastructure protection, and other functions of the Department; and

17(iii) coordinating with users of geospatial information within the Department to assure interoperability and prevent unnecessary duplication.

18In carrying out this subsection, the responsibilities of the Chief Information Officer shall include—

19(i) coordinating the geospatial information needs and activities of the Department;

20(ii) implementing standards, as adopted by the Director of the Office of Management and Budget under the processes established under section 216 of the E-Government Act of 2002 (44 U.S.C. 3501 note), to facilitate the interoperability of geospatial information pertaining to homeland security among all users of such information within—

21(I) the Department;

22(II) State and local government; and

23(III) the private sector;

24(iii) coordinating with the Federal Geographic Data Committee and carrying out the responsibilities of the Department pursuant to Office of Management and Budget Circular A–16 and Executive Order 12906; and

25(iv) making recommendations to the Secretary and the Executive Director of the Office for State and Local Government Coordination and Preparedness on awarding grants to—

26(I) fund the creation of geospatial data; and

27(II) execute information sharing agreements regarding geospatial data with State, local, and tribal governments.

28There are authorized to be appropriated such sums as may be necessary to carry out this subsection for each fiscal year.

344.

Chief Human Capital Officer

1The Chief Human Capital Officer shall report directly to the Under Secretary for Management.

2In addition to the responsibilities set forth in chapter 14 of title 5 and other applicable law, the Chief Human Capital Officer of the Department shall—

3(1) develop and implement strategic workforce planning policies, including with respect to leader development and employee engagement, that are consistent with Government-wide leading principles, in line with Department strategic human capital goals and priorities, and informed by best practices within the Federal Government and the private sector, taking into account the special requirements of members of the Armed Forces serving in the Coast Guard;

4(2) use performance measures to evaluate, on an ongoing basis, Department-wide strategic workforce planning efforts;

5(3) develop, improve, and implement policies that, to the extent practicable, are informed by employee feedback, including compensation flexibilities available to Federal agencies where appropriate, to recruit, hire, train, and retain the workforce of the Department, in coordination with all components of the Department;

6(4) identify methods for managing and overseeing human capital programs and initiatives, including leader development and employee engagement programs, in coordination with the head of each component of the Department;

7(5) develop a career path framework and create opportunities for leader development in coordination with all components of the Department that is informed by an assessment, carried out by the Chief Human Capital Officer, of the learning and developmental needs of employees in supervisory and nonsupervisory roles across the Department and appropriate workforce planning initiatives;

8(6) lead the efforts of the Department for managing employee resources, including training and development opportunities, in coordination with each component of the Department;

9(7) work to ensure the Department is implementing human capital programs and initiatives and effectively educating each component of the Department about these programs and initiatives;

10(8) identify and eliminate unnecessary and duplicative human capital policies and guidance;

11(9) maintain a catalogue of available employee development opportunities, including the Homeland Security Rotation Program pursuant to section 414 of this title, departmental leadership development programs, interagency development programs, and other rotational programs;

12(10) ensure that employee discipline and adverse action programs comply with the requirements of all pertinent laws, rules, regulations, and Federal guidance, and ensure due process for employees;

13(11) analyze each Department or Government-wide Federal workforce satisfaction or morale survey not later than 90 days after the date of the publication of each such survey and submit to the Secretary such analysis, including, as appropriate, recommendations to improve workforce satisfaction or morale within the Department;

14(12) review and approve all component employee engagement action plans to ensure such plans include initiatives responsive to the root cause of employee engagement challenges, as well as outcome-based performance measures and targets to track the progress of such initiatives;

15(13) provide input concerning the hiring and performance of the Chief Human Capital Officer or comparable official in each component of the Department; and

16(14) ensure that all employees of the Department are informed of their rights and remedies under chapters 12 and 23 of title 5.

17Each component of the Department shall, in coordination with the Chief Human Capital Officer of the Department, develop a 5-year workforce strategy for the component that will support the goals, objectives, and performance measures of the Department for determining the proper balance of Federal employees and private labor resources.

18In developing the strategy required under paragraph (1), each component shall consider the effect on human resources associated with creating additional Federal full-time equivalent positions, converting private contractors to Federal employees, or relying on the private sector for goods and services.

19The Chief Human Capital Officer may designate an employee of the Department to serve as a Chief Learning and Engagement Officer to assist the Chief Human Capital Officer in carrying out this section.

20Not later than 90 days after the date on which the Secretary submits the annual budget justification for the Department, the Secretary shall submit to the congressional homeland security committees a report that includes a table, delineated by component with actual and enacted amounts, including—

21(1) information on the progress within the Department of fulfilling the workforce strategies developed under subsection (c);

22(2) information on employee development opportunities catalogued pursuant to paragraph (9) of subsection (b) and any available data on participation rates, attrition rates, and impacts on retention and employee satisfaction;

23(3) information on the progress of Departmentwide strategic workforce planning efforts as determined under paragraph (2) of subsection (b);

24(4) information on the activities of the steering committee established pursuant to section 351(a) of this title, including the number of meetings, types of materials developed and distributed, and recommendations made to the Secretary;

25(5) the number of on-board staffing for Federal employees from the prior fiscal year;

26(6) the total contract hours submitted by each prime contractor as part of the service contract inventory required under section 743 of the Financial Services and General Government Appropriations Act, 2010 (division C of Public Law 111–117; 31 U.S.C. 501 note); and

27(7) the number of full-time equivalent personnel identified under the Intergovernmental Personnel Act of 1970 (42 U.S.C. 4701 et seq.).

28Nothing in this section overrides or otherwise affects the requirements specified in section 468 of this title.

345.

Establishment of Officer for Civil Rights and Civil Liberties

1The Officer for Civil Rights and Civil Liberties, who shall report directly to the Secretary, shall—

2(1) review and assess information concerning abuses of civil rights, civil liberties, and profiling on the basis of race, ethnicity, or religion, by employees and officials of the Department;

3(2) make public through the Internet, radio, television, or newspaper advertisements information on the responsibilities and functions of, and how to contact, the Officer;

4(3) assist the Secretary, directorates, and offices of the Department to develop, implement, and periodically review Department policies and procedures to ensure that the protection of civil rights and civil liberties is appropriately incorporated into Department programs and activities;

5(4) oversee compliance with constitutional, statutory, regulatory, policy, and other requirements relating to the civil rights and civil liberties of individuals affected by the programs and activities of the Department;

6(5) coordinate with the Privacy Officer to ensure that—

7(A) programs, policies, and procedures involving civil rights, civil liberties, and privacy considerations are addressed in an integrated and comprehensive manner; and

8(B) Congress receives appropriate reports regarding such programs, policies, and procedures; and

9(6) investigate complaints and information indicating possible abuses of civil rights or civil liberties, unless the Inspector General of the Department determines that any such complaint or information should be investigated by the Inspector General.

10The Secretary shall submit to the President of the Senate, the Speaker of the House of Representatives, and the appropriate committees and subcommittees of Congress on an annual basis a report on the implementation of this section, including the use of funds appropriated to carry out this section, and detailing any allegations of abuses described under subsection (a)(1) and any actions taken by the Department in response to such allegations.

346.

Consolidation and co-location of offices

1Not later than 1 year after November 25, 2002, the Secretary shall develop and submit to Congress a plan for consolidating and co-locating—

2(1) any regional offices or field offices of agencies that are transferred to the Department under this chapter, if such officers 1 are located in the same municipality; and

3(2) portions of regional and field offices of other Federal agencies, to the extent such offices perform functions that are transferred to the Secretary under this chapter.

347.

Quadrennial homeland security review

1In fiscal year 2009, and every 4 years thereafter, the Secretary shall conduct a review of the homeland security of the Nation (in this section referred to as a "quadrennial homeland security review").

2Each quadrennial homeland security review shall be a comprehensive examination of the homeland security strategy of the Nation, including recommendations regarding the long-term strategy and priorities of the Nation for homeland security and guidance on the programs, assets, capabilities, budget, policies, and authorities of the Department.

3The Secretary shall conduct each quadrennial homeland security review under this subsection in consultation with—

4(A) the heads of other Federal agencies, including the Attorney General, the Secretary of State, the Secretary of Defense, the Secretary of Health and Human Services, the Secretary of the Treasury, the Secretary of Agriculture the Secretary of Energy,,1 and the Director of National Intelligence;

5(B) key officials of the Department, including the Under Secretary for Strategy, Policy, and Plans;

6(C) representatives from appropriate advisory committees established pursuant to section 451 of this title, including the Homeland Security Advisory Council and the Homeland Security Science and Technology Advisory Committee, or otherwise established, including the Aviation Security Advisory Committee established pursuant to section 44946 of title 49; and

7(D) other relevant governmental and nongovernmental entities, including State, local, and tribal government officials, members of Congress, private sector representatives, academics, and other policy experts.

8The Secretary shall ensure that each review conducted under this section is coordinated with the Future Years Homeland Security Program required under section 454 of this title.

9In each quadrennial homeland security review, the Secretary shall—

10(1) delineate and update, as appropriate, the national homeland security strategy, consistent with appropriate national and Department strategies, strategic plans, and Homeland Security Presidential Directives, including the National Strategy for Homeland Security, the National Response Plan, and the Department Security Strategic Plan;

11(2) outline and prioritize the full range of the critical homeland security mission areas of the Nation based on the risk assessment required pursuant to subsection (c)(2)(B);

12(3) describe, to the extent practicable, the interagency cooperation, preparedness of Federal response assets, infrastructure, resources required, and other elements of the homeland security program and policies of the Nation associated with the national homeland security strategy, required to execute successfully the full range of missions called for in the national homeland security strategy described in paragraph (1) and the homeland security mission areas outlined under paragraph (2);

13(4) identify, to the extent practicable, the resources required to execute the full range of missions called for in the national homeland security strategy described in paragraph (1) and the homeland security mission areas outlined under paragraph (2), including any resources identified from redundant, wasteful, or unnecessary capabilities or capacities that may be redirected to better support other existing capabilities or capacities, as the case may be; and

14(5) include an assessment of the organizational alignment of the Department with the national homeland security strategy referred to in paragraph (1) and the homeland security mission areas outlined under paragraph (2).

15Not later than 60 days after the date of the submission of the President's budget for the fiscal year after the fiscal year in which a quadrennial homeland security review is conducted, the Secretary shall submit to Congress a report regarding that quadrennial homeland security review.

16Each report submitted under paragraph (1) shall include—

17(A) the results of the quadrennial homeland security review;

18(B) a risk assessment of the assumed or defined national homeland security interests of the Nation that were examined for the purposes of that review or for purposes of the quadrennial EMP and GMD risk assessment under section 195f(d)(1)(E) of this title;

19(C) the national homeland security strategy, including a prioritized list of the critical homeland security missions of the Nation, as required under subsection (b)(2);

20(D) to the extent practicable, a description of the interagency cooperation, preparedness of Federal response assets, infrastructure, resources required, and other elements of the homeland security program and policies of the Nation associated with the national homeland security strategy, required to execute successfully the full range of missions called for in the applicable national homeland security strategy referred to in subsection (b)(1) and the homeland security mission areas outlined under subsection (b)(2);

21(E) an assessment of the organizational alignment of the Department with the applicable national homeland security strategy referred to in subsection (b)(1) and the homeland security mission areas outlined under subsection (b)(2), including the Department's organizational structure, management systems, budget and accounting systems, human resources systems, procurement systems, and physical and technical infrastructure;

22(F) to the extent practicable, a discussion of cooperation among Federal agencies in the effort to promote national homeland security;

23(G) to the extent practicable, a discussion of cooperation between the Federal Government and State, local, and tribal governments in preventing terrorist attacks and preparing for emergency response to threats and risks to national homeland security; and

24(H) any other matter the Secretary considers appropriate.

25The Secretary shall retain and, upon request, provide to Congress the following documentation regarding each quadrennial homeland security review:

26(A) Records regarding the consultation carried out pursuant to subsection (a)(3), including the following:

27(i) All written communications, including communications sent out by the Secretary and feedback submitted to the Secretary through technology, online communications tools, in-person discussions, and the interagency process.

28(ii) Information on how feedback received by the Secretary informed each such quadrennial homeland security review.

29(B) Information regarding the risk assessment required pursuant to subsection (c)(2)(B), including the following:

30(i) The risk model utilized to generate such risk assessment.

31(ii) Information, including data used in the risk model, utilized to generate such risk assessment.

32(iii) Sources of information, including other risk assessments, utilized to generate such risk assessment.

33(iv) Information on assumptions, weighing factors, and subjective judgments utilized to generate such risk assessment, together with information on the rationale or basis thereof.

34The Secretary shall, consistent with the protection of national security and other sensitive matters, make each report submitted under paragraph (1) publicly available on the Internet website of the Department.

35Not later than 90 days after the submission of each report required under subsection (c)(1), the Secretary shall provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate information on the degree to which the findings and recommendations developed in the quadrennial homeland security review that is the subject of such report were integrated into the acquisition strategy and expenditure plans for the Department.

36There are authorized to be appropriated such sums as may be necessary to carry out this section.

348.

Joint task forces

1In this section, the term "situational awareness" means knowledge and unified understanding of unlawful cross-border activity, including—

2(1) threats and trends concerning illicit trafficking and unlawful crossings;

3(2) the ability to forecast future shifts in such threats and trends;

4(3) the ability to evaluate such threats and trends at a level sufficient to create actionable plans; and

5(4) the operational capability to conduct continuous and integrated surveillance of the air, land, and maritime borders of the United States.

6The Secretary may establish and operate departmental Joint Task Forces to conduct joint operations using personnel and capabilities of the Department for the purposes specified in paragraph (2).

7Subject to subparagraph (B), the purposes referred to in paragraph (1) are or relate to the following:

8(i) Securing the land and maritime borders of the United States.

9(ii) Homeland security crises.

10(iii) Establishing regionally-based operations.

11The Secretary may not establish a Joint Task Force for any major disaster or emergency declared under the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.) or an incident for which the Federal Emergency Management Agency has primary responsibility for management of the response under subchapter V of this chapter, including section 314(a)(3)(A) of this title, unless the responsibilities of such a Joint Task Force—

12(I) do not include operational functions related to incident management, including coordination of operations; and

13(II) are consistent with the requirements of paragraphs (3) and (4)(A) of section 313(c) and section 319(c) of this title, and section 302 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5143).

14Nothing in this section may be construed to reduce the responsibilities or functions of the Federal Emergency Management Agency or the Administrator of the Agency under subchapter V of this chapter or any other provision of law, including the diversion of any asset, function, or mission from the Agency or the Administrator of the Agency pursuant to section 316 of this title.

15Each Joint Task Force established and operated pursuant to paragraph (1) shall be headed by a Director, appointed by the President, for a term of not more than two years. The Secretary shall submit to the President recommendations for such appointments after consulting with the heads of the components of the Department with membership on any such Joint Task Force. Any Director appointed by the President shall be—

16(i) a current senior official of the Department with not less than one year of significant leadership experience at the Department; or

17(ii) if no suitable candidate is available at the Department, an individual with—

18(I) not less than one year of significant leadership experience in a Federal agency since the establishment of the Department; and

19(II) a demonstrated ability in, knowledge of, and significant experience working on the issues to be addressed by any such Joint Task Force.

20The Secretary may extend the appointment of a Director of a Joint Task Force under subparagraph (A) for not more than two years if the Secretary determines that such an extension is in the best interest of the Department.

21For each Joint Task Force, the Secretary shall appoint a Deputy Director who shall be an official of a different component or office of the Department than the Director of such Joint Task Force.

22The Director of a Joint Task Force, subject to the oversight, direction, and guidance of the Secretary, shall—

23(A) when established for the purpose referred to in paragraph (2)(A)(i), maintain situational awareness within the areas of responsibility of the Joint Task Force, as determined by the Secretary;

24(B) provide operational plans and requirements for standard operating procedures and contingency operations within the areas of responsibility of the Joint Task Force, as determined by the Secretary;

25(C) plan and execute joint task force activities within the areas of responsibility of the Joint Task Force, as determined by the Secretary;

26(D) set and accomplish strategic objectives through integrated operational planning and execution;

27(E) exercise operational direction over personnel and equipment from components and offices of the Department allocated to the Joint Task Force to accomplish the objectives of the Joint Task Force;

28(F) when established for the purpose referred to in paragraph (2)(A)(i), establish operational and investigative priorities within the areas of responsibility of the Joint Task Force, as determined by the Secretary;

29(G) coordinate with foreign governments and other Federal, State, and local agencies, as appropriate, to carry out the mission of the Joint Task Force; and

30(H) carry out other duties and powers the Secretary determines appropriate.

31The Secretary may, upon request of the Director of a Joint Task Force, and giving appropriate consideration of risk to the other primary missions of the Department, allocate to such Joint Task Force on a temporary basis personnel and equipment of components and offices of the Department.

32A Joint Task Force may not require more resources than would have otherwise been required by the Department to carry out the duties assigned to such Joint Task Force if such Joint Task Force had not been established.

33In establishing a location of operations for a Joint Task Force, the Secretary shall, to the extent practicable, use existing facilities that integrate efforts of components of the Department and State, local, tribal, or territorial law enforcement or military entities.

34When reviewing requests for allocation of component personnel and equipment under subparagraph (A), the Secretary shall consider the impact of such allocation on the ability of the donating component or office to carry out the primary missions of the Department, and in the case of the Coast Guard, the missions specified in section 468 of this title.

35Personnel and equipment of the Coast Guard allocated under this paragraph may be used only to carry out operations and investigations related to the missions specified in section 468 of this title.

36The Secretary shall, at the time the budget of the President is submitted to Congress for a fiscal year under section 1105(a) of title 31, submit to the Committee on Homeland Security and the Committee on Transportation and Infrastructure of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Commerce, Science, and Transportation of the Senate a report on the total funding, personnel, and other resources that each component or office of the Department allocated under this paragraph to each Joint Task Force to carry out the mission of such Joint Task Force during the fiscal year immediately preceding each such report, and a description of the degree to which the resources drawn from each component or office impact the primary mission of such component or office.

37As directed by the Secretary—

38(A) each Director of a Joint Task Force shall be provided sufficient resources from relevant components and offices of the Department and the authority necessary to carry out the missions and responsibilities of such Joint Task Force required under this section;

39(B) the resources referred to in subparagraph (A) shall be under the operational authority, direction, and control of the Director of the Joint Task Force to which such resources are assigned; and

40(C) the personnel and equipment of each Joint Task Force shall remain under the administrative direction of the head of the component or office of the Department that provided such personnel or equipment.

41Each Joint Task Force shall have a staff, composed of personnel from relevant components and offices of the Department, to assist the Director of such Joint Task Force in carrying out the mission and responsibilities of such Joint Task Force.

42The Secretary shall include in the report submitted under paragraph (6)(F)—

43(i) the number of personnel of each component or office permanently assigned to each Joint Task Force; and

44(ii) the number of personnel of each component or office assigned on a temporary basis to each Joint Task Force.

45The Secretary shall—

46(A) using leading practices in performance management and lessons learned by other law enforcement task forces and joint operations, establish—

47(i) the mission, strategic goals, and objectives of each Joint Task Force;

48(ii) the criteria for terminating each Joint Task Force;

49(iii) outcome-based and other appropriate performance metrics for evaluating the effectiveness of each Joint Task Force with respect to the mission, strategic goals, and objectives established pursuant to clause (i), including—

50(I) targets for each Joint Task Force to achieve by not later than one and three years after such establishment; and

51(II) a description of the methodology used to establish such metrics; and

52(iv) a staffing plan for each Joint Task Force;

53(B) not later than 120 days after December 23, 2022, and 120 days after the establishment of a new Joint Task Force, as appropriate, submit to the Committee on Homeland Security and the Committee on Transportation and Infrastructure of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Commerce, Science, and Transportation of the Senate the mission, strategic goals, objectives, and metrics established under subparagraph (A); and

54(C) not later than December 23, 2024, and annually thereafter, submit to the committees specified in subparagraph (B) a report containing information regarding—

55(i) the progress in implementing the outcome-based and other appropriate performance metrics established pursuant to subparagraph (A)(iii);

56(ii) the staffing plan developed for each Joint Task Force pursuant to subparagraph (A)(iv); and

57(iii) any modification to the mission, strategic goals, and objectives of each Joint Task Force, and a description of, and rationale for, any such modifications.

58The Secretary shall—

59(i) establish a joint duty training program in the Department for the purposes of—

60(I) enhancing coordination within the Department; and

61(II) promoting workforce professional development; and

62(ii) tailor such joint duty training program to improve joint operations as part of the Joint Task Forces.

63The joint duty training program established under subparagraph (A) shall address, at a minimum, the following topics:

64(i) National security strategy.

65(ii) Strategic and contingency planning.

66(iii) Command and control of operations under joint command.

67(iv) International engagement.

68(v) The homeland security enterprise.

69(vi) Interagency collaboration.

70(vii) Leadership.

71(viii) Specific subject matters relevant to the Joint Task Force, including matters relating to the missions specified in section 468 of this title, to which the joint duty training program is assigned.

72Except as provided in clauses (iii) and (iv), an individual shall complete the joint duty training program before being appointed Director or Deputy Director of a Joint Task Force.

73Each official serving on the staff of a Joint Task Force shall complete the joint duty training program within the first year of assignment to such Joint Task Force.

74Clause (i) shall not apply to the first Director or Deputy Director appointed to a Joint Task Force on or after December 23, 2016.

75The Secretary may waive the application of clause (i) if the Secretary determines that such a waiver is in the interest of homeland security or necessary to carry out the mission for which a Joint Task Force was established.

76Not later than seven days after establishing or terminating a Joint Task Force under this subsection, the Secretary shall submit to the majority leader of the Senate, the minority leader of the Senate, the Speaker of the House of Representatives, the majority leader of the House of Representatives, the minority leader of the House of Representatives, and the Committee on Homeland Security and the Committee on Transportation and Infrastructure of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Commerce, Science, and Transportation of the Senate a notification regarding such establishment or termination, as the case may be. The contents of any such notification shall include the following:

77(i) The criteria and conditions required to establish or terminate the Joint Task Force at issue.

78(ii) The primary mission, strategic goals, objectives, and plan of operations of such Joint Task Force.

79(iii) If such notification is a notification of termination, information on the effectiveness of such Joint Task Force as measured by the outcome-based performance metrics and other appropriate performance metrics established pursuant to paragraph (9)(A)(iii).

80(iv) The funding and resources required to establish or terminate such Joint Task Force.

81(v) The number of personnel of each component or office permanently assigned to such Joint Task Force.

82(vi) The number of personnel of each component and office assigned on a temporary basis to such Joint Task Force.

83(vii) If such notification is a notification of establishment, the anticipated costs of establishing and operating such Joint Task Force.

84(viii) If such notification is a notification of termination, funding allocated in the immediately preceding fiscal year to such Joint Task Force for—

85(I) operations, notwithstanding such termination; and

86(II) activities associated with such termination.

87(ix) The anticipated establishment or actual termination date of such Joint Task Force, as the case may be.

88The Secretary may waive the requirement under subparagraph (A) in the event of an emergency circumstance that imminently threatens the protection of human life or property.

89Not later than one year after December 23, 2022, the Comptroller General of the United States shall submit to the Committee on Homeland Security and the Committee on Transportation and Infrastructure of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Commerce, Science, and Transportation of the Senate an assessment of the effectiveness of the Secretary's utilization of the authority provided under this section for the purposes specified in subsection (b)(2) as among the range of options available to the Secretary to conduct joint operations among departmental components and offices and a review of the Joint Task Forces established under this subsection.

90The review required under subparagraph (A) shall include—

91(i) an assessment of methodology utilized to determine whether to establish or terminate each Joint Task Force; and

92(ii) an assessment of the effectiveness of oversight over each Joint Task Force, with specificity regarding the Secretary's utilization of outcome-based or other appropriate performance metrics (established pursuant to paragraph (9)(A)(iii)) to evaluate the effectiveness of each Joint Task Force in measuring progress with respect to the mission, strategic goals, and objectives (established pursuant to paragraph (9)(A)(i)) of such Joint Task Force.

93This section expires on September 30, 2026.

94After establishing the joint duty training program under subsection (b)(10), the Secretary shall establish a joint duty assignment program within the Department for the purposes of enhancing coordination in the Department and promoting workforce professional development.

349.

Office of Strategy, Policy, and Plans

1There is established in the Department an Office of Strategy, Policy, and Plans.

2The Office of Strategy, Policy, and Plans shall be headed by an Under Secretary for Strategy, Policy, and Plans, who shall serve as the principal policy advisor to the Secretary. The Under Secretary for Strategy, Policy, and Plans shall be appointed by the President, by and with the advice and consent of the Senate.

3The Under Secretary for Strategy, Policy, and Plans shall—

4(1) lead, conduct, and coordinate Department-wide policy development and implementation and strategic planning;

5(2) develop and coordinate policies to promote and ensure quality, consistency, and integration for the programs, components, offices, and activities across the Department;

6(3) develop and coordinate strategic plans and long-term goals of the Department with risk-based analysis and planning to improve operational mission effectiveness, including consultation with the Secretary regarding the quadrennial homeland security review under section 347 of this title;

7(4) manage Department leadership councils and provide analytics and support to such councils;

8(5) manage international coordination and engagement for the Department;

9(6) review and incorporate, as appropriate, external stakeholder feedback into Department policy; and

10(7) carry out such other responsibilities as the Secretary determines appropriate.

11The Secretary may—

12(A) establish within the Office of Strategy, Policy, and Plans a position of Deputy Under Secretary to support the Under Secretary for Strategy, Policy, and Plans in carrying out the Under Secretary's responsibilities; and

13(B) appoint a career employee to such position.

14A Deputy Under Secretary position (or any substantially similar position) within the Office of Strategy, Policy, and Plans may not be established except for the position provided for by paragraph (1), unless the Secretary receives prior authorization from Congress.

15For purposes of paragraph (1)—

16(A) the term "career employee" means any employee (as such term is defined in section 2105 of title 5), but does not include a political appointee; and

17(B) the term "political appointee" means any employee who occupies a position which has been excepted from the competitive service by reason of its confidential, policy-determining, policy-making, or policy-advocating character.

18To ensure consistency with the policy priorities of the Department, the head of each component of the Department shall coordinate with the Office of Strategy, Policy, and Plans in establishing or modifying policies or strategic planning guidance with respect to each such component.

19The Under Secretary for Strategy, Policy, and Plans shall—

20(A) establish standards of reliability and validity for statistical data collected and analyzed by the Department;

21(B) be provided by the heads of all components of the Department with statistical data maintained by the Department regarding the operations of the Department;

22(C) conduct or oversee analysis and reporting of such data by the Department as required by law or as directed by the Secretary; and

23(D) ensure the accuracy of metrics and statistical data provided to Congress.

24There shall be transferred to the Under Secretary for Strategy, Policy, and Plans the maintenance of all immigration statistical information of U.S. Customs and Border Protection, U.S. Immigration and Customs Enforcement, and United States Citizenship and Immigration Services, which shall include information and statistics of the type contained in the publication entitled "Yearbook of Immigration Statistics" prepared by the Office of Immigration Statistics, including region-by-region statistics on the aggregate number of applications and petitions filed by an alien (or filed on behalf of an alien) and denied, and the reasons for such denials, disaggregated by category of denial and application or petition type.

25There is established within the Office of Strategy, Policy, and Plans an Assistant Secretary, who shall assist the Secretary in carrying out the duties under paragraph (2) and the responsibilities under paragraph (3). Notwithstanding section 113(a)(1) of this title, the Assistant Secretary established under this paragraph shall be appointed by the President without the advice and consent of the Senate.

26At the direction of the Secretary, the Assistant Secretary established under paragraph (1) shall be responsible for policy formulation regarding matters relating to economic security and trade, as such matters relate to the mission and the operations of the Department.

27In addition to the duties specified in paragraph (2), the Assistant Secretary established under paragraph (1), at the direction of the Secretary, may—

28(A) oversee—

29(i) coordination of supply chain policy; and

30(ii) assessments and reports to Congress related to critical economic security domains;

31(B) coordinate with stakeholders in other Federal departments and agencies and nongovernmental entities with trade and economic security interests, authorities, and responsibilities; and

32(C) perform such additional duties as the Secretary or the Under Secretary of Strategy, Policy, and Plans may prescribe.

33In this subsection:

34The term "critical economic security domain" means any infrastructure, industry, technology, or intellectual property (or combination thereof) that is essential for the economic security of the United States.

35The term "economic security" has the meaning given such term in section 474(c)(2) of this title.

36Nothing in this section overrides or otherwise affects the requirements specified in section 468 of this title.

350.

Workforce health and medical support

1The Under Secretary for Management shall be responsible for workforce-focused health and medical activities of the Department. The Under Secretary for Management may further delegate responsibility for those activities, as appropriate.

2The Under Secretary for Management, in coordination with the Chief Medical Officer, shall—

3(1) provide oversight and coordinate the medical and health activities of the Department for the human and animal personnel of the Department;

4(2) establish medical, health, veterinary, and occupational health exposure policy, guidance, strategies, and initiatives for the human and animal personnel of the Department;

5(3) as deemed appropriate by the Under Secretary, provide medical liaisons to the components of the Department, on a reimbursable basis, to provide subject matter expertise on occupational medical and public health issues;

6(4) serve as the primary representative for the Department on agreements regarding the detail of Commissioned Corps officers of the Public Health Service of the Department of Health and Human Services to the Department, except that components of the Department shall retain authority for funding, determination of specific duties, and supervision of such detailed Commissioned Corps officers; and

7(5) perform such other duties relating to the responsibilities described in this subsection as the Secretary may require.

351.

Employee engagement

1Not later than 120 days after December 27, 2021, the Secretary shall establish an employee engagement steering committee, including representatives from operational components, headquarters, and field personnel, including supervisory and nonsupervisory personnel, and employee labor organizations that represent Department employees, and chaired by the Under Secretary for Management, to carry out the following activities:

2(1) Identify factors that have a negative impact on employee engagement, morale, and communications within the Department, such as perceptions about limitations on career progression, mobility, or development opportunities, collected through employee feedback platforms, including through annual employee surveys, questionnaires, and other communications, as appropriate.

3(2) Identify, develop, and distribute initiatives and best practices to improve employee engagement, morale, and communications within the Department, including through annual employee surveys, questionnaires, and other communications, as appropriate.

4(3) Monitor efforts of each component to address employee engagement, morale, and communications based on employee feedback provided through annual employee surveys, questionnaires, and other communications, as appropriate.

5(4) Advise the Secretary on efforts to improve employee engagement, morale, and communications within specific components and across the Department.

6(5) Conduct regular meetings and report, not less than once per quarter, to the Under Secretary for Management, the head of each component, and the Secretary on Departmentwide efforts to improve employee engagement, morale, and communications.

7The Secretary, acting through the Chief Human Capital Officer, shall—

8(1) not later than 120 days after the date of the establishment of the employee engagement steering committee under subsection (a), issue a Departmentwide employee engagement action plan, reflecting input from the steering committee and employee feedback provided through annual employee surveys, questionnaires, and other communications in accordance with paragraph (1) of such subsection, to execute strategies to improve employee engagement, morale, and communications within the Department; and

9(2) require the head of each component to—

10(A) develop and implement a component-specific employee engagement plan to advance the action plan required under paragraph (1) that includes performance measures and objectives, is informed by employee feedback provided through annual employee surveys, questionnaires, and other communications, as appropriate, and sets forth how employees and, where applicable, their labor representatives are to be integrated in developing programs and initiatives;

11(B) monitor progress on implementation of such action plan; and

12(C) provide to the Chief Human Capital Officer and the steering committee quarterly reports on actions planned and progress made under this paragraph.

13This section shall terminate on the date that is five years after December 27, 2021.

352.

Annual employee award program

1The Secretary may establish an annual employee award program to recognize Department employees or groups of employees for significant contributions to the achievement of the Department's goals and missions. If such a program is established, the Secretary shall—

2(1) establish within such program categories of awards, each with specific criteria, that emphasize honoring employees who are at the nonsupervisory level;

3(2) publicize within the Department how any employee or group of employees may be nominated for an award;

4(3) establish an internal review board comprised of representatives from Department components, headquarters, and field personnel to submit to the Secretary award recommendations regarding specific employees or groups of employees;

5(4) select recipients from the pool of nominees submitted by the internal review board under paragraph (3) and convene a ceremony at which employees or groups of employees receive such awards from the Secretary; and

6(5) publicize such program within the Department.

7The internal review board described in subsection (a)(3) shall, when carrying out its function under such subsection, consult with representatives from operational components and headquarters, including supervisory and nonsupervisory personnel, and employee labor organizations that represent Department employees.

8Nothing in this section may be construed to authorize additional funds to carry out the requirements of this section or to require the Secretary to provide monetary bonuses to recipients of an award under this section.

353.

Acquisition professional career program

1There is established in the Department an acquisition professional career program to develop a cadre of acquisition professionals within the Department.

2The Under Secretary for Management shall administer the acquisition professional career program established pursuant to subsection (a).

3The Under Secretary for Management shall carry out the following with respect to the acquisition professional career program.1

4(1) Designate the occupational series, grades, and number of acquisition positions throughout the Department to be included in the program and manage centrally such positions.

5(2) Establish and publish on the Department's website eligibility criteria for candidates to participate in the program.

6(3) Carry out recruitment efforts to attract candidates—

7(A) from institutions of higher education, including such institutions with established acquisition specialties and courses of study, historically Black colleges and universities, and Hispanic-serving institutions;

8(B) with diverse work experience outside of the Federal Government; or

9(C) with military service.

10(4) Hire eligible candidates for designated positions under the program.

11(5) Develop a structured program comprised of acquisition training, on-the-job experience, Department-wide rotations, mentorship, shadowing, and other career development opportunities for program participants.

12(6) Provide, beyond required training established for program participants, additional specialized acquisition training, including small business contracting and innovative acquisition techniques training.

13Not later than one year after December 27, 2021, and annually thereafter through 2027, the Secretary shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the acquisition professional career program. Each such report shall include the following information:

14(1) The number of candidates approved for the program.

15(2) The number of candidates who commenced participation in the program, including generalized information on such candidates' backgrounds with respect to education and prior work experience, but not including personally identifiable information.

16(3) A breakdown of the number of participants hired under the program by type of acquisition position.

17(4) A list of Department components and offices that participated in the program and information regarding length of time of each program participant in each rotation at such components or offices.

18(5) Program attrition rates and post-program graduation retention data, including information on how such data compare to the prior year's data, as available.

19(6) The Department's recruiting efforts for the program.

20(7) The Department's efforts to promote retention of program participants.

21In this section:

22The term "Hispanic-serving institution" has the meaning given such term in section 1101a of title 20.

23The term "historically Black colleges and universities" has the meaning given the term "part B institution" in section 1061(2) of title 20.

24The term "institution of higher education" has the meaning given such term in section 1001 of title 20.

361.

Office for State and Local Government Coordination

1There is established within the Office of the Secretary the Office for State and Local Government Coordination, to oversee and coordinate departmental programs for and relationships with State and local governments.

2The Office established under subsection (a) shall—

3(1) coordinate the activities of the Department relating to State and local government;

4(2) assess, and advocate for, the resources needed by State and local government to implement the national strategy for combating terrorism;

5(3) provide State and local government with regular information, research, and technical support to assist local efforts at securing the homeland; and

6(4) develop a process for receiving meaningful input from State and local government to assist the development of the national strategy for combating terrorism and other homeland security activities.

371.

Repealed. Pub. L. 108–7, div. L, §104(c)(1), Feb. 20, 2003, 117 Stat. 531

381.

Functions transferred

1In accordance with subchapter XII, there shall be transferred to the Secretary the functions, personnel, assets, and obligations of the United States Secret Service, which shall be maintained as a distinct entity within the Department, including the functions of the Secretary of the Treasury relating thereto.

382.

Use of proceeds derived from criminal investigations

1During fiscal year 2014 and thereafter, with respect to any undercover investigative operation of the United States Secret Service (hereafter referred to in this section as the "Secret Service") that is necessary for the detection and prosecution of crimes against the United States—

2(1) sums appropriated for the Secret Service, including unobligated balances available from prior fiscal years, may be used for purchasing property, buildings, and other facilities, and for leasing space, within the United States, the District of Columbia, and the territories and possessions of the United States, without regard to sections 1341 and 3324 of title 31, section 8141 of title 40, sections 6301(a), (b)(1) to (3) and 6306(a) of title 41, and section 3901 and chapter 45 of title 41;

3(2) sums appropriated for the Secret Service, including unobligated balances available from prior fiscal years, may be used to establish or to acquire proprietary corporations or business entities as part of such undercover operation, and to operate such corporations or business entities on a commercial basis, without regard to sections 9102 and 9103 of title 31;

4(3) sums appropriated for the Secret Service, including unobligated balances available from prior fiscal years and the proceeds from such undercover operation, may be deposited in banks or other financial institutions, without regard to section 648 of title 18 and section 3302 of title 31; and

5(4) proceeds from such undercover operation may be used to offset necessary and reasonable expenses incurred in such operation, without regard to section 3302 of title 31.

6The authority set forth in subsection (a) may be exercised only upon the written certification of the Director of the Secret Service or designee that any action authorized by any paragraph of such subsection is necessary for the conduct of an undercover investigative operation. Such certification shall continue in effect for the duration of such operation, without regard to fiscal years.

7As soon as practicable after the proceeds from an undercover investigative operation with respect to which an action is authorized and carried out under paragraphs (3) and (4) of subsection (a) are no longer necessary for the conduct of such operation, such proceeds or the balance of such proceeds remaining at the time shall be deposited in the Treasury of the United States as miscellaneous receipts.

8If a corporation or business entity established or acquired as part of an undercover investigative operation under paragraph (2) of subsection (a) with a net value of over $50,000 is to be liquidated, sold, or otherwise disposed of, the Secret Service, as much in advance as the Director or designee determines is practicable, shall report the circumstance to the Secretary of Homeland Security. The proceeds of the liquidation, sale, or other disposition, after obligations are met, shall be deposited in the Treasury of the United States as miscellaneous receipts.

9(1) The Secret Service shall conduct detailed financial audits of closed undercover investigative operations for which a written certification was made pursuant to subsection (b) on a quarterly basis and shall report the results of the audits in writing to the Secretary of Homeland Security.

10(2) The Secretary of Homeland Security shall annually submit to the Committees on Appropriations of the Senate and House of Representatives, at the time that the President's budget is submitted under section 1105(a) of title 31, a summary of such audits.

383.

National Computer Forensics Institute

1There is authorized for fiscal years 2023 through 2028 within the United States Secret Service a National Computer Forensics Institute (in this section referred to as the "Institute"). The Institute's mission shall be to educate, train, and equip State, local, territorial, and Tribal law enforcement officers, prosecutors, and judges, as well as participants in the United States Secret Service's network of cyber fraud task forces who are Federal employees, members of the uniformed services, or State, local, Tribal, or territorial employees, regarding the investigation and prevention of cybersecurity incidents, electronic crimes, and related cybersecurity threats, including through the dissemination of homeland security information, in accordance with relevant Federal law regarding privacy, civil rights, and civil liberties protections.

2In furtherance of subsection (a), all education and training of the Institute shall be conducted in accordance with relevant Federal law regarding privacy, civil rights, and civil liberties protections. Education and training provided pursuant to subsection (a) shall relate to the following:

3(1) Investigating and preventing cybersecurity incidents, electronic crimes, and related cybersecurity threats, including relating to instances involving illicit use of digital assets and emerging trends in cybersecurity and electronic crime.

4(2) Conducting forensic examinations of computers, mobile devices, and other information systems.

5(3) Prosecutorial and judicial considerations related to cybersecurity incidents, electronic crimes, related cybersecurity threats, and forensic examinations of computers, mobile devices, and other information systems.

6(4) Methods to obtain, process, store, and admit digital evidence in court.

7In carrying out the functions specified in subsection (b), the Institute shall ensure, to the extent practicable, that timely, actionable, and relevant expertise and information related to cybersecurity incidents, electronic crimes, and related cybersecurity threats is shared with recipients of education and training provided pursuant to subsection (a). When selecting participants for such training, the Institute shall prioritize, to the extent reasonable and practicable, providing education and training to individuals from geographically-diverse jurisdictions throughout the United States, and the Institute shall prioritize, to the extent reasonable and practicable, State, local, tribal, and territorial law enforcement officers, prosecutors, judges, and other employees.

8The Institute may provide recipients of education and training provided pursuant to subsection (a) with computer equipment, hardware, software, manuals, and tools for investigating and preventing cybersecurity incidents, electronic crimes, and related cybersecurity threats, and for forensic examinations of computers, mobile devices, and other information systems.

9The Institute shall facilitate the expansion of the network of Cyber Fraud Task Forces of the United States Secret Service through the addition of recipients of education and training provided pursuant to subsection (a) educated and trained by the Institute.

10All authorized activities and functions carried out by the Institute at any location as of the day before November 2, 2017, are authorized to continue to be carried out at any such location on and after such date.

11The Director of the United States Secret Service may pay for all or a part of the education, training, or equipment provided by the Institute, including relating to the travel, transportation, and subsistence expenses of recipients of education and training provided pursuant to subsection (a).

12The Secretary shall include in the annual report required under section 1116 of title 31 information regarding the activities of the Institute, including, where possible, the following:

13(A) An identification of jurisdictions with recipients of the education and training provided pursuant to subsection (a) during such year.

14(B) Information relating to the costs associated with that education and training.

15(C) Any information regarding projected future demand for the education and training provided pursuant to subsection (a).

16(D) Impacts of the activities of the Institute on the capability of jurisdictions to investigate and prevent cybersecurity incidents, electronic crimes, and related cybersecurity threats.

17(E) A description of the nomination process for potential recipients of the information and training provided pursuant to subsection (a).

18(F) Any other issues determined relevant by the Secretary.

19Any information required under paragraph (1) that is submitted as part of the annual budget submitted by the President to Congress under section 1105 of title 31 is not required to be included in the report required under paragraph (1).

20In this section:

21The term "cybersecurity threat" has the meaning given such term in section 1501 of this title.

22The term "incident" has the meaning given such term in section 659(a) 1 of this title.

23The term "information system" has the meaning given such term in section 1501(9) of this title.

391.

Research and development projects

1Until September 30, 2024, and subject to subsection (d),1 the Secretary may carry out a pilot program under which the Secretary may exercise the following authorities:

2When the Secretary carries out basic, applied, and advanced research and development projects, including the expenditure of funds for such projects, the Secretary may exercise the same authority (subject to the same limitations and conditions) with respect to such research and projects as the Secretary of Defense may exercise under section 4021 of title 10 (except for subsections (b) and (f)), after making a determination that the use of a contract, grant, or cooperative agreement for such project is not feasible or appropriate. The annual report required under subsection (b) 1 of this section, as applied to the Secretary by this paragraph, shall be submitted to the President of the Senate and the Speaker of the House of Representatives.

3The Secretary—

4(A) may, under the authority of paragraph (1), carry out prototype projects under section 4022 of title 10; and

5(B) in applying the authorities of such section 4022, the Secretary shall perform the functions of the Secretary of Defense as prescribed in such section.

6The Secretary may—

7(1) procure the temporary or intermittent services of experts or consultants (or organizations thereof) in accordance with section 3109(b) of title 5; and

8(2) whenever necessary due to an urgent homeland security need, procure temporary (not to exceed 1 year) or intermittent personal services, including the services of experts or consultants (or organizations thereof), without regard to the pay limitations of such section 3109.

9The authority of the Secretary under this section shall terminate September 30, 2024, unless before that date the Secretary—

10(A) issues policy guidance detailing the appropriate use of that authority; and

11(B) provides training to each employee that is authorized to exercise that authority.

12The Secretary shall provide an annual report to the Committees on Appropriations of the Senate and the House of Representatives, the Committee on Homeland Security and Governmental Affairs of the Senate, and the Committee on Homeland Security of the House of Representatives detailing the projects for which the authority granted by subsection (a) was used, the rationale for its use, the funds spent using that authority, the outcome of each project for which that authority was used, and the results of any audits of such projects.

13In this section, the term "nontraditional Government contractor" has the same meaning as the term "nontraditional defense contractor" as defined in section 4022(e) of title 10.

392.

Personal services

1The Secretary—

2(1) may procure the temporary or intermittent services of experts or consultants (or organizations thereof) in accordance with section 3109 of title 5; and

3(2) may, whenever necessary due to an urgent homeland security need, procure temporary (not to exceed 1 year) or intermittent personal services, including the services of experts or consultants (or organizations thereof), without regard to the pay limitations of such section 3109.

393.

Special streamlined acquisition authority

1The Secretary may use the authorities set forth in this section with respect to any procurement made during the period beginning on the effective date of this chapter and ending September 30, 2007, if the Secretary determines in writing that the mission of the Department (as described in section 111 of this title) would be seriously impaired without the use of such authorities.

2The authority to make the determination described in paragraph (1) may not be delegated by the Secretary to an officer of the Department who is not appointed by the President with the advice and consent of the Senate.

3Not later than the date that is 7 days after the date of any determination under paragraph (1), the Secretary shall submit to the Committee on Government Reform of the House of Representatives and the Committee on Governmental Affairs of the Senate—

4(A) notification of such determination; and

5(B) the justification for such determination.

6The Secretary may designate certain employees of the Department to make procurements described in subsection (a) for which in the administration of section 1902 of title 41 the amount specified in subsections (a), (d), and (e) of such section 1902 shall be deemed to be $7,500.

7The number of employees designated under paragraph (1) shall be—

8(A) fewer than the number of employees of the Department who are authorized to make purchases without obtaining competitive quotations, pursuant to section 1902(d) of title 41;

9(B) sufficient to ensure the geographic dispersal of the availability of the use of the procurement authority under such paragraph at locations reasonably considered to be potential terrorist targets; and

10(C) sufficiently limited to allow for the careful monitoring of employees designated under such paragraph.

11Procurements made under the authority of this subsection shall be subject to review by a designated supervisor on not less than a monthly basis. The supervisor responsible for the review shall be responsible for no more than 7 employees making procurements under this subsection.

12With respect to a procurement described in subsection (a), the Secretary may deem the simplified acquisition threshold referred to in section 134 of title 41 to be—

13(A) in the case of a contract to be awarded and performed, or purchase to be made, within the United States, $200,000; and

14(B) in the case of a contract to be awarded and performed, or purchase to be made, outside of the United States, $300,000.

15With respect to a procurement described in subsection (a), the Secretary may deem any item or service to be a commercial item for the purpose of Federal procurement laws.

16The $5,000,000 limitation provided in section 1901(a)(2) of title 41 and section 3305(a)(2) of title 41 shall be deemed to be $7,500,000 for purposes of property or services under the authority of this subsection.

17Authority under a provision of law referred to in paragraph (2) that expires under section 4202(e) of the Clinger-Cohen Act of 1996 (divisions D and E of Public Law 104–106; 10 U.S.C. 2304 note) shall, notwithstanding such section, continue to apply for a procurement described in subsection (a).

18Not later than 180 days after the end of fiscal year 2005, the Comptroller General shall submit to the Committee on Governmental Affairs of the Senate and the Committee on Government Reform of the House of Representatives a report on the use of the authorities provided in this section. The report shall contain the following:

19(1) An assessment of the extent to which property and services acquired using authorities provided under this section contributed to the capacity of the Federal workforce to facilitate the mission of the Department as described in section 111 of this title.

20(2) An assessment of the extent to which prices for property and services acquired using authorities provided under this section reflected the best value.

21(3) The number of employees designated by each executive agency under subsection (b)(1).

22(4) An assessment of the extent to which the Department has implemented subsections (b)(2) and (b)(3) to monitor the use of procurement authority by employees designated under subsection (b)(1).

23(5) Any recommendations of the Comptroller General for improving the effectiveness of the implementation of the provisions of this section.

394.

Unsolicited proposals

1Within 1 year of November 25, 2002, the Federal Acquisition Regulation shall be revised to include regulations with regard to unsolicited proposals.

2The regulations prescribed under subsection (a) shall require that before initiating a comprehensive evaluation, an agency contact point shall consider, among other factors, that the proposal—

3(1) is not submitted in response to a previously published agency requirement; and

4(2) contains technical and cost information for evaluation and overall scientific, technical or socioeconomic merit, or cost-related or price-related factors.

395.

Prohibition on contracts with corporate expatriates

1The Secretary may not enter into any contract with a foreign incorporated entity which is treated as an inverted domestic corporation under subsection (b), or any subsidiary of such an entity.

2For purposes of this section, a foreign incorporated entity shall be treated as an inverted domestic corporation if, pursuant to a plan (or a series of related transactions)—

3(1) the entity completes before, on, or after November 25, 2002, the direct or indirect acquisition of substantially all of the properties held directly or indirectly by a domestic corporation or substantially all of the properties constituting a trade or business of a domestic partnership;

4(2) after the acquisition at least 80 percent of the stock (by vote or value) of the entity is held—

5(A) in the case of an acquisition with respect to a domestic corporation, by former shareholders of the domestic corporation by reason of holding stock in the domestic corporation; or

6(B) in the case of an acquisition with respect to a domestic partnership, by former partners of the domestic partnership by reason of holding a capital or profits interest in the domestic partnership; and

7(3) the expanded affiliated group which after the acquisition includes the entity does not have substantial business activities in the foreign country in which or under the law of which the entity is created or organized when compared to the total business activities of such expanded affiliated group.

8In applying subsection (b) for purposes of subsection (a), the following rules shall apply:

9There shall not be taken into account in determining ownership for purposes of subsection (b)(2)—

10(i) stock held by members of the expanded affiliated group which includes the foreign incorporated entity; or

11(ii) stock of such entity which is sold in a public offering related to the acquisition described in subsection (b)(1).

12If a foreign incorporated entity acquires directly or indirectly substantially all of the properties of a domestic corporation or partnership during the 4-year period beginning on the date which is 2 years before the ownership requirements of subsection (b)(2) are met, such actions shall be treated as pursuant to a plan.

13The transfer of properties or liabilities (including by contribution or distribution) shall be disregarded if such transfers are part of a plan a principal purpose of which is to avoid the purposes of this section.

14For purposes of applying subsection (b) to the acquisition of a domestic partnership, except as provided in regulations, all domestic partnerships which are under common control (within the meaning of section 482 of title 26) shall be treated as I 1 partnership.

15The Secretary shall prescribe such regulations as may be necessary to—

16(i) treat warrants, options, contracts to acquire stock, convertible debt instruments, and other similar interests as stock; and

17(ii) treat stock as not stock.

18The term "expanded affiliated group" means an affiliated group as defined in section 1504(a) of title 26 (without regard to section 1504(b) of such title), except that section 1504 of such title shall be applied by substituting "more than 50 percent" for "at least 80 percent" each place it appears.

19The term "foreign incorporated entity" means any entity which is, or but for subsection (b) would be, treated as a foreign corporation for purposes of title 26.

20The terms "person", "domestic", and "foreign" have the meanings given such terms by paragraphs (1), (4), and (5) of section 7701(a) of title 26, respectively.

21The Secretary shall waive subsection (a) with respect to any specific contract if the Secretary determines that the waiver is required in the interest of national security.

396.

Lead system integrator; financial interests

1With respect to contracts entered into after July 1, 2007, and except as provided in subsection (b), no entity performing lead system integrator functions in the acquisition of a major system by the Department of Homeland Security may have any direct financial interest in the development or construction of any individual system or element of any system of systems.

2An entity described in subsection (a) may have a direct financial interest in the development or construction of an individual system or element of a system of systems if—

3(1) the Secretary of Homeland Security certifies to the Committees on Appropriations of the Senate and the House of Representatives, the Committee on Homeland Security of the House of Representatives, the Committee on Transportation and Infrastructure of the House of Representatives, the Committee on Homeland Security and Governmental Affairs of the Senate, and the Committee on Commerce, Science and Transportation of the Senate that—

4(A) the entity was selected by the Department of Homeland Security as a contractor to develop or construct the system or element concerned through the use of competitive procedures; and

5(B) the Department took appropriate steps to prevent any organizational conflict of interest in the selection process; or

6(2) the entity was selected by a subcontractor to serve as a lower-tier subcontractor, through a process over which the entity exercised no control.

7Nothing in this section shall be construed to preclude an entity described in subsection (a) from performing work necessary to integrate two or more individual systems or elements of a system of systems with each other.

8Not later than July 1, 2007, the Secretary of Homeland Security shall update the acquisition regulations of the Department of Homeland Security in order to specify fully in such regulations the matters with respect to lead system integrators set forth in this section. Included in such regulations shall be: (1) a precise and comprehensive definition of the term "lead system integrator", modeled after that used by the Department of Defense; and (2) a specification of various types of contracts and fee structures that are appropriate for use by lead system integrators in the production, fielding, and sustainment of complex systems.

397.

Requirements to buy certain items related to national security interests

1In this section:

2The term "covered item" means any of the following:

3(A) Footwear provided as part of a uniform.

4(B) Uniforms.

5(C) Holsters and tactical pouches.

6(D) Patches, insignia, and embellishments.

7(E) Chemical, biological, radiological, and nuclear protective gear.

8(F) Body armor components intended to provide ballistic protection for an individual, consisting of 1 or more of the following:

9(i) Soft ballistic panels.

10(ii) Hard ballistic plates.

11(iii) Concealed armor carriers worn under a uniform.

12(iv) External armor carriers worn over a uniform.

13(G) Any other item of clothing or protective equipment as determined appropriate by the Secretary.

14The term "frontline operational component" means any of the following entities of the Department:

15(A) U.S. Customs and Border Protection.

16(B) U.S. Immigration and Customs Enforcement.

17(C) The United States Secret Service.

18(D) The Transportation Security Administration.

19(E) The Federal Protective Service.

20(F) The Federal Emergency Management Agency.

21(G) The Federal Law Enforcement Training Centers.

22(H) The Cybersecurity and Infrastructure Security Agency.

23The Secretary shall ensure that any procurement of a covered item for a frontline operational component meets the following criteria:

24(A)(i) To the maximum extent possible, not less than one-third of funds obligated in a specific fiscal year for the procurement of such covered items shall be covered items that are manufactured or supplied in the United States by entities that qualify as small business concerns, as such term is described under section 632 of title 15.

25(ii) Covered items may only be supplied pursuant to subparagraph (A) to the extent that United States entities that qualify as small business concerns—

26(I) are unable to manufacture covered items in the United States; and

27(II) meet the criteria identified in subparagraph (B).

28(B) Each contractor with respect to the procurement of such a covered item, including the end-item manufacturer of such a covered item—

29(i) is an entity registered with the System for Award Management (or successor system) administered by the General Services Administration; and

30(ii) is in compliance with ISO 9001:2015 of the International Organization for Standardization (or successor standard) or a standard determined appropriate by the Secretary to ensure the quality of products and adherence to applicable statutory and regulatory requirements.

31(C) Each supplier of such a covered item with an insignia (such as any patch, badge, or emblem) and each supplier of such an insignia, if such covered item with such insignia or such insignia, as the case may be, is not produced, applied, or assembled in the United States, shall—

32(i) store such covered item with such insignia or such insignia in a locked area;

33(ii) report any pilferage or theft of such covered item with such insignia or such insignia occurring at any stage before delivery of such covered item with such insignia or such insignia; and

34(iii) destroy any such defective or unusable covered item with insignia or insignia in a manner established by the Secretary, and maintain records, for three years after the creation of such records, of such destruction that include the date of such destruction, a description of the covered item with insignia or insignia destroyed, the quantity of the covered item with insignia or insignia destroyed, and the method of destruction.

35In the case of a national emergency declared by the President under the National Emergencies Act (50 U.S.C. 1601 et seq.) or a major disaster declared by the President under section 5170 of title 42, the Secretary may waive a requirement in subparagraph (A), (B) or (C) of paragraph (1) if the Secretary determines there is an insufficient supply of a covered item that meets such requirement.

36Not later than 60 days after the date on which the Secretary determines a waiver under subparagraph (A) is necessary, the Secretary shall provide to the Committee on Homeland Security and Governmental Affairs and the Committee on Appropriations of the Senate and the Committee on Homeland Security, the Committee on Oversight and Reform, and the Committee on Appropriations of the House of Representatives notice of such determination, which shall include the following:

37(i) Identification of the national emergency or major disaster declared by the President.

38(ii) Identification of the covered item for which the Secretary intends to issue the waiver.

39(iii) A description of the demand for the covered item and corresponding lack of supply from contractors able to meet the criteria described in subparagraph (B) or (C) of paragraph (1).

40The Secretary shall ensure that covered items are purchased at a fair and reasonable price, consistent with the procedures and guidelines specified in the Federal Acquisition Regulation.

41Not later than one year after December 23, 2022, and annually thereafter, the Secretary shall provide to the Committee on Homeland Security, the Committee on Oversight and Reform, the Committee on Small Business, and the Committee on Appropriations of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs, the Committee on Small Business and Entrepreneurship, and the Committee on Appropriations of the Senate a briefing on instances in which vendors have failed to meet deadlines for delivery of covered items and corrective actions taken by the Department in response to such instances.

42This section applies with respect to a contract entered into by the Department or any frontline operational component on or after the date that is 180 days after December 23, 2022.

411.

Establishment of human resources management system

1It is the sense of Congress that—

2(A) it is extremely important that employees of the Department be allowed to participate in a meaningful way in the creation of any human resources management system affecting them;

3(B) such employees have the most direct knowledge of the demands of their jobs and have a direct interest in ensuring that their human resources management system is conducive to achieving optimal operational efficiencies;

4(C) the 21st century human resources management system envisioned for the Department should be one that benefits from the input of its employees; and

5(D) this collaborative effort will help secure our homeland.

6Except as otherwise provided in this chapter, the transfer under this chapter of full-time personnel (except special Government employees) and part-time personnel holding permanent positions shall not cause any such employee to be separated or reduced in grade or compensation for 1 year after the date of transfer to the Department.

7Any person who, on the day preceding such person's date of transfer pursuant to this chapter, held a position compensated in accordance with the Executive Schedule prescribed in chapter 53 of title 5 and who, without a break in service, is appointed in the Department to a position having duties comparable to the duties performed immediately preceding such appointment shall continue to be compensated in such new position at not less than the rate provided for such position, for the duration of the service of such person in such new position.

8Any exercise of authority under chapter 97 of title 5, including under any system established under such chapter, shall be in conformance with the requirements of this subsection.

412.

Labor-management relations

1No agency or subdivision of an agency which is transferred to the Department pursuant to this chapter shall be excluded from the coverage of chapter 71 of title 5 as a result of any order issued under section 7103(b)(1) of such title 5 after June 18, 2002, unless—

2(A) the mission and responsibilities of the agency (or subdivision) materially change; and

3(B) a majority of the employees within such agency (or subdivision) have as their primary duty intelligence, counterintelligence, or investigative work directly related to terrorism investigation.

4Nothing in paragraph (1) shall affect the effectiveness of any order to the extent that such order excludes any portion of an agency or subdivision of an agency as to which—

5(A) recognition as an appropriate unit has never been conferred for purposes of chapter 71 of such title 5; or

6(B) any such recognition has been revoked or otherwise terminated as a result of a determination under subsection (b)(1).

7Each unit which is recognized as an appropriate unit for purposes of chapter 71 of title 5 as of the day before the effective date of this chapter (and any subdivision of any such unit) shall, if such unit (or subdivision) is transferred to the Department pursuant to this chapter, continue to be so recognized for such purposes, unless—

8(A) the mission and responsibilities of such unit (or subdivision) materially change; and

9(B) a majority of the employees within such unit (or subdivision) have as their primary duty intelligence, counterintelligence, or investigative work directly related to terrorism investigation.

10No position or employee within a unit (or subdivision of a unit) as to which continued recognition is given in accordance with paragraph (1) shall be excluded from such unit (or subdivision), for purposes of chapter 71 of such title 5, unless the primary job duty of such position or employee—

11(A) materially changes; and

12(B) consists of intelligence, counterintelligence, or investigative work directly related to terrorism investigation.

13In the case of any positions within a unit (or subdivision) which are first established on or after the effective date of this chapter and any employees first appointed on or after such date, the preceding sentence shall be applied disregarding subparagraph (A).

14If the President determines that the application of subsections (a), (b), and (d) would have a substantial adverse impact on the ability of the Department to protect homeland security, the President may waive the application of such subsections 10 days after the President has submitted to Congress a written explanation of the reasons for such determination.

15No other provision of this chapter or of any amendment made by this chapter may be construed or applied in a manner so as to limit, supersede, or otherwise affect the provisions of this section, except to the extent that it does so by specific reference to this section.

16Nothing in section 9701(e) of title 5 shall be considered to apply with respect to any agency or subdivision of any agency, which is excluded from the coverage of chapter 71 of title 5 by virtue of an order issued in accordance with section 7103(b) of such title 5 and the preceding provisions of this section (as applicable), or to any employees of any such agency or subdivision or to any individual or entity representing any such employees or any representatives thereof.

413.

Use of counternarcotics enforcement activities in certain employee performance appraisals

1Each subdivision of the Department that is a National Drug Control Program Agency shall include as one of the criteria in its performance appraisal system, for each employee directly or indirectly involved in the enforcement of Federal, State, or local narcotics laws, the performance of that employee with respect to the enforcement of Federal, State, or local narcotics laws, relying to the greatest extent practicable on objective performance measures, including—

2(1) the contribution of that employee to seizures of narcotics and arrests of violators of Federal, State, or local narcotics laws; and

3(2) the degree to which that employee cooperated with or contributed to the efforts of other employees, either within the Department or other Federal, State, or local agencies, in counternarcotics enforcement.

4For purposes of this section—

5(1) the term "National Drug Control Program Agency" means—

6(A) a National Drug Control Program Agency 1, as defined in section 1701(7) 2 of title 21 (as last in effect); and

7(B) any subdivision of the Department that has a significant counternarcotics responsibility, as determined by—

8(i) the counternarcotics officer, appointed under section 458 of this title; or

9(ii) if applicable, the counternarcotics officer's successor in function (as determined by the Secretary); and

10(2) the term "performance appraisal system" means a system under which periodic appraisals of job performance of employees are made, whether under chapter 43 of title 5, or otherwise.

414.

Homeland Security Rotation Program

1Not later than 180 days after October 4, 2006, the Secretary shall establish the Homeland Security Rotation Program (in this section referred to as the "Rotation Program") for employees of the Department. The Rotation Program shall use applicable best practices, including those from the Chief Human Capital Officers Council.

2The Rotation Program established by the Secretary shall—

3(A) be established in accordance with the Human Capital Strategic Plan of the Department;

4(B) provide middle and senior level employees in the Department the opportunity to broaden their knowledge through exposure to other components of the Department;

5(C) expand the knowledge base of the Department by providing for rotational assignments of employees to other components;

6(D) build professional relationships and contacts among the employees in the Department;

7(E) invigorate the workforce with exciting and professionally rewarding opportunities;

8(F) incorporate Department human capital strategic plans and activities, and address critical human capital deficiencies, recruitment and retention efforts, and succession planning within the Federal workforce of the Department; and

9(G) complement and incorporate (but not replace) rotational programs within the Department in effect on October 4, 2006.

10The Chief Human Capital Officer shall administer the Rotation Program.

11The Chief Human Capital Officer shall—

12(i) provide oversight of the establishment and implementation of the Rotation Program;

13(ii) establish a framework that supports the goals of the Rotation Program and promotes cross-disciplinary rotational opportunities;

14(iii) establish eligibility for employees to participate in the Rotation Program and select participants from employees who apply;

15(iv) establish incentives for employees to participate in the Rotation Program, including promotions and employment preferences;

16(v) ensure that the Rotation Program provides professional education and training;

17(vi) ensure that the Rotation Program develops qualified employees and future leaders with broad-based experience throughout the Department;

18(vii) provide for greater interaction among employees in components of the Department; and

19(viii) coordinate with rotational programs within the Department in effect on October 4, 2006.

20All allowances, privileges, rights, seniority, and other benefits of employees participating in the Rotation Program shall be preserved.

21Not later than 180 days after the date of the establishment of the Rotation Program, the Secretary shall submit a report on the status of the Rotation Program, including a description of the Rotation Program, the number of employees participating, and how the Rotation Program is used in succession planning and leadership development to the appropriate committees of Congress.

415.

Homeland Security Education Program

1The Secretary, acting through the Administrator, shall establish a graduate-level Homeland Security Education Program in the National Capital Region to provide educational opportunities to senior Federal officials and selected State and local officials with homeland security and emergency management responsibilities. The Administrator shall appoint an individual to administer the activities under this section.

2To maximize efficiency and effectiveness in carrying out the Program, the Administrator shall use existing Department-reviewed Master's Degree curricula in homeland security, including curricula pending accreditation, together with associated learning materials, quality assessment tools, digital libraries, exercise systems and other educational facilities, including the National Domestic Preparedness Consortium, the National Fire Academy, and the Emergency Management Institute. The Administrator may develop additional educational programs, as appropriate.

3The student body of the Program shall include officials from Federal, State, local, and tribal governments, and from other sources designated by the Administrator.

4The Administrator shall establish policies governing student enrollment priorities and selection criteria that are consistent with the mission of the Program.

5The Administrator shall take reasonable steps to ensure that the student body represents racial, gender, and ethnic diversity.

6Before any employee selected for the Program may be assigned to participate in the program, the employee shall agree in writing—

7(A) to continue in the service of the agency sponsoring the employee during the 2-year period beginning on the date on which the employee completes the program, unless the employee is involuntarily separated from the service of that agency for reasons other than a reduction in force; and

8(B) to pay to the Government the amount of the additional expenses incurred by the Government in connection with the employee's education if the employee is voluntarily separated from the service to the agency before the end of the period described in subparagraph (A).

9An employee who leaves the service of the sponsoring agency to enter into the service of another agency in any branch of the Government shall not be required to make a payment under paragraph (1)(B), unless the head of the agency that sponsored the education of the employee notifies that employee before the date on which the employee enters the service of the other agency that payment is required under that paragraph.

10If an employee is required to make a payment under paragraph (1)(B), the agency that sponsored the education of the employee shall determine the amount of the payment, except that such amount may not exceed the pro rata share of the expenses incurred for the time remaining in the 2-year period.

11If an employee who is required to make a payment under this subsection does not make the payment, a sum equal to the amount of the expenses incurred by the Government for the education of that employee is recoverable by the Government from the employee or his estate by—

12(A) setoff against accrued pay, compensation, amount of retirement credit, or other amount due the employee from the Government; or

13(B) such other method as is provided by lay 1 for the recovery of amounts owing to the Government.

416.

Use of protective equipment or measures by employees

1None of the funds made available in this or any other Act for fiscal year 2013 and thereafter may be used to propose or effect a disciplinary or adverse action, with respect to any Department of Homeland Security employee who engages regularly with the public in the performance of his or her official duties solely because that employee elects to utilize protective equipment or measures, including but not limited to surgical masks, N95 respirators, gloves, or hand-sanitizers, where use of such equipment or measures is in accord with Department of Homeland Security policy, and Centers for Disease Control and Prevention and Office of Personnel Management guidance.

417.

Rotational cybersecurity research program

1To enhance the Department's cybersecurity capacity, the Secretary may establish a rotational research, development, and training program for—

2(1) detail to the Cybersecurity and Infrastructure Security Agency (including the national cybersecurity and communications integration center authorized by section 659 of this title) of Coast Guard Academy graduates and faculty; and

3(2) detail to the Coast Guard Academy, as faculty, of individuals with expertise and experience in cybersecurity who are employed by—

4(A) the Agency (including the center);

5(B) the Directorate of Science and Technology; or

6(C) institutions that have been designated by the Department as a Center of Excellence for Cyber Defense, or the equivalent.

421.

Definition

1In this part, the term "executive agency" has the meaning given that term under section 133 of title 41.

422.

Procurements for defense against or recovery from terrorism or nuclear, biological, chemical, or radiological attack

1The authorities provided in this part apply to any procurement of property or services by or for an executive agency that, as determined by the head of the executive agency, are to be used to facilitate defense against or recovery from terrorism or nuclear, biological, chemical, or radiological attack, but only if a solicitation of offers for the procurement is issued during the 1-year period beginning on November 25, 2002.

423.

Increased simplified acquisition threshold for procurements in support of humanitarian or peacekeeping operations or contingency operations

1For a procurement referred to in section 422 of this title that is carried out in support of a humanitarian or peacekeeping operation or a contingency operation, the simplified acquisition threshold definitions shall be applied as if the amount determined under the exception provided for such an operation in those definitions were—

2(1) in the case of a contract to be awarded and performed, or purchase to be made, inside the United States, $200,000; or

3(2) in the case of a contract to be awarded and performed, or purchase to be made, outside the United States, $300,000.

4In this section, the term "simplified acquisition threshold definitions" means the following:

5(1) Section 134 of title 41.

6(2) Section 153 of title 41.

7(3) Section 3015 of title 10.

8For a procurement carried out pursuant to subsection (a), section 644(j) of title 15 shall be applied as if the maximum anticipated value identified therein is equal to the amounts referred to in subsection (a).

424.

Increased micro-purchase threshold for certain procurements

1In the administration of section 1902 of title 41 with respect to a procurement referred to in section 422 of this title, the amount specified in subsections (a), (d), and (e) of such section 1902 shall be deemed to be $7,500.

425.

Application of certain commercial items authorities to certain procurements

1The head of an executive agency may apply the provisions of law listed in paragraph (2) to a procurement referred to in section 422 of this title without regard to whether the property or services are commercial items.

2The provisions of law referred to in paragraph (1) are as follows:

3(A) Sections 1901 and 1906 of title 41.

4(B) Section 3205 of title 10.

5(C) Section 3305 of title 41.

6The $5,000,000 limitation provided in section 1901(a)(2) of title 41, section 3205(a)(2) of title 10, and section 3305(a)(2) of title 41 shall not apply to purchases of property or services to which any of the provisions of law referred to in subsection (a) are applied under the authority of this section.

7The Director of the Office of Management and Budget shall issue guidance and procedures for the use of simplified acquisition procedures for a purchase of property or services in excess of $5,000,000 under the authority of this section.

8Authority under a provision of law referred to in subsection (a)(2) that expires under section 4202(e) of the Clinger-Cohen Act of 1996 (divisions D and E of Public Law 104–106; 10 U.S.C. 2304 note) shall, notwithstanding such section, continue to apply for use by the head of an executive agency as provided in subsections (a) and (b).

426.

Use of streamlined procedures

1The head of an executive agency shall, when appropriate, use streamlined acquisition authorities and procedures authorized by law for a procurement referred to in section 422 of this title, including authorities and procedures that are provided under the following provisions of law:

2In division C of subtitle I of title 41:

3(A) Paragraphs (1), (2), (6), and (7) of subsection (a) of section 3304 of title 41, relating to use of procedures other than competitive procedures under certain circumstances (subject to subsection (d) of such section).

4(B) Section 4106 of title 41, relating to orders under task and delivery order contracts.

5In part V of subtitle A of title 10:

6(A) Paragraphs (1), (2), (6), and (7) of subsection (a) of section 3204, relating to use of procedures other than competitive procedures under certain circumstances (subject to subsection (d) of such section).

7(B) Section 3406, relating to orders under task and delivery order contracts.

8Paragraphs (1)(B), (1)(D), and (2)(A) of section 1708(b) of title 41, relating to inapplicability of a requirement for procurement notice.

9Subclause (II) of section 637(a)(1)(D)(i) of title 15 and clause (ii) of section 657a(b)(2)(A) 1 of title 15 shall not apply in the use of streamlined acquisition authorities and procedures referred to in paragraphs (1)(A) and (2)(A) of subsection (a) for a procurement referred to in section 422 of this title.

427.

Review and report by Comptroller General

1Not later than March 31, 2004, the Comptroller General shall—

2(1) complete a review of the extent to which procurements of property and services have been made in accordance with this part; and

3(2) submit a report on the results of the review to the Committee on Governmental Affairs of the Senate and the Committee on Government Reform of the House of Representatives.

4The report under subsection (a)(2) shall include the following matters:

5The Comptroller General's assessment of—

6(A) the extent to which property and services procured in accordance with this subchapter have contributed to the capacity of the workforce of Federal Government employees within each executive agency to carry out the mission of the executive agency; and

7(B) the extent to which Federal Government employees have been trained on the use of technology.

8Any recommendations of the Comptroller General resulting from the assessment described in paragraph (1).

9In preparing for the review under subsection (a)(1), the Comptroller shall consult with the Committee on Governmental Affairs of the Senate and the Committee on Government Reform of the House of Representatives on the specific issues and topics to be reviewed. The extent of coverage needed in areas such as technology integration, employee training, and human capital management, as well as the data requirements of the study, shall be included as part of the consultation.

428.

Identification of new entrants into the Federal marketplace

1The head of each executive agency shall conduct market research on an ongoing basis to identify effectively the capabilities, including the capabilities of small businesses and new entrants into Federal contracting, that are available in the marketplace for meeting the requirements of the executive agency in furtherance of defense against or recovery from terrorism or nuclear, biological, chemical, or radiological attack. The head of the executive agency shall, to the maximum extent practicable, take advantage of commercially available market research methods, including use of commercial databases, to carry out the research.

441.

Administration

1The Secretary shall be responsible for the administration of this part.

2The Secretary may designate anti-terrorism technologies that qualify for protection under the system of risk management set forth in this part in accordance with criteria that shall include, but not be limited to, the following:

3(1) Prior United States Government use or demonstrated substantial utility and effectiveness.

4(2) Availability of the technology for immediate deployment in public and private settings.

5(3) Existence of extraordinarily large or extraordinarily unquantifiable potential third party liability risk exposure to the Seller or other provider of such anti-terrorism technology.

6(4) Substantial likelihood that such anti-terrorism technology will not be deployed unless protections under the system of risk management provided under this part are extended.

7(5) Magnitude of risk exposure to the public if such anti-terrorism technology is not deployed.

8(6) Evaluation of all scientific studies that can be feasibly conducted in order to assess the capability of the technology to substantially reduce risks of harm.

9(7) Anti-terrorism technology that would be effective in facilitating the defense against acts of terrorism, including technologies that prevent, defeat or respond to such acts.

10The Secretary may issue such regulations, after notice and comment in accordance with section 553 of title 5, as may be necessary to carry out this part.

442.

Litigation management

1There shall exist a Federal cause of action for claims arising out of, relating to, or resulting from an act of terrorism when qualified anti-terrorism technologies have been deployed in defense against or response or recovery from such act and such claims result or may result in loss to the Seller. The substantive law for decision in any such action shall be derived from the law, including choice of law principles, of the State in which such acts of terrorism occurred, unless such law is inconsistent with or preempted by Federal law. Such Federal cause of action shall be brought only for claims for injuries that are proximately caused by sellers 1 that provide qualified anti-terrorism technology to Federal and non-Federal government 2 customers.

2Such appropriate district court of the United States shall have original and exclusive jurisdiction over all actions for any claim for loss of property, personal injury, or death arising out of, relating to, or resulting from an act of terrorism when qualified anti-terrorism technologies have been deployed in defense against or response or recovery from such act and such claims result or may result in loss to the Seller.

3In an action brought under this section for damages the following provisions apply:

4No punitive damages intended to punish or deter, exemplary damages, or other damages not intended to compensate a plaintiff for actual losses may be awarded, nor shall any party be liable for interest prior to the judgment.

5Noneconomic damages may be awarded against a defendant only in an amount directly proportional to the percentage of responsibility of such defendant for the harm to the plaintiff, and no plaintiff may recover noneconomic damages unless the plaintiff suffered physical harm.

6For purposes of subparagraph (A), the term "noneconomic damages" means damages for losses for physical and emotional pain, suffering, inconvenience, physical impairment, mental anguish, disfigurement, loss of enjoyment of life, loss of society and companionship, loss of consortium, hedonic damages, injury to reputation, and any other nonpecuniary losses.

7Any recovery by a plaintiff in an action under this section shall be reduced by the amount of collateral source compensation, if any, that the plaintiff has received or is entitled to receive as a result of such acts of terrorism that result or may result in loss to the Seller.

8Should a product liability or other lawsuit be filed for claims arising out of, relating to, or resulting from an act of terrorism when qualified anti-terrorism technologies approved by the Secretary, as provided in paragraphs (2) and (3) of this subsection, have been deployed in defense against or response or recovery from such act and such claims result or may result in loss to the Seller, there shall be a rebuttable presumption that the government contractor defense applies in such lawsuit. This presumption shall only be overcome by evidence showing that the Seller acted fraudulently or with willful misconduct in submitting information to the Secretary during the course of the Secretary's consideration of such technology under this subsection. This presumption of the government contractor defense shall apply regardless of whether the claim against the Seller arises from a sale of the product to Federal Government or non-Federal Government customers.

9The Secretary will be exclusively responsible for the review and approval of anti-terrorism technology for purposes of establishing a government contractor defense in any product liability lawsuit for claims arising out of, relating to, or resulting from an act of terrorism when qualified anti-terrorism technologies approved by the Secretary, as provided in this paragraph and paragraph (3), have been deployed in defense against or response or recovery from such act and such claims result or may result in loss to the Seller. Upon the Seller's submission to the Secretary for approval of anti-terrorism technology, the Secretary will conduct a comprehensive review of the design of such technology and determine whether it will perform as intended, conforms to the Seller's specifications, and is safe for use as intended. The Seller will conduct safety and hazard analyses on such technology and will supply the Secretary with all such information.

10For anti-terrorism technology reviewed and approved by the Secretary, the Secretary will issue a certificate of conformance to the Seller and place the anti-terrorism technology on an Approved Product List for Homeland Security.

11Nothing in this section shall in any way limit the ability of any person to seek any form of recovery from any person, government, or other entity that—

12(1) attempts to commit, knowingly participates in, aids and abets, or commits any act of terrorism, or any criminal act related to or resulting from such act of terrorism; or

13(2) participates in a conspiracy to commit any such act of terrorism or any such criminal act.

443.

Risk management

1Any person or entity that sells or otherwise provides a qualified anti-terrorism technology to Federal and non-Federal Government customers ("Seller") shall obtain liability insurance of such types and in such amounts as shall be required in accordance with this section and certified by the Secretary to satisfy otherwise compensable third-party claims arising out of, relating to, or resulting from an act of terrorism when qualified anti-terrorism technologies have been deployed in defense against or response or recovery from such act.

2For the total claims related to 1 such act of terrorism, the Seller is not required to obtain liability insurance of more than the maximum amount of liability insurance reasonably available from private sources on the world market at prices and terms that will not unreasonably distort the sales price of Seller's anti-terrorism technologies.

3Liability insurance obtained pursuant to this subsection shall, in addition to the Seller, protect the following, to the extent of their potential liability for involvement in the manufacture, qualification, sale, use, or operation of qualified anti-terrorism technologies deployed in defense against or response or recovery from an act of terrorism:

4(A) Contractors, subcontractors, suppliers, vendors and customers of the Seller.

5(B) Contractors, subcontractors, suppliers, and vendors of the customer.

6Such liability insurance under this section shall provide coverage against third party claims arising out of, relating to, or resulting from the sale or use of anti-terrorism technologies.

7The Seller shall enter into a reciprocal waiver of claims with its contractors, subcontractors, suppliers, vendors and customers, and contractors and subcontractors of the customers, involved in the manufacture, sale, use or operation of qualified anti-terrorism technologies, under which each party to the waiver agrees to be responsible for losses, including business interruption losses, that it sustains, or for losses sustained by its own employees resulting from an activity resulting from an act of terrorism when qualified anti-terrorism technologies have been deployed in defense against or response or recovery from such act.

8Notwithstanding any other provision of law, liability for all claims against a Seller arising out of, relating to, or resulting from an act of terrorism when qualified anti-terrorism technologies have been deployed in defense against or response or recovery from such act and such claims result or may result in loss to the Seller, whether for compensatory or punitive damages or for contribution or indemnity, shall not be in an amount greater than the limits of liability insurance coverage required to be maintained by the Seller under this section.

444.

Definitions

1For purposes of this part, the following definitions apply:

2For purposes of this part, the term "qualified anti-terrorism technology" means any product, equipment, service (including support services), device, or technology (including information technology) designed, developed, modified, or procured for the specific purpose of preventing, detecting, identifying, or deterring acts of terrorism or limiting the harm such acts might otherwise cause, that is designated as such by the Secretary.

3(A) The term "act of terrorism" means any act that the Secretary determines meets the requirements under subparagraph (B), as such requirements are further defined and specified by the Secretary.

4(B) Requirements.—An act meets the requirements of this subparagraph if the act—

5(i) is unlawful;

6(ii) causes harm to a person, property, or entity, in the United States, or in the case of a domestic United States air carrier or a United States-flag vessel (or a vessel based principally in the United States on which United States income tax is paid and whose insurance coverage is subject to regulation in the United States), in or outside the United States; and

7(iii) uses or attempts to use instrumentalities, weapons or other methods designed or intended to cause mass destruction, injury or other loss to citizens or institutions of the United States.

8The term "insurance carrier" means any corporation, association, society, order, firm, company, mutual,1 partnership, individual aggregation of individuals, or any other legal entity that provides commercial property and casualty insurance. Such term includes any affiliates of a commercial insurance carrier.

9The term "liability insurance" means insurance for legal liabilities incurred by the insured resulting from—

10(i) loss of or damage to property of others;

11(ii) ensuing loss of income or extra expense incurred because of loss of or damage to property of others;

12(iii) bodily injury (including) to persons other than the insured or its employees; or

13(iv) loss resulting from debt or default of another.

14The term "loss" means death, bodily injury, or loss of or damage to property, including business interruption loss.

15The term "non-Federal Government customers" means any customer of a Seller that is not an agency or instrumentality of the United States Government with authority under Public Law 85–804 [50 U.S.C. 1431 et seq.] to provide for indemnification under certain circumstances for third-party claims against its contractors, including but not limited to State and local authorities and commercial entities.

451.

Advisory committees

1The Secretary may establish, appoint members of, and use the services of, advisory committees, as the Secretary may deem necessary. An advisory committee established under this section may be exempted by the Secretary from chapter 10 of title 5, but the Secretary shall publish notice in the Federal Register announcing the establishment of such a committee and identifying its purpose and membership. Notwithstanding the preceding sentence, members of an advisory committee that is exempted by the Secretary under the preceding sentence who are special Government employees (as that term is defined in section 202 of title 18) shall be eligible for certifications under subsection (b)(3) of section 208 of title 18 for official actions taken as a member of such advisory committee.

2Any advisory committee established by the Secretary shall terminate 2 years after the date of its establishment, unless the Secretary makes a written determination to extend the advisory committee to a specified date, which shall not be more than 2 years after the date on which such determination is made. The Secretary may make any number of subsequent extensions consistent with this subsection.

452.

Reorganization

1The Secretary may allocate or reallocate functions among the officers of the Department, and may establish, consolidate, alter, or discontinue organizational units within the Department, but only—

2(1) pursuant to section 542(b) of this title; or

3(2) after the expiration of 60 days after providing notice of such action to the appropriate congressional committees, which shall include an explanation of the rationale for the action.

4Authority under subsection (a)(1) does not extend to the abolition of any agency, entity, organizational unit, program, or function established or required to be maintained by this chapter.

5Authority under subsection (a)(2) does not extend to the abolition of any agency, entity, organizational unit, program, or function established or required to be maintained by statute.

453.

Use of appropriated funds

1If specifically authorized to dispose of real property in this chapter or any other Act, the Secretary shall exercise this authority in strict compliance with subchapter IV of chapter 5 of title 40.

2The Secretary shall deposit the proceeds of any exercise of property disposal authority into the miscellaneous receipts of the Treasury in accordance with section 3302(b) of title 31.

3Except as authorized by section 2601 of title 10, by section 93 1 of title 14, or by section 321n or 464 of this title, gifts or donations of services or property of or for the Department may not be accepted, used, or disposed of unless specifically permitted in advance in an appropriations Act and only under the conditions and for the purposes specified in such appropriations Act.

4Under section 1105 of title 31, the President shall submit to Congress a detailed budget request for the Department for fiscal year 2004, and for each subsequent fiscal year.

453a.

Additional uses of appropriated funds

1In fiscal year 2004 and thereafter, unless otherwise provided, funds may be used for purchase of uniforms without regard to the general purchase price limitation for the current fiscal year; purchase of insurance for official motor vehicles operated in foreign countries; entering into contracts with the Department of State to furnish health and medical services to employees and their dependents serving in foreign countries; services authorized by section 3109 of title 5; and the hire and purchase of motor vehicles, as authorized by section 1343 of title 31: Provided, That purchase for police-type use of passenger vehicles may be made without regard to the general purchase price limitation for the current fiscal year.

453b.

Requirement to buy certain items related to national security interests from American sources; exceptions

1Except as provided in subsections (c) through (g), funds appropriated or otherwise available to the Department of Homeland Security may not be used for the procurement of an item described in subsection (b) if the item is not grown, reprocessed, reused, or produced in the United States.

2An item referred to in subsection (a) is any of the following, if the item is directly related to the national security interests of the United States:

3(1) 1 An article or item of—

4(A) clothing and the materials and components thereof, other than sensors, electronics, or other items added to, and not normally associated with, clothing (and the materials and components thereof);

5(B) tents, tarpaulins, covers, textile belts, bags, protective equipment (including but not limited to body armor), sleep systems, load carrying equipment (including but not limited to fieldpacks), textile marine equipment, parachutes, or bandages;

6(C) cotton and other natural fiber products, woven silk or woven silk blends, spun silk yarn for cartridge cloth, synthetic fabric or coated synthetic fabric (including all textile fibers and yarns that are for use in such fabrics), canvas products, or wool (whether in the form of fiber or yarn or contained in fabrics, materials, or manufactured articles); or

7(D) any item of individual equipment manufactured from or containing such fibers, yarns, fabrics, or materials.

8Subsection (a) does not apply to the extent that the Secretary of Homeland Security determines that satisfactory quality and sufficient quantity of any such article or item described in subsection (b)(1) grown, reprocessed, reused, or produced in the United States cannot be procured as and when needed at United States market prices. This section is not applicable to covered items that are, or include, materials determined to be non-available in accordance with Federal Acquisition Regulation 25.104 Nonavailable Articles.

9Notwithstanding subsection (a), the Secretary of Homeland Security may accept delivery of an item covered by subsection (b) that contains non-compliant fibers if the total value of non-compliant fibers contained in the end item does not exceed 10 percent of the total purchase price of the end item.

10Subsection (a) does not apply to the following:

11(1) Procurements by vessels in foreign waters.

12(2) Emergency procurements.

13Subsection (a) does not apply to purchases for amounts not greater than the simplified acquisition threshold referred to in section 3205 of title 10.

14This section is applicable to contracts and subcontracts for the procurement of commercial products notwithstanding section 1906 of title 41, with the exception of commercial products listed under subsections (b)(1)(C) and (b)(1)(D) above. For the purposes of this section, "commercial product" shall be as defined in section 103 of title 41.

15In this section, the term "United States" includes the possessions of the United States.

16In the case of any contract for the procurement of an item described in subsection (b)(1), if the Secretary of Homeland Security applies an exception set forth in subsection (c) with respect to that contract, the Secretary shall, not later than 7 days after the award of the contract, post a notification that the exception has been applied on the Internet site maintained by the General Services Administration known as FedBizOps.gov (or any successor site).

17The Secretary of Homeland Security shall ensure that each member of the acquisition workforce in the Department of Homeland Security who participates personally and substantially in the acquisition of textiles on a regular basis receives training during fiscal year 2009 on the requirements of this section and the regulations implementing this section.

18The Secretary shall ensure that any training program for the acquisition workforce developed or implemented after February 17, 2009, includes comprehensive information on the requirements described in paragraph (1).

19This section shall be applied in a manner consistent with United States obligations under international agreements.

20This section applies with respect to contracts entered into by the Department of Homeland Security 180 days after February 17, 2009.

453c.

Disposition of equines unfit for service

1None of the funds made available in this or any other Act for fiscal year 2012 and thereafter may be used to destroy or put out to pasture any horse or other equine belonging to any component or agency of the Department of Homeland Security that has become unfit for service, unless the trainer or handler is first given the option to take possession of the equine through an adoption program that has safeguards against slaughter and inhumane treatment.

454.

Future Years Homeland Security Program

1Each budget request submitted to Congress for the Department under section 1105 of title 31 shall, at or about the same time, be accompanied by a Future Years Homeland Security Program.

2The Future Years Homeland Security Program under subsection (a) shall—

3(1) include the same type of information, organizational structure, and level of detail as the future years defense program submitted to Congress by the Secretary of Defense under section 221 of title 10;

4(2) set forth the homeland security strategy of the Department, which shall be developed and updated as appropriate annually by the Secretary, that was used to develop program planning guidance for the Future Years Homeland Security Program; and

5(3) include an explanation of how the resource allocations included in the Future Years Homeland Security Program correlate to the homeland security strategy set forth under paragraph (2).

6This section shall take effect with respect to the preparation and submission of the fiscal year 2005 budget request for the Department and for any subsequent fiscal year, except that the first Future Years Homeland Security Program shall be submitted not later than 90 days after the Department's fiscal year 2005 budget request is submitted to Congress.

455.

Miscellaneous authorities

1The Department shall have a seal, whose design is subject to the approval of the President.

2With respect to the Department, the Secretary shall have the same authorities that the Secretary of Transportation has with respect to the Department of Transportation under section 324 of title 49.

3Unless otherwise provided in the delegation or by law, any function delegated under this chapter may be redelegated to any subordinate.

4At the request of an appropriate law enforcement official of a State or political subdivision, the Secretary, through deployment of the Secret Service or United States Immigration and Customs Enforcement, may assist in the investigation of violent acts and shootings occurring in a place of public use, and in the investigation of mass killings and attempted mass killings. Any assistance provided by the Secretary under this subsection shall be presumed to be within the scope of Federal office or employment.

5For purposes of this subsection—

6(A) the term "mass killings" means 3 or more killings in a single incident; and

7(B) the term "place of public use" has the meaning given that term under section 2332f(e)(6) of title 18.

456.

Military activities

1Nothing in this chapter shall confer upon the Secretary any authority to engage in warfighting, the military defense of the United States, or other military activities, nor shall anything in this chapter limit the existing authority of the Department of Defense or the Armed Forces to engage in warfighting, the military defense of the United States, or other military activities.

457.

Regulatory authority and preemption

1Except as otherwise provided in sections 186(c) and 441(c) of this title and section 1315 of title 40,1 this chapter vests no new regulatory authority in the Secretary or any other Federal official, and transfers to the Secretary or another Federal official only such regulatory authority as exists on November 25, 2002, within any agency, program, or function transferred to the Department pursuant to this chapter, or that on November 25, 2002, is exercised by another official of the executive branch with respect to such agency, program, or function. Any such transferred authority may not be exercised by an official from whom it is transferred upon transfer of such agency, program, or function to the Secretary or another Federal official pursuant to this chapter. This chapter may not be construed as altering or diminishing the regulatory authority of any other executive agency, except to the extent that this chapter transfers such authority from the agency.

2Except as otherwise provided in this chapter, this chapter preempts no State or local law, except that any authority to preempt State or local law vested in any Federal agency or official transferred to the Department pursuant to this chapter shall be transferred to the Department effective on the date of the transfer to the Department of that Federal agency or official.

458.

Office of Counternarcotics Enforcement

1There is established in the Department an Office of Counternarcotics Enforcement, which shall be headed by a Director appointed by the President.

2The Secretary shall assign permanent staff to the Office, consistent with effective management of Department resources.

3The Secretary shall designate senior employees from each appropriate subdivision of the Department that has significant counternarcotics responsibilities to act as a liaison between that subdivision and the Office of Counternarcotics Enforcement.

4The Director of the Office of Counternarcotics Enforcement shall not be employed by, assigned to, or serve as the head of, any other branch of the Federal Government, any State or local government, or any subdivision of the Department other than the Office of Counternarcotics Enforcement.

5The Secretary shall direct the Director of the Office of Counternarcotics Enforcement—

6(1) to coordinate policy and operations within the Department, between the Department and other Federal departments and agencies, and between the Department and State and local agencies with respect to stopping the entry of illegal drugs into the United States;

7(2) to ensure the adequacy of resources within the Department for stopping the entry of illegal drugs into the United States;

8(3) to recommend the appropriate financial and personnel resources necessary to help the Department better fulfill its responsibility to stop the entry of illegal drugs into the United States;

9(4) within the Joint Terrorism Task Force construct to track and sever connections between illegal drug trafficking and terrorism; and

10(5) to be a representative of the Department on all task forces, committees, or other entities whose purpose is to coordinate the counternarcotics enforcement activities of the Department and other Federal, State or local agencies.

11Nothing in this section shall be construed to authorize direct control of the operations conducted by the Directorate of Border and Transportation Security,1 the Coast Guard, or joint terrorism task forces.

12The Director of the Office of Counternarcotics Enforcement shall, not later than 30 days after the submission by the President to Congress of any request for expenditures for the Department, submit to the Committees on Appropriations and the authorizing committees of jurisdiction of the House of Representatives and the Senate a review and evaluation of such request. The review and evaluation shall—

13(A) identify any request or subpart of any request that affects or may affect the counternarcotics activities of the Department or any of its subdivisions, or that affects the ability of the Department or any subdivision of the Department to meet its responsibility to stop the entry of illegal drugs into the United States;

14(B) describe with particularity how such requested funds would be or could be expended in furtherance of counternarcotics activities; and

15(C) compare such requests with requests for expenditures and amounts appropriated by Congress in the previous fiscal year.

16The Director of the Office of Counternarcotics Enforcement shall, not later than February 1 of each year, submit to the Committees on Appropriations and the authorizing committees of jurisdiction of the House of Representatives and the Senate a review and evaluation of the counternarcotics activities of the Department for the previous fiscal year. The review and evaluation shall—

17(A) describe the counternarcotics activities of the Department and each subdivision of the Department (whether individually or in cooperation with other subdivisions of the Department, or in cooperation with other branches of the Federal Government or with State or local agencies), including the methods, procedures, and systems (including computer systems) for collecting, analyzing, sharing, and disseminating information concerning narcotics activity within the Department and between the Department and other Federal, State, and local agencies;

18(B) describe the results of those activities, using quantifiable data whenever possible;

19(C) state whether those activities were sufficient to meet the responsibility of the Department to stop the entry of illegal drugs into the United States, including a description of the performance measures of effectiveness that were used in making that determination; and

20(D) recommend, where appropriate, changes to those activities to improve the performance of the Department in meeting its responsibility to stop the entry of illegal drugs into the United States.

21Any content of a review and evaluation described in the reports required in this subsection that involves information classified under criteria established by an Executive order, or whose public disclosure, as determined by the Secretary, would be detrimental to the law enforcement or national security activities of the Department or any other Federal, State, or local agency, shall be presented to Congress separately from the rest of the review and evaluation.

459.

Office of International Affairs

1There is established within the Office of the Secretary an Office of International Affairs. The Office shall be headed by a Director, who shall be a senior official appointed by the Secretary.

2The Director shall have the following duties:

3(1) To promote information and education exchange with nations friendly to the United States in order to promote sharing of best practices and technologies relating to homeland security. Such exchange shall include the following:

4(A) Exchange of information on research and development on homeland security technologies.

5(B) Joint training exercises of first responders.

6(C) Exchange of expertise on terrorism prevention, response, and crisis management.

7(2) To identify areas for homeland security information and training exchange where the United States has a demonstrated weakness and another friendly nation or nations have a demonstrated expertise.

8(3) To plan and undertake international conferences, exchange programs, and training activities.

9(4) To manage international activities within the Department in coordination with other Federal officials with responsibility for counter-terrorism matters.

460.

Prohibition of the Terrorism Information and Prevention System

1Any and all activities of the Federal Government to implement the proposed component program of the Citizen Corps known as Operation TIPS (Terrorism Information and Prevention System) are hereby prohibited.

461.

Review of pay and benefit plans

1Notwithstanding any other provision of this chapter, the Secretary shall, in consultation with the Director of the Office of Personnel Management, review the pay and benefit plans of each agency whose functions are transferred under this chapter to the Department and, within 90 days after November 25, 2002, submit a plan to the President of the Senate and the Speaker of the House of Representatives and the appropriate committees and subcommittees of Congress, for ensuring, to the maximum extent practicable, the elimination of disparities in pay and benefits throughout the Department, especially among law enforcement personnel, that are inconsistent with merit system principles set forth in section 2301 of title 5.

462.

Office of National Capital Region Coordination

1There is established within the Office of the Secretary the Office of National Capital Region Coordination, to oversee and coordinate Federal programs for and relationships with State, local, and regional authorities in the National Capital Region, as defined under section 2674(f)(2) of title 10.

2The Office established under paragraph (1) shall be headed by a Director, who shall be appointed by the Secretary.

3The Secretary shall cooperate with the Mayor of the District of Columbia, the Governors of Maryland and Virginia, and other State, local, and regional officers in the National Capital Region to integrate the District of Columbia, Maryland, and Virginia into the planning, coordination, and execution of the activities of the Federal Government for the enhancement of domestic preparedness against the consequences of terrorist attacks.

4The Office established under subsection (a)(1) shall—

5(1) coordinate the activities of the Department relating to the National Capital Region, including cooperation with the Office for State and Local Government Coordination;

6(2) assess, and advocate for, the resources needed by State, local, and regional authorities in the National Capital Region to implement efforts to secure the homeland;

7(3) provide State, local, and regional authorities in the National Capital Region with regular information, research, and technical support to assist the efforts of State, local, and regional authorities in the National Capital Region in securing the homeland;

8(4) develop a process for receiving meaningful input from State, local, and regional authorities and the private sector in the National Capital Region to assist in the development of the homeland security plans and activities of the Federal Government;

9(5) coordinate with Federal agencies in the National Capital Region on terrorism preparedness, to ensure adequate planning, information sharing, training, and execution of the Federal role in domestic preparedness activities;

10(6) coordinate with Federal, State, local, and regional agencies, and the private sector in the National Capital Region on terrorism preparedness to ensure adequate planning, information sharing, training, and execution of domestic preparedness activities among these agencies and entities; and

11(7) serve as a liaison between the Federal Government and State, local, and regional authorities, and private sector entities in the National Capital Region to facilitate access to Federal grants and other programs.

12The Office established under subsection (a) shall submit an annual report to Congress that includes—

13(1) the identification of the resources required to fully implement homeland security efforts in the National Capital Region;

14(2) an assessment of the progress made by the National Capital Region in implementing homeland security efforts; and

15(3) recommendations to Congress regarding the additional resources needed to fully implement homeland security efforts in the National Capital Region.

16Nothing contained in this section shall be construed as limiting the power of State and local governments.

463.

Requirement to comply with laws protecting equal employment opportunity and providing whistleblower protections

1Nothing in this chapter shall be construed as exempting the Department from requirements applicable with respect to executive agencies—

2(1) to provide equal employment protection for employees of the Department (including pursuant to the provisions in section 2302(b)(1) of title 5 and the Notification and Federal Employee Antidiscrimination and Retaliation Act of 2002 (Public Law 107–174)); or

3(2) to provide whistleblower protections for employees of the Department (including pursuant to the provisions in section 2302(b)(8) and (9) of such title and the Notification and Federal Employee Antidiscrimination and Retaliation Act of 2002).

464.

Federal Law Enforcement Training Centers

1The Secretary shall maintain in the Department the Federal Law Enforcement Training Centers (FLETC), headed by a Director, who shall report to the Secretary.

2The Director shall occupy a career-reserved position within the Senior Executive Service.

3The Director shall—

4(1) develop training goals and establish strategic and tactical organizational program plan and priorities;

5(2) provide direction and management for FLETC's training facilities, programs, and support activities while ensuring that organizational program goals and priorities are executed in an effective and efficient manner;

6(3) develop homeland security and law enforcement training curricula, including curricula related to domestic preparedness and response to threats or acts of terrorism, for Federal, State, local, tribal, territorial, and international law enforcement and security agencies and private sector security agencies;

7(4) monitor progress toward strategic and tactical FLETC plans regarding training curricula, including curricula related to domestic preparedness and response to threats or acts of terrorism, and facilities;

8(5) ensure the timely dissemination of homeland security information as necessary to Federal, State, local, tribal, territorial, and international law enforcement and security agencies and the private sector to achieve the training goals for such entities, in accordance with paragraph (1);

9(6) carry out delegated acquisition responsibilities in a manner that—

10(A) fully complies with—

11(i) Federal law;

12(ii) the Federal Acquisition Regulation, including requirements regarding agency obligations to contract only with responsible prospective contractors; and

13(iii) Department acquisition management directives; and

14(B) maximizes opportunities for small business participation;

15(7) coordinate and share information with the heads of relevant components and offices on digital learning and training resources, as appropriate;

16(8) advise the Secretary on matters relating to executive level policy and program administration of Federal, State, local, tribal, territorial, and international law enforcement and security training activities and private sector security agency training activities, including training activities related to domestic preparedness and response to threats or acts of terrorism;

17(9) collaborate with the Secretary and relevant officials at other Federal departments and agencies, as appropriate, to improve international instructional development, training, and technical assistance provided by the Federal Government to foreign law enforcement; and

18(10) carry out such other functions as the Secretary determines are appropriate.

19The Director is authorized to provide training to employees of Federal agencies who are engaged, directly or indirectly, in homeland security operations or Federal law enforcement activities, including such operations or activities related to domestic preparedness and response to threats or acts of terrorism. In carrying out such training, the Director shall—

20(A) evaluate best practices of law enforcement training methods and curriculum content to maintain state-of-the-art expertise in adult learning methodology;

21(B) provide expertise and technical assistance, including on domestic preparedness and response to threats or acts of terrorism, to Federal, State, local, tribal, territorial, and international law enforcement and security agencies and private sector security agencies; and

22(C) maintain a performance evaluation process for students.

23The Director shall consult with relevant law enforcement and security agencies in the development and delivery of FLETC's training programs.

24The training required under paragraph (1) may be conducted at FLETC facilities, at appropriate off-site locations, or by distributed learning.

25The Director may—

26(i) execute strategic partnerships with State and local law enforcement to provide such law enforcement with specific training, including maritime law enforcement training; and

27(ii) coordinate with the Director of the Cybersecurity and Infrastructure Security Agency and with private sector stakeholders, including critical infrastructure owners and operators, to provide training pertinent to improving coordination, security, and resiliency of critical infrastructure.

28The Director shall provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate, upon request, information on activities undertaken in the previous year pursuant to subparagraph (A).

29The Director may detail employees of FLETC to positions throughout the Department in furtherance of improving the effectiveness and quality of training provided by the Department and, as appropriate, the development of critical departmental programs and initiatives.

30Partner organizations that wish to participate in FLETC training programs shall assign non-reimbursable detailed instructors to FLETC for designated time periods to support all training programs at FLETC, as appropriate. The Director shall determine the number of detailed instructors that is proportional to the number of training hours requested by each partner organization scheduled by FLETC for each fiscal year. If a partner organization is unable to provide a proportional number of detailed instructors, such partner organization shall reimburse FLETC for the salary equivalent for such detailed instructors, as appropriate.

31Partner organizations shall be responsible for the following expenses:

32(i) Salaries, travel expenses, lodging expenses, and miscellaneous per diem allowances of their personnel attending training courses at FLETC.

33(ii) Salaries and travel expenses of instructors and support personnel involved in conducting advanced training at FLETC for partner organization personnel and the cost of expendable supplies and special equipment for such training, unless such supplies and equipment are common to FLETC-conducted training and have been included in FLETC's budget for the applicable fiscal year.

34All hours of advanced training and hours of basic training provided in excess of the training for which appropriations were made available shall be paid by the partner organizations and provided to FLETC on a reimbursable basis in accordance with section 4104 of title 5.

35The Director is authorized to charge and retain fees that would pay for its actual costs of the training for the following:

36(i) State, local, tribal, and territorial law enforcement personnel.

37(ii) Foreign law enforcement officials, including provision of such training at the International Law Enforcement Academies wherever established.

38(iii) Private sector security officers, participants in the Federal Flight Deck Officer program under section 44921 of title 49, and other appropriate private sector individuals.

39The Director may waive the requirement for reimbursement of any cost under this section and shall maintain records regarding the reasons for any requirements so waived.

40The Director is authorized to reimburse travel or other expenses for non-Federal personnel who attend activities related to training sponsored by FLETC, at travel and per diem rates established by the General Services Administration.

41In furtherance of its training mission, the Director is authorized to provide the following support to students:

42(A) Athletic and related activities.

43(B) Short-term medical services.

44(C) Chaplain services.

45Notwithstanding any other provision of law, the Director is authorized to appoint and maintain, as necessary, Federal annuitants who have expert knowledge and experience to meet the training responsibilities under this subsection.

46A Federal annuitant employed pursuant to this paragraph shall not be subject to any reduction in pay for annuity allocable to the period of actual employment under the provisions of section 8344 or 8468 of title 5 or similar provision of any other retirement system for employees.

47A Federal annuitant employed pursuant to this paragraph shall not be considered an employee for purposes of subchapter III of chapter 83 or chapter 84 of title 5 or such other retirement system (referred to in subparagraph (B)) as may apply.

48Federal annuitants shall be counted on a full time equivalent basis.

49No appointment under this paragraph may be made which would result in the displacement of any employee.

50The Director is authorized to reimburse intermittent Federal employees traveling from outside a commuting distance (to be predetermined by the Director) for travel expenses.

51Notwithstanding any other provision of law, individuals attending training at any FLETC facility shall, to the extent practicable and in accordance with FLETC policy, reside in on-FLETC or FLETC-provided housing.

52In order to further the goals and objectives of FLETC, the Director is authorized to—

53(1) expend funds for public awareness and to enhance community support of law enforcement training, including the advertisement of available law enforcement training programs;

54(2) accept and use gifts of property, both real and personal, and to accept gifts of services, for purposes that promote the functions of the Director pursuant to subsection (c) and the training responsibilities of the Director under subsection (d);

55(3) accept reimbursement from other Federal agencies for the construction or renovation of training and support facilities and the use of equipment and technology on government owned-property; 1

56(4) obligate funds in anticipation of reimbursements from agencies receiving training at FLETC, except that total obligations at the end of a fiscal year may not exceed total budgetary resources available at the end of such fiscal year;

57(5) in accordance with the purchasing authority provided under section 453a of this title—

58(A) purchase employee and student uniforms; and

59(B) purchase and lease passenger motor vehicles, including vehicles for police-type use;

60(6) provide room and board for student interns; and

61(7) expend funds each fiscal year to honor and memorialize FLETC graduates who have died in the line of duty.

62In this section:

63The term "basic training" means the entry-level training required to instill in new Federal law enforcement personnel fundamental knowledge of criminal laws, law enforcement and investigative techniques, laws and rules of evidence, rules of criminal procedure, constitutional rights, search and seizure, and related issues.

64The term "detailed instructors" means personnel who are assigned to the Federal Law Enforcement Training Centers for a period of time to serve as instructors for the purpose of conducting basic and advanced training.

65The term "Director" means the Director of the Federal Law Enforcement Training Centers.

66The term "distributed learning" means education in which students take academic courses by accessing information and communicating with the instructor, from various locations, on an individual basis, over a computer network or via other technologies.

67The term "employee" has the meaning given such term in section 2105 of title 5.

68The term "Federal agency" means—

69(A) an Executive Department as defined in section 101 of title 5;

70(B) an independent establishment as defined in section 104 of title 5;

71(C) a Government corporation as defined in section 9101 of title 31;

72(D) the Government Printing Office;

73(E) the United States Capitol Police;

74(F) the United States Supreme Court Police; and

75(G) Government agencies with law enforcement related duties.

76The term "law enforcement personnel" means an individual, including criminal investigators (commonly known as "agents") and uniformed police (commonly known as "officers"), who has statutory authority to search, seize, make arrests, or to carry firearms.

77The term "local" means—

78(A) of or pertaining to any county, parish, municipality, city, town, township, rural community, unincorporated town or village, local public authority, educational institution, special district, intrastate district, council of governments (regardless of whether the council of governments is incorporated as a nonprofit corporation under State law), regional or interstate government entity, any agency or instrumentality of a local government, or any other political subdivision of a State; and

79(B) an Indian tribe or authorized tribal organization, or in Alaska a Native village or Alaska Regional Native Corporation.

80The term "partner organization" means any Federal agency participating in FLETC's training programs under a formal memorandum of understanding.

81The term "State" means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Virgin Islands, Guam, American Samoa, the Commonwealth of the Northern Mariana Islands, and any possession of the United States.

82The term "student intern" means any eligible baccalaureate or graduate degree student participating in FLETC's College Intern Program.

83No funds are authorized to carry out this section. This section shall be carried out using amounts otherwise appropriated or made available for such purpose.

464a.

Repealed. Pub. L. 111–245, §2(b)(2), Sept. 30, 2010, 124 Stat. 2621

464b.

Staffing accreditation function

1In fiscal year 2004 and thereafter, the Center is authorized to accept detailees from other Federal agencies, on a non-reimbursable basis, to staff the accreditation function.

464c.

Student housing

1In fiscal year 2004 and thereafter, students attending training at any Center site shall reside in on-Center or Center-provided housing, insofar as available and in accordance with Center policy.

464d.

Additional funds for training

1In fiscal year 2004 and thereafter, funds appropriated in this account shall be available, at the discretion of the Director, for the following: training United States Postal Service law enforcement personnel and Postal police officers; State and local government law enforcement training on a space-available basis; training of foreign law enforcement officials on a space-available basis with reimbursement of actual costs to this appropriation, except that reimbursement may be waived by the Secretary for law enforcement training activities in foreign countries undertaken under section 801 of the Antiterrorism and Effective Death Penalty Act of 1996 (28 U.S.C. 509 note); training of private sector security officials on a space-available basis with reimbursement of actual costs to this appropriation; and travel expenses of non-Federal personnel to attend course development meetings and training sponsored by the Center.

464e.

Short-term medical services for students

1In fiscal year 2004 and thereafter, the Center is authorized to provide short-term medical services for students undergoing training at the Center.

465.

Joint Interagency Task Force

1The Secretary may establish and operate a permanent Joint Interagency Homeland Security Task Force composed of representatives from military and civilian agencies of the United States Government for the purposes of anticipating terrorist threats against the United States and taking appropriate actions to prevent harm to the United States.

2It is the sense of Congress that the Secretary should model the Joint Interagency Homeland Security Task Force on the approach taken by the Joint Interagency Task Forces for drug interdiction at Key West, Florida and Alameda, California, to the maximum extent feasible and appropriate.

466.

Sense of Congress reaffirming the continued importance and applicability of the Posse Comitatus Act

1Congress finds the following:

2(1) Section 1385 of title 18 (commonly known as the "Posse Comitatus Act") prohibits the use of the Armed Forces as a posse comitatus to execute the laws except in cases and under circumstances expressly authorized by the Constitution or Act of Congress.

3(2) Enacted in 1878, the Posse Comitatus Act was expressly intended to prevent United States Marshals, on their own initiative, from calling on the Army for assistance in enforcing Federal law.

4(3) The Posse Comitatus Act has served the Nation well in limiting the use of the Armed Forces to enforce the law.

5(4) Nevertheless, by its express terms, the Posse Comitatus Act is not a complete barrier to the use of the Armed Forces for a range of domestic purposes, including law enforcement functions, when the use of the Armed Forces is authorized by Act of Congress or the President determines that the use of the Armed Forces is required to fulfill the President's obligations under the Constitution to respond promptly in time of war, insurrection, or other serious emergency.

6(5) Existing laws, including chapter 13 of title 10 (commonly known as the "Insurrection Act"), and the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.), grant the President broad powers that may be invoked in the event of domestic emergencies, including an attack against the Nation using weapons of mass destruction, and these laws specifically authorize the President to use the Armed Forces to help restore public order.

7Congress reaffirms the continued importance of section 1385 of title 18, and it is the sense of Congress that nothing in this chapter should be construed to alter the applicability of such section to any use of the Armed Forces as a posse comitatus to execute the laws.

467.

Coordination with the Department of Health and Human Services under the Public Health Service Act

1The annual Federal response plan developed by the Department shall be consistent with section 319 of the Public Health Service Act (42 U.S.C. 247d).

2Full disclosure among relevant agencies shall be made in accordance with this subsection.

3During the period in which the Secretary of Health and Human Services has declared the existence of a public health emergency under section 319(a) of the Public Health Service Act (42 U.S.C. 247d(a)), the Secretary of Health and Human Services shall keep relevant agencies, including the Department of Homeland Security, the Department of Justice, and the Federal Bureau of Investigation, fully and currently informed.

4In cases involving, or potentially involving, a public health emergency, but in which no determination of an emergency by the Secretary of Health and Human Services under section 319(a) of the Public Health Service Act (42 U.S.C. 247d(a)), has been made, all relevant agencies, including the Department of Homeland Security, the Department of Justice, and the Federal Bureau of Investigation, shall keep the Secretary of Health and Human Services and the Director of the Centers for Disease Control and Prevention fully and currently informed.

468.

Preserving Coast Guard mission performance

1In this section:

2The term "non-homeland security missions" means the following missions of the Coast Guard:

3(A) Marine safety.

4(B) Search and rescue.

5(C) Aids to navigation.

6(D) Living marine resources (fisheries law enforcement).

7(E) Marine environmental protection.

8(F) Ice operations.

9The term "homeland security missions" means the following missions of the Coast Guard:

10(A) Ports, waterways and coastal security.

11(B) Drug interdiction.

12(C) Migrant interdiction.

13(D) Defense readiness.

14(E) Other law enforcement.

15There are transferred to the Department the authorities, functions, personnel, and assets of the Coast Guard, which shall be maintained as a distinct entity within the Department, including the authorities and functions of the Secretary of Transportation relating thereto.

16Notwithstanding any other provision of this chapter, the authorities, functions, and capabilities of the Coast Guard to perform its missions shall be maintained intact and without significant reduction after the transfer of the Coast Guard to the Department, except as specified in subsequent Acts.

17No mission, function, or asset (including for purposes of this subsection any ship, aircraft, or helicopter) of the Coast Guard may be diverted to the principal and continuing use of any other organization, unit, or entity of the Department, except for details or assignments that do not reduce the Coast Guard's capability to perform its missions.

18The Secretary may not substantially or significantly reduce the missions of the Coast Guard or the Coast Guard's capability to perform those missions, except as specified in subsequent Acts.

19The Secretary may waive the restrictions under paragraph (1) for a period of not to exceed 90 days upon a declaration and certification by the Secretary to Congress that a clear, compelling, and immediate need exists for such a waiver. A certification under this paragraph shall include a detailed justification for the declaration and certification, including the reasons and specific information that demonstrate that the Nation and the Coast Guard cannot respond effectively if the restrictions under paragraph (1) are not waived.

20Upon the transfer of the Coast Guard to the Department, the Commandant shall report directly to the Secretary without being required to report through any other official of the Department.

21None of the conditions and restrictions in this section shall apply when the Coast Guard operates as a service in the Navy under section 3 1 of title 14.

469.

Fees for credentialing and background investigations in transportation

1For fiscal year 2004 and thereafter, the Secretary of Homeland Security shall charge reasonable fees for providing credentialing and background investigations in the field of transportation: Provided, That the establishment and collection of fees shall be subject to the following requirements:

2(1) such fees, in the aggregate, shall not exceed the costs incurred by the Department of Homeland Security associated with providing the credential or performing the background record checks;

3(2) the Secretary shall charge fees in amounts that are reasonably related to the costs of providing services in connection with the activity or item for which the fee is charged;

4(3) a fee may not be collected except to the extent such fee will be expended to pay for the costs of conducting or obtaining a criminal history record check and a review of available law enforcement databases and commercial databases and records of other governmental and international agencies; reviewing and adjudicating requests for waiver and appeals of agency decisions with respect to providing the credential, performing the background record check, and denying requests for waiver and appeals; and any other costs related to providing the credential or performing the background record check; and

5(4) any fee collected shall be available for expenditure only to pay the costs incurred in providing services in connection with the activity or item for which the fee is charged and shall remain available until expended.

6Notwithstanding section 44939(e) of title 49, the Secretary shall establish a process to ensure that an alien (as defined in section 101(a)(3) of the Immigration and Nationality Act (8 U.S.C. 1101(a)(3)) applying for recurrent training in the operation of any aircraft is properly identified and has not, since the time of any prior threat assessment conducted pursuant to section 44939(a) of such title, become a risk to aviation or national security.

7If the Secretary determines, in carrying out the process established under paragraph (1), that an alien is a present risk to aviation or national security, the Secretary shall immediately notify the person providing the training of the determination and that person shall not provide the training or if such training has commenced that person shall immediately terminate the training.

8The Secretary may charge reasonable fees under subsection (a) for providing credentialing and background investigations for aliens in connection with the process for recurrent training established under paragraph (1). Such fees shall be promulgated by notice in the Federal Register.

469a.

Collection of fees from non-Federal participants in meetings

1For fiscal year 2010 and thereafter, the Secretary of Homeland Security may collect fees from any non-Federal participant in a conference, seminar, exhibition, symposium, or similar meeting conducted by the Department of Homeland Security in advance of the conference, either directly or by contract, and those fees shall be credited to the appropriation or account from which the costs of the conference, seminar, exhibition, symposium, or similar meeting are paid and shall be available to pay the costs of the Department of Homeland Security with respect to the conference or to reimburse the Department for costs incurred with respect to the conference: Provided, That in the event the total amount of fees collected with respect to a conference exceeds the actual costs of the Department of Homeland Security with respect to the conference, the amount of such excess shall be deposited into the Treasury as miscellaneous receipts: Provided further, That the Secretary shall provide a report to the Committees on Appropriations of the Senate and the House of Representatives not later than January 5, 2011, providing the level of collections and a summary by agency of the purposes and levels of expenditures for the prior fiscal year,.1

470.

Disclosures regarding homeland security grants

1In this section:

2The term "homeland security grant" means any grant made or administered by the Department, including—

3(A) the State Homeland Security Grant Program;

4(B) the Urban Area Security Initiative Grant Program;

5(C) the Law Enforcement Terrorism Prevention Program;

6(D) the Citizen Corps; and

7(E) the Metropolitan Medical Response System.

8The term "local government" has the meaning given the term in section 101 of this title.

9Each State or local government that receives a homeland security grant shall, not later than 12 months after the later of October 13, 2006, and the date of receipt of such grant, and every 12 months thereafter until all funds provided under such grant are expended, submit a report to the Secretary that contains a list of all expenditures made by such State or local government using funds from such grant.

471.

Annual ammunition report

1(a) The Secretary of Homeland Security shall submit to Congress, 180 days after January 17, 2014, and annually thereafter beginning with the submission of the President's budget proposal for fiscal year 2016 pursuant to section 1105(a) of title 31, a comprehensive report on the purchase and usage of ammunition, subdivided by ammunition type. The report shall include—

2(1) the quantity of ammunition in inventory at the end of the preceding calendar year, and the amount of ammunition expended and purchased, subdivided by ammunition type, during the year for each relevant component or agency in the Department of Homeland Security;

3(2) a description of how such quantity, usage, and purchase aligns to each component or agency's mission requirements for certification, qualification, training, and operations; and

4(3) details on all contracting practices applied by the Department of Homeland Security, including comparative details regarding other contracting options with respect to cost and availability.

5(b) The reports required by subsection (a) shall be submitted in an appropriate format in order to ensure the safety of law enforcement personnel.

472.

Annual weaponry report

1(a) The Secretary of Homeland Security shall submit to the Congress, not later than 180 days after March 4, 2015, and annually thereafter, beginning at the time the President's budget proposal for fiscal year 2017 is submitted pursuant to section 1105(a) of title 31, a comprehensive report on the purchase and usage of weapons, subdivided by weapon type. The report shall include—

2(1) the quantity of weapons in inventory at the end of the preceding calendar year, and the amount of weapons, subdivided by weapon type, included in the budget request for each relevant component or agency in the Department of Homeland Security;

3(2) a description of how such quantity and purchase aligns to each component or agency's mission requirements for certification, qualification, training, and operations; and

4(3) details on all contracting practices applied by the Department of Homeland Security, including comparative details regarding other contracting options with respect to cost and availability.

5(b) The reports required by subsection (a) shall be submitted in an appropriate format in order to ensure the safety of law enforcement personnel.

473.

Cyber Crimes Center, Child Exploitation Investigations Unit, Computer Forensics Unit, and Cyber Crimes Unit

1The Secretary shall operate, within United States Immigration and Customs Enforcement, Homeland Security Investigations, a Cyber Crimes Center (referred to in this section as the "Center").

2The Center shall provide investigative assistance, training, and equipment to support domestic and international investigations of cyber-related crimes by the Department.

3The Secretary shall operate, within the Center, a Child Exploitation Investigations Unit (referred to in this subsection as the "CEIU").

4The CEIU—

5(A) shall coordinate all United States Immigration and Customs Enforcement child exploitation initiatives, including investigations into—

6(i) child exploitation;

7(ii) child pornography;

8(iii) child victim identification;

9(iv) traveling child sex offenders; and

10(v) forced child labor, including the sexual exploitation of minors;

11(B) shall, among other things, focus on—

12(i) child exploitation prevention;

13(ii) investigative capacity building;

14(iii) enforcement operations; and

15(iv) training for Federal, State, local, tribal, and foreign law enforcement agency personnel, upon request;

16(C) shall provide training, technical expertise, support, or coordination of child exploitation investigations, as needed, to cooperating law enforcement agencies and personnel, which shall include participating in training for Homeland Security Investigations personnel conducted by Internet Crimes Against Children Task Forces;

17(D) shall provide psychological support and counseling services for United States Immigration and Customs Enforcement personnel engaged in child exploitation prevention initiatives, including making available other existing services to assist employees who are exposed to child exploitation material during investigations;

18(E) is authorized to collaborate with the Department of Defense and the National Association to Protect Children for the purpose of the recruiting, training, equipping and hiring of wounded, ill, and injured veterans and transitioning service members, through the Human Exploitation Rescue Operative (HERO) Child Rescue Corps program 1; and

19(F) shall collaborate with other governmental, nongovernmental, and nonprofit entities approved by the Secretary for the sponsorship of, and participation in, outreach and training activities.

20The CEIU shall collect and maintain data concerning—

21(A) the total number of suspects identified by United States Immigration and Customs Enforcement;

22(B) the number of arrests by United States Immigration and Customs Enforcement in child exploitation investigations, disaggregated by type, including—

23(i) the number of child victims identified through investigations carried out by United States Immigration and Customs Enforcement; and

24(ii) the number of suspects arrested who were in positions of trust or authority over children;

25(C) the number of child exploitation cases opened for investigation by United States Immigration and Customs Enforcement; and

26(D) the number of child exploitation cases resulting in a Federal, State, foreign, or military prosecution.

27In addition to submitting the reports required under paragraph (7), the CEIU shall make the data collected and maintained under paragraph (3) available to the committees of Congress described in paragraph (7).

28The CEIU is authorized to enter into cooperative agreements to accomplish the functions set forth in paragraphs (2) and (3).

29The Secretary is authorized to accept monies and in-kind donations from the Virtual Global Taskforce, national laboratories, Federal agencies, not-for-profit organizations, and educational institutions to create and expand public awareness campaigns in support of the functions of the CEIU.

30Gifts authorized under subparagraph (A) shall not be subject to the Federal Acquisition Regulation for competition when the services provided by the entities referred to in such subparagraph are donated or of minimal cost to the Department.

31Not later than 1 year after May 29, 2015, and annually for the following 4 years, the CEIU shall—

32(A) submit a report containing a summary of the data collected pursuant to paragraph (3) during the previous year to—

33(i) the Committee on Homeland Security and Governmental Affairs of the Senate;

34(ii) the Committee on the Judiciary of the Senate;

35(iii) the Committee on Appropriations of the Senate;

36(iv) the Committee on Homeland Security of the House of Representatives;

37(v) the Committee on the Judiciary of the House of Representatives; and

38(vi) the Committee on Appropriations of the House of Representatives; and

39(B) make a copy of each report submitted under subparagraph (A) publicly available on the website of the Department.

40The Secretary shall operate, within the Center, a Computer Forensics Unit (referred to in this subsection as the "CFU").

41The CFU—

42(A) shall provide training and technical support in digital forensics and administer the Digital Forensics and Document and Media Exploitation program to—

43(i) United States Immigration and Customs Enforcement personnel; and

44(ii) Federal, State, local, tribal, military, and foreign law enforcement agency personnel engaged in the investigation of crimes within their respective jurisdictions, upon request and subject to the availability of funds;

45(B) shall provide computer hardware, software, and forensic licenses for all computer forensics personnel within United States Immigration and Customs Enforcement;

46(C) shall participate in research and development in the area of digital forensics and emerging technologies, in coordination with appropriate components of the Department; and

47(D) is authorized to collaborate with the Department of Defense, the National Association to Protect Children, and other governmental entities for the purpose of recruiting, training, equipping, and hiring wounded, ill, and injured veterans and transitioning service members, through the Human Exploitation Rescue Operative (HERO) Child Rescue Corps program 1.

48The CFU is authorized to enter into cooperative agreements to accomplish the functions set forth in paragraph (2).

49The Secretary is authorized to accept monies and in-kind donations from the Virtual Global Task Force, national laboratories, Federal agencies, not-for-profit organizations, and educational institutions to create and expand public awareness campaigns in support of the functions of the CFU.

50Gifts authorized under subparagraph (A) shall not be subject to the Federal Acquisition Regulation for competition when the services provided by the entities referred to in such subparagraph are donated or of minimal cost to the Department.

51The Secretary shall operate, within the Center, a Cyber Crimes Unit (referred to in this subsection as the "CCU").

52The CCU—

53(A) shall oversee the cyber security strategy and cyber-related operations and programs for United States Immigration and Customs Enforcement;

54(B) shall enhance United States Immigration and Customs Enforcement's ability to combat criminal enterprises operating on or through the Internet, with specific focus in the areas of—

55(i) cyber economic crime;

56(ii) digital theft of intellectual property;

57(iii) illicit e-commerce (including hidden marketplaces);

58(iv) Internet-facilitated proliferation of arms and strategic technology; and

59(v) cyber-enabled smuggling and money laundering;

60(C) shall provide training and technical support in cyber investigations to—

61(i) United States Immigration and Customs Enforcement personnel; and

62(ii) Federal, State, local, tribal, military, and foreign law enforcement agency personnel engaged in the investigation of crimes within their respective jurisdictions, upon request and subject to the availability of funds;

63(D) shall participate in research and development in the area of cyber investigations, in coordination with appropriate components of the Department; and

64(E) is authorized to recruit participants of the Human Exploitation Rescue Operative (HERO) Child Rescue Corps program 1 for investigative and forensic positions in support of the functions of the CCU.

65The CCU is authorized to enter into cooperative agreements to accomplish the functions set forth in paragraph (2).

66There is established within the Center a Human Exploitation Rescue Operation 3 Child-Rescue Corps Program (referred to in this section as the "HERO Child-Rescue Corps Program"), which shall be a Department-wide program, in collaboration with the Department of Defense and the National Association to Protect Children.

67As part of the HERO Child-Rescue Corps Program, the National Association to Protect Children shall provide logistical support for program participants.

68The purpose of the HERO Child-Rescue Corps Program shall be to recruit, train, equip, and employ members of the Armed Forces on active duty and wounded, ill, and injured veterans to combat and prevent child exploitation, including in investigative, intelligence, analyst, inspection, and forensic positions or any other positions determined appropriate by the employing agency.

69The HERO Child-Rescue Program shall—

70(A) provide, recruit, train, and equip participants of the Program in the areas of digital forensics, investigation, analysis, intelligence, and victim identification, as determined by the Center and the needs of the Department; and

71(B) ensure that during the internship period, participants of the Program are assigned to investigate and analyze—

72(i) child exploitation;

73(ii) child pornography;

74(iii) unidentified child victims;

75(iv) human trafficking;

76(v) traveling child sex offenders; and

77(vi) forced child labor, including the sexual exploitation of minors.

78The Secretary shall establish a paid internship and hiring program for the purpose of placing participants of the HERO Child-Rescue Corps Program (in this subsection referred to as "participants") into paid internship positions, for the subsequent appointment of the participants to permanent positions, as described in the guidelines promulgated under paragraph (3).

79Under the paid internship and hiring program required to be established under paragraph (1), the Secretary shall assign or detail participants to positions within United States Immigration and Customs Enforcement or any other Federal agency in accordance with the guidelines promulgated under paragraph (3).

80The Secretary shall promulgate guidelines for assigning or detailing participants to positions within United States Immigration and Customs Enforcement and other Federal agencies, which shall include requirements for internship duties and agreements regarding the subsequent appointment of the participants to permanent positions.

81The Secretary shall give a preference to Homeland Security Investigations in assignments or details under the guidelines promulgated under subparagraph (A).

82An appointment to an internship position under this subsection shall be for a term not to exceed 12 months.

83After completion of initial group training and upon beginning work at an assigned office, a participant appointed to an internship position under this subsection who is not receiving monthly basic pay as a member of the Armed Forces on active duty shall receive compensation at a rate that is—

84(A) not less than the minimum rate of basic pay payable for a position at level GS–5 of the General Schedule; and

85(B) not more than the maximum rate of basic pay payable for a position at level GS–7 of the General Schedule.

86In establishing the paid internship and hiring program required under paragraph (1), the Secretary shall ensure that the eligibility requirements for participation in the internship program are the same as the eligibility requirements for participation in the HERO Child-Rescue Corps Program.

87The Secretary shall establish within Homeland Security Investigations positions, which shall be in addition to any positions in existence on December 21, 2019, for the hiring and permanent employment of graduates of the paid internship program required to be established under paragraph (1).

88There are authorized to be appropriated to the Secretary such sums as are necessary to carry out this section.

89Of the amount made available pursuant to paragraph (1) in each of fiscal years 2022 through 2027, not more than $10,000,000 shall be used to carry out subsection (e) and not less than $2,000,000 shall be used to carry out subsection (f).

474.

Homeland security critical domain research and development

1The Secretary is authorized to conduct research and development to—

2(A) identify United States critical domains for economic security and homeland security; and

3(B) evaluate the extent to which disruption, corruption, exploitation, or dysfunction of any of such domain poses a substantial threat to homeland security.

4The research under paragraph (1) shall include a risk analysis of each identified United States critical domain for economic security to determine the degree to which there exists a present or future threat to homeland security in the event of disruption, corruption, exploitation, or dysfunction to such domain. Such research shall consider, to the extent possible, the following:

5(i) The vulnerability and resilience of relevant supply chains.

6(ii) Foreign production, processing, and manufacturing methods.

7(iii) Influence of malign economic actors.

8(iv) Asset ownership.

9(v) Relationships within the supply chains of such domains.

10(vi) The degree to which the conditions referred to in clauses (i) through (v) would place such a domain at risk of disruption, corruption, exploitation, or dysfunction.

11Based on the identification and risk analysis of United States critical domains for economic security pursuant to paragraph (1) and subparagraph (A) of this paragraph, respectively, the Secretary may conduct additional research into those critical domains, or specific elements thereof, with respect to which there exists the highest degree of a present or future threat to homeland security in the event of disruption, corruption, exploitation, or dysfunction to such a domain. For each such high-risk domain, or element thereof, such research shall—

12(i) describe the underlying infrastructure and processes;

13(ii) analyze present and projected performance of industries that comprise or support such domain;

14(iii) examine the extent to which the supply chain of a product or service necessary to such domain is concentrated, either through a small number of sources, or if multiple sources are concentrated in one geographic area;

15(iv) examine the extent to which the demand for supplies of goods and services of such industries can be fulfilled by present and projected performance of other industries, identify strategies, plans, and potential barriers to expand the supplier industrial base, and identify the barriers to the participation of such other industries;

16(v) consider each such domain's performance capacities in stable economic environments, adversarial supply conditions, and under crisis economic constraints;

17(vi) identify and define needs and requirements to establish supply resiliency within each such domain; and

18(vii) consider the effects of sector consolidation, including foreign consolidation, either through mergers or acquisitions, or due to recent geographic realignment, on such industries' performances.

19In conducting the research under paragraph (1) and subparagraph (B) of paragraph (2), the Secretary may consult with appropriate Federal agencies, State agencies, and private sector stakeholders.

20Beginning one year after December 27, 2021, the Secretary shall publish a report containing information relating to the research under paragraph (1) and subparagraph (B) of paragraph (2), including findings, evidence, analysis, and recommendations. Such report shall be updated annually through 2026.

21Not later than 90 days after the publication of each report required under paragraph (4) of subsection (a), the Secretary shall transmit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate each such report, together with a description of actions the Secretary, in consultation with appropriate Federal agencies, will undertake or has undertaken in response to each such report.

22In this section:

23The term "United States critical domains for economic security" means the critical infrastructure and other associated industries, technologies, and intellectual property, or any combination thereof, that are essential to the economic security of the United States.

24The term "economic security" means the condition of having secure and resilient domestic production capacity, combined with reliable access to the global resources necessary to maintain an acceptable standard of living and to protect core national values.

25There is authorized to be appropriated $1,000,000 for each of fiscal years 2022 through 2026 to carry out this section.

475.

Transnational Criminal Investigative Units

1The Secretary, with the concurrence of the Secretary of State, shall operate Transnational Criminal Investigative Units within Homeland Security Investigations.

2Each Transnational Criminal Investigative Unit shall be composed of trained foreign law enforcement officials who shall collaborate with Homeland Security Investigations to investigate and prosecute individuals involved in transnational criminal activity.

3Before entry into a Transnational Criminal Investigative Unit, and at periodic intervals while serving in such a unit, foreign law enforcement officials shall be required to pass certain security evaluations, which may include a background check, a polygraph examination, a urinalysis test, or other measures that the Secretary determines to be appropriate.

4No member of a foreign law enforcement unit may join a Transnational Criminal Investigative Unit if the Secretary, in coordination with the Secretary of State, has credible information that such foreign law enforcement unit has committed a gross violation of human rights, consistent with the limitations set forth in section 2378d of title 22.

5The establishment and continued support of the Transnational Criminal Investigative Units who are assigned under paragraph (1)—

6(A) shall be performed with the approval of the chief of mission to the foreign country to which the personnel are assigned;

7(B) shall be consistent with the duties and powers of the Secretary of State and the chief of mission for a foreign country under section 4802 of title 22 and section 3927 of title 22, respectively; and

8(C) shall not be established without the concurrence of the Assistant Secretary of State for International Narcotics and Law Enforcement Affairs.

9The Executive Associate Director of Homeland Security Investigations shall submit a report to the Committee on Foreign Relations of the Senate, the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on the Judiciary of the Senate, the Committee on Foreign Affairs of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the Committee on the Judiciary of the House of Representatives that describes—

10(A) the procedures used for vetting Transnational Criminal Investigative Unit members to include compliance with the vetting required under this subsection; and

11(B) any additional measures that should be implemented to prevent personnel in vetted units from being compromised by criminal organizations.

12The Executive Associate Director of Homeland Security Investigations is authorized to pay vetted members of a Transnational Criminal Investigative Unit a monetary stipend in an amount associated with their duties dedicated to unit activities.

13The Executive Associate Director of Homeland Security Investigations, during the 5-year period beginning on December 23, 2022, shall provide an annual unclassified briefing to the congressional committees referred to in subsection (c)(4), which may include a classified session, if necessary, that identifies—

14(1) the number of vetted members of Transnational Criminal Investigative Unit in each country;

15(2) the amount paid in stipends to such members, disaggregated by country;

16(3) relevant enforcement statistics, such as arrests and progress made on joint investigations, in each such country; and

17(4) whether any vetted members of the Transnational Criminal Investigative Unit in each country were involved in any unlawful activity, including human rights abuses or significant acts of corruption.

475a.

Mentor-protégé program

1There is established in the Department a mentor-protégé program (in this section referred to as the "Program") under which a mentor firm enters into an agreement with a protégé firm for the purpose of assisting the protégé firm to compete for prime contracts and subcontracts of the Department.

2The Secretary shall establish criteria for mentor firms and protégé firms to be eligible to participate in the Program, including a requirement that a firm is not included on any list maintained by the Federal Government of contractors that have been suspended or debarred.

3The Secretary, acting through the Office of Small and Disadvantaged Business Utilization of the Department, shall establish a process for submission of an application jointly by a mentor firm and the protégé firm selected by the mentor firm. The application shall include each of the following:

4(A) A description of the assistance to be provided by the mentor firm, including, to the extent available, the number and a brief description of each anticipated subcontract to be awarded to the protégé firm.

5(B) A schedule with milestones for achieving the assistance to be provided over the period of participation in the Program.

6(C) An estimate of the costs to be incurred by the mentor firm for providing assistance under the Program.

7(D) Attestations that Program participants will submit to the Secretary reports at times specified by the Secretary to assist the Secretary in evaluating the protégé firm's developmental progress.

8(E) Attestations that Program participants will inform the Secretary in the event of a change in eligibility or voluntary withdrawal from the Program.

9Not later than 60 days after receipt of an application pursuant to paragraph (1), the head of the Office of Small and Disadvantaged Business Utilization shall notify applicants of approval or, in the case of disapproval, the process for resubmitting an application for reconsideration.

10The head of the Office of Small and Disadvantaged Business Utilization may rescind the approval of an application under this subsection if it determines that such action is in the best interest of the Department.

11A mentor firm and protégé firm approved under subsection (c) shall enter into an agreement to participate in the Program for a period of not less than 36 months.

12A mentor firm and protégé firm that enter into an agreement under subsection (d) may receive the following Program benefits:

13(1) With respect to an award of a contract that requires a subcontracting plan, a mentor firm may receive evaluation credit for participating in the Program.

14(2) With respect to an award of a contract that requires a subcontracting plan, a mentor firm may receive credit for a protégé firm performing as a first tier subcontractor or a subcontractor at any tier in an amount equal to the total dollar value of any subcontracts awarded to such protégé firm.

15(3) A protégé firm may receive technical, managerial, financial, or any other mutually agreed upon benefit from a mentor firm, including a subcontract award.

16Not later than one year after December 23, 2022, and annually thereafter, the head of the Office of Small and Disadvantaged Business Utilization shall submit to the Committee on Homeland Security and Governmental Affairs and the Committee on Small Business and Entrepreneurship of the Senate and the Committee on Homeland Security and the Committee on Small Business of the House of Representatives a report that—

17(1) identifies each agreement between a mentor firm and a protégé firm entered into under this section, including the number of protégé firm participants that are—

18(A) small business concerns;

19(B) small business concerns owned and controlled by veterans;

20(C) small business concerns owned and controlled by service-disabled veterans;

21(D) qualified HUBZone small business concerns;

22(E) small business concerns owned and controlled by socially and economically disadvantaged individuals;

23(F) small business concerns owned and controlled by women;

24(G) historically Black colleges and universities; and

25(H) minority-serving institutions;

26(2) describes the type of assistance provided by mentor firms to protégé firms;

27(3) identifies contracts within the Department in which a mentor firm serving as the prime contractor provided subcontracts to a protégé firm under the Program; and

28(4) assesses the degree to which there has been—

29(A) an increase in the technical capabilities of protégé firms; and

30(B) an increase in the quantity and estimated value of prime contract and subcontract awards to protégé firms for the period covered by the report.

31Nothing in this section may be construed to limit, diminish, impair, or otherwise affect the authority of the Department to participate in any program carried out by or requiring approval of the Small Business Administration or adopt or follow any regulation or policy that the Administrator of the Small Business Administration may promulgate, except that, to the extent that any provision of this section (including subsection (h)) conflicts with any other provision of law, regulation, or policy, this section shall control.

32In this section:

33The term "historically Black college or university" has the meaning given the term "part B institution" in section 1061 of title 20.

34The term "mentor firm" means a for-profit business concern that is not a small business concern that—

35(A) has the ability to assist and commits to assisting a protégé to compete for Federal prime contracts and subcontracts; and

36(B) satisfies any other requirements imposed by the Secretary.

37The term "minority-serving institution" means an institution of higher education described in section 1067q(a) of title 20.1

38The term "protégé firm" means a small business concern, a historically Black college or university, or a minority-serving institution that—

39(A) is eligible to enter into a prime contract or subcontract with the Department; and

40(B) satisfies any other requirements imposed by the Secretary.

41The terms "small business concern", "small business concern owned and controlled by veterans", "small business concern owned and controlled by service-disabled veterans", "qualified HUBZone small business concern", "and small 2 business concern owned and controlled by women" have the meanings given such terms, respectively, under section 632 of title 15. The term "small business concern owned and controlled by socially and economically disadvantaged individuals" has the meaning given such term in section 637(d)(3)(C) of title 15.

481.

Short title; findings; and sense of Congress

1This part may be cited as the "Homeland Security Information Sharing Act".

2Congress finds the following:

3(1) The Federal Government is required by the Constitution to provide for the common defense, which includes terrorist attack.

4(2) The Federal Government relies on State and local personnel to protect against terrorist attack.

5(3) The Federal Government collects, creates, manages, and protects classified and sensitive but unclassified information to enhance homeland security.

6(4) Some homeland security information is needed by the State and local personnel to prevent and prepare for terrorist attack.

7(5) The needs of State and local personnel to have access to relevant homeland security information to combat terrorism must be reconciled with the need to preserve the protected status of such information and to protect the sources and methods used to acquire such information.

8(6) Granting security clearances to certain State and local personnel is one way to facilitate the sharing of information regarding specific terrorist threats among Federal, State, and local levels of government.

9(7) Methods exist to declassify, redact, or otherwise adapt classified information so it may be shared with State and local personnel without the need for granting additional security clearances.

10(8) State and local personnel have capabilities and opportunities to gather information on suspicious activities and terrorist threats not possessed by Federal agencies.

11(9) The Federal Government and State and local governments and agencies in other jurisdictions may benefit from such information.

12(10) Federal, State, and local governments and intelligence, law enforcement, and other emergency preparation and response agencies must act in partnership to maximize the benefits of information gathering and analysis to prevent and respond to terrorist attacks.

13(11) Information systems, including the National Law Enforcement Telecommunications System and the Terrorist Threat Warning System, have been established for rapid sharing of classified and sensitive but unclassified information among Federal, State, and local entities.

14(12) Increased efforts to share homeland security information should avoid duplicating existing information systems.

15It is the sense of Congress that Federal, State, and local entities should share homeland security information to the maximum extent practicable, with special emphasis on hard-to-reach urban and rural communities.

482.

Facilitating homeland security information sharing procedures

1(1) The President shall prescribe and implement procedures under which relevant Federal agencies—

2(A) share relevant and appropriate homeland security information with other Federal agencies, including the Department, and appropriate State and local personnel;

3(B) identify and safeguard homeland security information that is sensitive but unclassified; and

4(C) to the extent such information is in classified form, determine whether, how, and to what extent to remove classified information, as appropriate, and with which such personnel it may be shared after such information is removed.

5(2) The President shall ensure that such procedures apply to all agencies of the Federal Government.

6(3) Such procedures shall not change the substantive requirements for the classification and safeguarding of classified information.

7(4) Such procedures shall not change the requirements and authorities to protect sources and methods.

8(1) Under procedures prescribed by the President, all appropriate agencies, including the intelligence community, shall, through information sharing systems, share homeland security information with Federal agencies and appropriate State and local personnel to the extent such information may be shared, as determined in accordance with subsection (a), together with assessments of the credibility of such information.

9(2) Each information sharing system through which information is shared under paragraph (1) shall—

10(A) have the capability to transmit unclassified or classified information, though the procedures and recipients for each capability may differ;

11(B) have the capability to restrict delivery of information to specified subgroups by geographic location, type of organization, position of a recipient within an organization, or a recipient's need to know such information;

12(C) be configured to allow the efficient and effective sharing of information; and

13(D) be accessible to appropriate State and local personnel.

14(3) The procedures prescribed under paragraph (1) shall establish conditions on the use of information shared under paragraph (1)—

15(A) to limit the redissemination of such information to ensure that such information is not used for an unauthorized purpose;

16(B) to ensure the security and confidentiality of such information;

17(C) to protect the constitutional and statutory rights of any individuals who are subjects of such information; and

18(D) to provide data integrity through the timely removal and destruction of obsolete or erroneous names and information.

19(4) The procedures prescribed under paragraph (1) shall ensure, to the greatest extent practicable, that the information sharing system through which information is shared under such paragraph include existing information sharing systems, including, but not limited to, the National Law Enforcement Telecommunications System, the Regional Information Sharing System, and the Terrorist Threat Warning System of the Federal Bureau of Investigation.

20(5) Each appropriate Federal agency, as determined by the President, shall have access to each information sharing system through which information is shared under paragraph (1), and shall therefore have access to all information, as appropriate, shared under such paragraph.

21(6) The procedures prescribed under paragraph (1) shall ensure that appropriate State and local personnel are authorized to use such information sharing systems—

22(A) to access information shared with such personnel; and

23(B) to share, with others who have access to such information sharing systems, the homeland security information of their own jurisdictions, which shall be marked appropriately as pertaining to potential terrorist activity.

24(7) Under procedures prescribed jointly by the Director of Central Intelligence and the Attorney General, each appropriate Federal agency, as determined by the President, shall review and assess the information shared under paragraph (6) and integrate such information with existing intelligence.

25(1) The President shall prescribe procedures under which Federal agencies may, to the extent the President considers necessary, share with appropriate State and local personnel homeland security information that remains classified or otherwise protected after the determinations prescribed under the procedures set forth in subsection (a).

26(2) It is the sense of Congress that such procedures may include 1 or more of the following means:

27(A) Carrying out security clearance investigations with respect to appropriate State and local personnel.

28(B) With respect to information that is sensitive but unclassified, entering into nondisclosure agreements with appropriate State and local personnel.

29(C) Increased use of information-sharing partnerships that include appropriate State and local personnel, such as the Joint Terrorism Task Forces of the Federal Bureau of Investigation, the Anti-Terrorism Task Forces of the Department of Justice, and regional Terrorism Early Warning Groups.

30(3)(A) The Secretary shall establish a program to provide appropriate training to officials described in subparagraph (B) in order to assist such officials in—

31(i) identifying sources of potential terrorist threats through such methods as the Secretary determines appropriate;

32(ii) reporting information relating to such potential terrorist threats to the appropriate Federal agencies in the appropriate form and manner;

33(iii) assuring that all reported information is systematically submitted to and passed on by the Department for use by appropriate Federal agencies; and

34(iv) understanding the mission and roles of the intelligence community to promote more effective information sharing among Federal, State, and local officials and representatives of the private sector to prevent terrorist attacks against the United States.

35(B) The officials referred to in subparagraph (A) are officials of State and local government agencies and representatives of private sector entities with responsibilities relating to the oversight and management of first responders, counterterrorism activities, or critical infrastructure.

36(C) The Secretary shall consult with the Attorney General to ensure that the training program established in subparagraph (A) does not duplicate the training program established in section 908 of the USA PATRIOT Act (Public Law 107–56; 28 U.S.C. 509 note).

37(D) The Secretary shall carry out this paragraph in consultation with the Director of Central Intelligence and the Attorney General.

38For each affected Federal agency, the head of such agency shall designate an official to administer this chapter with respect to such agency.

39Under procedures prescribed under this section, information obtained by a State or local government from a Federal agency under this section shall remain under the control of the Federal agency, and a State or local law authorizing or requiring such a government to disclose information shall not apply to such information.

40As used in this section:

41(1) The term "homeland security information" means any information possessed by a Federal, State, or local agency that—

42(A) relates to the threat of terrorist activity;

43(B) relates to the ability to prevent, interdict, or disrupt terrorist activity;

44(C) would improve the identification or investigation of a suspected terrorist or terrorist organization; or

45(D) would improve the response to a terrorist act.

46(2) The term "intelligence community" has the meaning given such term in section 3003(4) of title 50.

47(3) The term "State and local personnel" means any of the following persons involved in prevention, preparation, or response for terrorist attack:

48(A) State Governors, mayors, and other locally elected officials.

49(B) State and local law enforcement personnel and firefighters.

50(C) Public health and medical professionals.

51(D) Regional, State, and local emergency management agency personnel, including State adjutant generals.

52(E) Other appropriate emergency response agency personnel.

53(F) Employees of private-sector entities that affect critical infrastructure, cyber, economic, or public health security, as designated by the Federal Government in procedures developed pursuant to this section.

54(4) The term "State" includes the District of Columbia and any commonwealth, territory, or possession of the United States.

55Nothing in this chapter shall be construed as authorizing any department, bureau, agency, officer, or employee of the Federal Government to request, receive, or transmit to any other Government entity or personnel, or transmit to any State or local entity or personnel otherwise authorized by this chapter to receive homeland security information, any information collected by the Federal Government solely for statistical purposes in violation of any other provision of law relating to the confidentiality of such information.

483.

Report

1Not later than 12 months after November 25, 2002, the President shall submit to the congressional committees specified in subsection (b) a report on the implementation of section 482 of this title. The report shall include any recommendations for additional measures or appropriation requests, beyond the requirements of section 482 of this title, to increase the effectiveness of sharing of information between and among Federal, State, and local entities.

2The congressional committees referred to in subsection (a) are the following committees:

3(1) The Permanent Select Committee on Intelligence and the Committee on the Judiciary of the House of Representatives.

4(2) The Select Committee on Intelligence and the Committee on the Judiciary of the Senate.

484.

Authorization of appropriations

1There are authorized to be appropriated such sums as may be necessary to carry out section 482 of this title.

484a.

Reciprocal information sharing

1Acting in accordance with a bilateral or multilateral arrangement, the Secretary, in the Secretary's discretion and on the basis of reciprocity, may provide information from the National Sex Offender Registry relating to a conviction for a sex offense against a minor (as such terms are defined in section 20911 of title 34) to a foreign government upon the request of the foreign government, and may receive comparable information from the foreign government.

485.

Information sharing

1In this section:

2The term "homeland security information" has the meaning given that term in section 482(f) of this title.

3The term "Information Sharing Council" means the Information Systems Council established by Executive Order 13356, or any successor body designated by the President, and referred to under subsection (g).

4The terms "information sharing environment" and "ISE" mean an approach that facilitates the sharing of terrorism and homeland security information, which may include any method determined necessary and appropriate for carrying out this section.

5The term "program manager" means the program manager designated under subsection (f).

6The term "terrorism information"—

7(A) means all information, whether collected, produced, or distributed by intelligence, law enforcement, military, homeland security, or other activities relating to—

8(i) the existence, organization, capabilities, plans, intentions, vulnerabilities, means of finance or material support, or activities of foreign or international terrorist groups or individuals, or of domestic groups or individuals involved in transnational terrorism;

9(ii) threats posed by such groups or individuals to the United States, United States persons, or United States interests, or to those of other nations;

10(iii) communications of or by such groups or individuals; or

11(iv) groups or individuals reasonably believed to be assisting or associated with such groups or individuals; and

12(B) includes weapons of mass destruction information.

13The term "weapons of mass destruction information" means information that could reasonably be expected to assist in the development, proliferation, or use of a weapon of mass destruction (including a chemical, biological, radiological, or nuclear weapon) that could be used by a terrorist or a terrorist organization against the United States, including information about the location of any stockpile of nuclear materials that could be exploited for use in such a weapon that could be used by a terrorist or a terrorist organization against the United States.

14The President shall—

15(A) create an information sharing environment for the sharing of terrorism information in a manner consistent with national security and with applicable legal standards relating to privacy and civil liberties;

16(B) designate the organizational and management structures that will be used to operate and manage the ISE; and

17(C) determine and enforce the policies, directives, and rules that will govern the content and usage of the ISE.

18The President shall, through the structures described in subparagraphs (B) and (C) of paragraph (1), ensure that the ISE provides and facilitates the means for sharing terrorism information among all appropriate Federal, State, local, and tribal entities, and the private sector through the use of policy guidelines and technologies. The President shall, to the greatest extent practicable, ensure that the ISE provides the functional equivalent of, or otherwise supports, a decentralized, distributed, and coordinated environment that—

19(A) connects existing systems, where appropriate, provides no single points of failure, and allows users to share information among agencies, between levels of government, and, as appropriate, with the private sector;

20(B) ensures direct and continuous online electronic access to information;

21(C) facilitates the availability of information in a form and manner that facilitates its use in analysis, investigations and operations;

22(D) builds upon existing systems capabilities currently in use across the Government;

23(E) employs an information access management approach that controls access to data rather than just systems and networks, without sacrificing security;

24(F) facilitates the sharing of information at and across all levels of security;

25(G) provides directory services, or the functional equivalent, for locating people and information;

26(H) incorporates protections for individuals' privacy and civil liberties;

27(I) incorporates strong mechanisms to enhance accountability and facilitate oversight, including audits, authentication, and access controls;

28(J) integrates the information within the scope of the information sharing environment, including any such information in legacy technologies;

29(K) integrates technologies, including all legacy technologies, through Internet-based services, consistent with appropriate security protocols and safeguards, to enable connectivity among required users at the Federal, State, and local levels;

30(L) allows the full range of analytic and operational activities without the need to centralize information within the scope of the information sharing environment;

31(M) permits analysts to collaborate both independently and in a group (commonly known as "collective and noncollective collaboration"), and across multiple levels of national security information and controlled unclassified information;

32(N) provides a resolution process that enables changes by authorized officials regarding rules and policies for the access, use, and retention of information within the scope of the information sharing environment; and

33(O) incorporates continuous, real-time, and immutable audit capabilities, to the maximum extent practicable.

34Subject to subparagraph (B), the President may delegate responsibility for carrying out this subsection.

35The President may not delegate responsibility for carrying out this subsection to the Director of National Intelligence.

36Not later than 180 days after December 17, 2004, the program manager shall, in consultation with the Information Sharing Council—

37(1) submit to the President and Congress a description of the technological, legal, and policy issues presented by the creation of the ISE, and the way in which these issues will be addressed;

38(2) establish an initial capability to provide electronic directory services, or the functional equivalent, to assist in locating in the Federal Government intelligence and terrorism information and people with relevant knowledge about intelligence and terrorism information; and

39(3) conduct a review of relevant current Federal agency capabilities, databases, and systems for sharing information.

40As soon as possible, but in no event later than 270 days after December 17, 2004, the President shall—

41(1) leverage all ongoing efforts consistent with establishing the ISE and issue guidelines for acquiring, accessing, sharing, and using information, including guidelines to ensure that information is provided in its most shareable form, such as by using tearlines to separate out data from the sources and methods by which the data are obtained;

42(2) in consultation with the Privacy and Civil Liberties Oversight Board established under section 2000ee of title 42, issue guidelines that—

43(A) protect privacy and civil liberties in the development and use of the ISE; and

44(B) shall be made public, unless nondisclosure is clearly necessary to protect national security; and

45(3) require the heads of Federal departments and agencies to promote a culture of information sharing by—

46(A) reducing disincentives to information sharing, including over-classification of information and unnecessary requirements for originator approval, consistent with applicable laws and regulations; and

47(B) providing affirmative incentives for information sharing.

48Not later than one year after December 17, 2004, the President shall, with the assistance of the program manager, submit to Congress a report containing an implementation plan for the ISE. The report shall include the following:

49(1) A description of the functions, capabilities, resources, and conceptual design of the ISE, including standards.

50(2) A description of the impact on enterprise architectures of participating agencies.

51(3) A budget estimate that identifies the incremental costs associated with designing, testing, integrating, deploying, and operating the ISE.

52(4) A project plan for designing, testing, integrating, deploying, and operating the ISE.

53(5) The policies and directives referred to in subsection (b)(1)(C), as well as the metrics and enforcement mechanisms that will be utilized.

54(6) Objective, systemwide performance measures to enable the assessment of progress toward achieving the full implementation of the ISE.

55(7) A description of the training requirements needed to ensure that the ISE will be adequately implemented and properly utilized.

56(8) A description of the means by which privacy and civil liberties will be protected in the design and operation of the ISE.

57(9) The recommendations of the program manager, in consultation with the Information Sharing Council, regarding whether, and under what conditions, the ISE should be expanded to include other intelligence information.

58(10) A delineation of the roles of the Federal departments and agencies that will participate in the ISE, including an identification of the agencies that will deliver the infrastructure needed to operate and manage the ISE (as distinct from individual department or agency components that are part of the ISE), with such delineation of roles to be consistent with—

59(A) the authority of the Director of National Intelligence under this title,1 and the amendments made by this title,1 to set standards for information sharing throughout the intelligence community; and

60(B) the authority of the Secretary of Homeland Security and the Attorney General, and the role of the Department of Homeland Security and the Department of Justice, in coordinating with State, local, and tribal officials and the private sector.

61(11) The recommendations of the program manager, in consultation with the Information Sharing Council, for a future management structure for the ISE, including whether the position of program manager should continue to remain in existence.

62Not later than 120 days after December 17, 2004, with notification to Congress, the President shall designate an individual as the program manager responsible for information sharing across the Federal Government. Beginning on December 20, 2019, each individual designated as the program manager shall be appointed by the Director of National Intelligence. The program manager, in consultation with the head of any affected department or agency, shall have and exercise governmentwide authority over the sharing of information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, by all Federal departments, agencies, and components, irrespective of the Federal department, agency, or component in which the program manager may be administratively located, except as otherwise expressly provided by law.

63The program manager shall, in consultation with the Information Sharing Council—

64(i) plan for and oversee the implementation of, and manage, the ISE;

65(ii) assist in the development of policies, as appropriate, to foster the development and proper operation of the ISE;

66(iii) consistent with the direction and policies issued by the President, the Director of National Intelligence, and the Director of the Office of Management and Budget, issue governmentwide procedures, guidelines, instructions, and functional standards, as appropriate, for the management, development, and proper operation of the ISE;

67(iv) identify and resolve information sharing disputes between Federal departments, agencies, and components; and

68(v) assist, monitor, and assess the implementation of the ISE by Federal departments and agencies to ensure adequate progress, technological consistency and policy compliance; and regularly report the findings to Congress.

69The policies, procedures, guidelines, rules, and standards under subparagraph (A)(ii) shall—

70(i) take into account the varying missions and security requirements of agencies participating in the ISE;

71(ii) address development, implementation, and oversight of technical standards and requirements;

72(iii) take into account ongoing and planned efforts that support development, implementation and management of the ISE;

73(iv) address and facilitate information sharing between and among departments and agencies of the intelligence community, the Department of Defense, the homeland security community and the law enforcement community;

74(v) address and facilitate information sharing between Federal departments and agencies and State, tribal, and local governments;

75(vi) address and facilitate, as appropriate, information sharing between Federal departments and agencies and the private sector;

76(vii) address and facilitate, as appropriate, information sharing between Federal departments and agencies with foreign partners and allies; and

77(viii) ensure the protection of privacy and civil liberties.

78There is established an Information Sharing Council that shall assist the President and the program manager in their duties under this section. The Information Sharing Council shall serve until removed from service or replaced by the President (at the sole discretion of the President) with a successor body.

79In assisting the President and the program manager in their duties under this section, the Information Sharing Council shall—

80(A) advise the President and the program manager in developing policies, procedures, guidelines, roles,2 and standards necessary to establish, implement, and maintain the ISE;

81(B) work to ensure coordination among the Federal departments and agencies participating in the ISE in the establishment, implementation, and maintenance of the ISE;

82(C) identify and, as appropriate, recommend the consolidation and elimination of current programs, systems, and processes used by Federal departments and agencies to share information, and recommend, as appropriate, the redirection of existing resources to support the ISE;

83(D) identify gaps, if any, between existing technologies, programs and systems used by Federal departments and agencies to share information and the parameters of the proposed information sharing environment;

84(E) recommend solutions to address any gaps identified under subparagraph (D);

85(F) recommend means by which the ISE can be extended to allow interchange of information between Federal departments and agencies and appropriate authorities of State and local governments;

86(G) assist the program manager in identifying and resolving information sharing disputes between Federal departments, agencies, and components;

87(H) identify appropriate personnel for assignment to the program manager to support staffing needs identified by the program manager; and

88(I) recommend whether or not, and by which means, the ISE should be expanded so as to allow future expansion encompassing other relevant categories of information.

89In performing its duties, the Information Sharing Council shall consider input from persons and entities outside the Federal Government having significant experience and expertise in policy, technical matters, and operational matters relating to the ISE.

90The Information Sharing Council (including any subsidiary group of the Information Sharing Council) shall not be subject to the requirements of chapter 10 of title 5.

91Upon a request by the Director of National Intelligence, the departments and agencies represented on the Information Sharing Council shall detail to the program manager, on a reimbursable basis, appropriate personnel identified under paragraph (2)(H).

92The head of each department or agency that possesses or uses intelligence or terrorism information, operates a system in the ISE, or otherwise participates (or expects to participate) in the ISE shall—

93(1) ensure full department or agency compliance with information sharing policies, procedures, guidelines, rules, and standards established under subsections (b) and (f);

94(2) ensure the provision of adequate resources for systems and activities supporting operation of and participation in the ISE;

95(3) ensure full department or agency cooperation in the development of the ISE to implement governmentwide information sharing; and

96(4) submit, at the request of the President or the program manager, any reports on the implementation of the requirements of the ISE within such department or agency.

97Not later than 180 days after August 3, 2007, the President shall report to the Committee on Homeland Security and Governmental Affairs of the Senate, the Select Committee on Intelligence of the Senate, the Committee on Homeland Security of the House of Representatives, and the Permanent Select Committee on Intelligence of the House of Representatives on the feasibility of—

98(A) eliminating the use of any marking or process (including "Originator Control") intended to, or having the effect of, restricting the sharing of information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, between and among participants in the information sharing environment, unless the President has—

99(i) specifically exempted categories of information from such elimination; and

100(ii) reported that exemption to the committees of Congress described in the matter preceding this subparagraph; and

101(B) continuing to use Federal agency standards in effect on August 3, 2007, for the collection, sharing, and access to information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, relating to citizens and lawful permanent residents;

102(C) replacing the standards described in subparagraph (B) with a standard that would allow mission-based or threat-based permission to access or share information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, for a particular purpose that the Federal Government, through an appropriate process established in consultation with the Privacy and Civil Liberties Oversight Board established under section 2000ee of title 42, has determined to be lawfully permissible for a particular agency, component, or employee (commonly known as an "authorized use" standard); and

103(D) the use of anonymized data by Federal departments, agencies, or components collecting, possessing, disseminating, or handling information within the scope of the information sharing environment, including homeland security information, terrorism information, and weapons of mass destruction information, in any cases in which—

104(i) the use of such information is reasonably expected to produce results materially equivalent to the use of information that is transferred or stored in a non-anonymized form; and

105(ii) such use is consistent with any mission of that department, agency, or component (including any mission under a Federal statute or directive of the President) that involves the storage, retention, sharing, or exchange of personally identifiable information.

106In this subsection, the term "anonymized data" means data in which the individual to whom the data pertains is not identifiable with reasonable efforts, including information that has been encrypted or hidden through the use of other technology.

107The program manager is authorized to hire not more than 40 full-time employees to assist the program manager in—

108(1) activities associated with the implementation of the information sharing environment, including—

109(A) implementing the requirements under subsection (b)(2); and

110(B) any additional implementation initiatives to enhance and expedite the creation of the information sharing environment; and

111(2) identifying and resolving information sharing disputes between Federal departments, agencies, and components under subsection (f)(2)(A)(iv).

112There is authorized to be appropriated to carry out this section $30,000,000 for each of fiscal years 2008 and 2009.

486.

Limitation of liability

1A person who has completed a security awareness training course approved by or operated under a cooperative agreement with the Department of Homeland Security using funds made available in fiscal year 2006 and thereafter or in any prior appropriations Acts, who is enrolled in a program recognized or acknowledged by an Information Sharing and Analysis Center, and who reports a situation, activity or incident pursuant to that program to an appropriate authority, shall not be liable for damages in any action brought in a Federal or State court which result from any act or omission unless such person is guilty of gross negligence or willful misconduct.

488.

Definitions

1In this part:

2The term "ammonium nitrate" means—

3(A) solid ammonium nitrate that is chiefly the ammonium salt of nitric acid and contains not less than 33 percent nitrogen by weight; and

4(B) any mixture containing a percentage of ammonium nitrate that is equal to or greater than the percentage determined by the Secretary under section 488a(b) of this title.

5The term "ammonium nitrate facility" means any entity that produces, sells or otherwise transfers ownership of, or provides application services for ammonium nitrate.

6The term "ammonium nitrate purchaser" means any person who purchases ammonium nitrate from an ammonium nitrate facility.

488a.

Regulation of the sale and transfer of ammonium nitrate

1The Secretary shall regulate the sale and transfer of ammonium nitrate by an ammonium nitrate facility in accordance with this part to prevent the misappropriation or use of ammonium nitrate in an act of terrorism. Such regulations shall be carried out by the Cybersecurity and Infrastructure Security Agency.

2Not later than 90 days after December 26, 2007, the Secretary, in consultation with the heads of appropriate Federal departments and agencies (including the Secretary of Agriculture), shall, after notice and an opportunity for comment, establish a threshold percentage for ammonium nitrate in a substance.

3The Secretary shall establish a process by which any person that—

4(A) owns an ammonium nitrate facility is required to register with the Department; and

5(B) registers under subparagraph (A) is issued a registration number for purposes of this part.

6Any person applying to register under paragraph (1) shall submit to the Secretary—

7(A) the name, address, and telephone number of each ammonium nitrate facility owned by that person;

8(B) the name of the person designated by that person as the point of contact for each such facility, for purposes of this part; and

9(C) such other information as the Secretary may determine is appropriate.

10The Secretary shall establish a process by which any person that—

11(A) intends to be an ammonium nitrate purchaser is required to register with the Department; and

12(B) registers under subparagraph (A) is issued a registration number for purposes of this part.

13Any person applying to register under paragraph (1) as an ammonium nitrate purchaser shall submit to the Secretary—

14(A) the name, address, and telephone number of the applicant; and

15(B) the intended use of ammonium nitrate to be purchased by the applicant.

16The owner of an ammonium nitrate facility shall—

17(A) maintain a record of each sale or transfer of ammonium nitrate, during the two-year period beginning on the date of that sale or transfer; and

18(B) include in such record the information described in paragraph (2).

19For each sale or transfer of ammonium nitrate, the owner of an ammonium nitrate facility shall—

20(A) record the name, address, telephone number, and registration number issued under subsection (c) or (d) of each person that purchases ammonium nitrate, in a manner prescribed by the Secretary;

21(B) if applicable, record the name, address, and telephone number of an agent acting on behalf of the person described in subparagraph (A), at the point of sale;

22(C) record the date and quantity of ammonium nitrate sold or transferred; and

23(D) verify the identity of the persons described in subparagraphs (A) and (B), as applicable, in accordance with a procedure established by the Secretary.

24In maintaining records in accordance with paragraph (1), the owner of an ammonium nitrate facility shall take reasonable actions to ensure the protection of the information included in such records.

25The Secretary may exempt from this part a person producing, selling, or purchasing ammonium nitrate exclusively for use in the production of an explosive under a license or permit issued under chapter 40 of title 18.

26In carrying out this section, the Secretary shall consult with the Secretary of Agriculture, States, and appropriate private sector entities, to ensure that the access of agricultural producers to ammonium nitrate is not unduly burdened.

27Notwithstanding section 552 of title 5 or the USA PATRIOT ACT (Public Law 107–56; 115 Stat. 272), and except as provided in paragraph (2), the Secretary may not disclose to any person any information obtained under this part.

28The Secretary may disclose any information obtained by the Secretary under this part to—

29(A) an officer or employee of the United States, or a person that has entered into a contract with the United States, who has a need to know the information to perform the duties of the officer, employee, or person; or

30(B) to a State agency under section 488c of this title, under appropriate arrangements to ensure the protection of the information.

31The Secretary shall establish procedures to efficiently receive applications for registration numbers under this part, conduct the checks required under paragraph (2), and promptly issue or deny a registration number.

32The Secretary shall take steps to maximize the number of registration applications that are submitted and processed during the six-month period described in section 488e(e) of this title.

33The Secretary shall conduct a check of appropriate identifying information of any person seeking to register with the Department under subsection (c) or (d) against identifying information that appears in the terrorist screening database of the Department.

34If the identifying information of a person seeking to register with the Department under subsection (c) or (d) appears in the terrorist screening database of the Department, the Secretary may deny issuance of a registration number under this part.

35Following the six-month period described in section 488e(e) of this title, the Secretary shall, to the extent practicable, issue or deny registration numbers under this part not later than 72 hours after the time the Secretary receives a complete registration application, unless the Secretary determines, in the interest of national security, that additional time is necessary to review an application.

36In all cases, the Secretary shall notify a person seeking to register with the Department under subsection (c) or (d) of the status of the application of that person not later than 72 hours after the time the Secretary receives a complete registration application.

37The Secretary shall establish an expedited appeals process for persons denied a registration number under this part.

38The Secretary shall, to the extent practicable, resolve appeals not later than 72 hours after receiving a complete request for appeal unless the Secretary determines, in the interest of national security, that additional time is necessary to resolve an appeal.

39The Secretary, in developing the appeals process under subparagraph (A), shall consult with appropriate stakeholders.

40The Secretary shall provide guidance regarding the procedures and information required for an appeal under subparagraph (A) to any person denied a registration number under this part.

41Any information constituting grounds for denial of a registration number under this section shall be maintained confidentially by the Secretary and may be used only for making determinations under this section.

42Notwithstanding any other provision of this part, the Secretary may share any such information with Federal, State, local, and tribal law enforcement agencies, as appropriate.

43The Secretary may require a person applying for a registration number under this part to submit such information as may be necessary to carry out the requirements of this section.

44The Secretary may require persons issued a registration under this part to update registration information submitted to the Secretary under this part, as appropriate.

45The Secretary shall, as appropriate, recheck persons provided a registration number pursuant to this part against the terrorist screening database of the Department, and may revoke such registration number if the Secretary determines such person may pose a threat to national security.

46The Secretary shall, as appropriate, provide prior notice to a person whose registration number is revoked under this section and such person shall have an opportunity to appeal, as provided in paragraph (4).

488b.

Inspection and auditing of records

1The Secretary shall establish a process for the periodic inspection and auditing of the records maintained by owners of ammonium nitrate facilities for the purpose of monitoring compliance with this part or for the purpose of deterring or preventing the misappropriation or use of ammonium nitrate in an act of terrorism.

488c.

Administrative provisions

1The Secretary—

2(1) may enter into a cooperative agreement with the Secretary of Agriculture, or the head of any State department of agriculture or its designee involved in agricultural regulation, in consultation with the State agency responsible for homeland security, to carry out the provisions of this part; and

3(2) wherever possible, shall seek to cooperate with State agencies or their designees that oversee ammonium nitrate facility operations when seeking cooperative agreements to implement the registration and enforcement provisions of this part.

4The Secretary may delegate to a State the authority to assist the Secretary in the administration and enforcement of this part.

5At the request of a Governor of a State, the Secretary shall delegate to that State the authority to carry out functions under sections 488a and 488b of this title, if the Secretary determines that the State is capable of satisfactorily carrying out such functions.

6Subject to the availability of appropriations, if the Secretary delegates functions to a State under this subsection, the Secretary shall provide to that State sufficient funds to carry out the delegated functions.

7The Secretary shall make available to each owner of an ammonium nitrate facility registered under section 488a(c)(1) of this title guidance on—

8(A) the identification of suspicious ammonium nitrate purchases or transfers or attempted purchases or transfers;

9(B) the appropriate course of action to be taken by the ammonium nitrate facility owner with respect to such a purchase or transfer or attempted purchase or transfer, including—

10(i) exercising the right of the owner of the ammonium nitrate facility to decline sale of ammonium nitrate; and

11(ii) notifying appropriate law enforcement entities; and

12(C) additional subjects determined appropriate to prevent the misappropriation or use of ammonium nitrate in an act of terrorism.

13In providing guidance under this subsection, the Secretary shall, to the extent practicable, leverage any relevant materials and programs.

14The Secretary shall make available materials suitable for posting at locations where ammonium nitrate is sold.

15Materials made available under subparagraph (A) shall be designed to notify prospective ammonium nitrate purchasers of—

16(i) the record-keeping requirements under section 488a of this title; and

17(ii) the penalties for violating such requirements.

488d.

Theft reporting requirement

1Any person who is required to comply with section 488a(e) of this title who has knowledge of the theft or unexplained loss of ammonium nitrate shall report such theft or loss to the appropriate Federal law enforcement authorities not later than 1 calendar day of the date on which the person becomes aware of such theft or loss. Upon receipt of such report, the relevant Federal authorities shall inform State, local, and tribal law enforcement entities, as appropriate.

488e.

Prohibitions and penalty

1No person shall purchase ammonium nitrate from an ammonium nitrate facility unless such person is registered under subsection (c) or (d) of section 488a of this title, or is an agent of a person registered under subsection (c) or (d) of that section.

2An owner of an ammonium nitrate facility shall not transfer possession of ammonium nitrate from the ammonium nitrate facility to any ammonium nitrate purchaser who is not registered under subsection (c) or (d) of section 488a of this title, or to any agent acting on behalf of an ammonium nitrate purchaser when such purchaser is not registered under subsection (c) or (d) of section 488a of this title.

3No person shall—

4(A) purchase ammonium nitrate without a registration number required under subsection (c) or (d) of section 488a of this title;

5(B) own or operate an ammonium nitrate facility without a registration number required under section 488a(c) of this title; or

6(C) fail to comply with any requirement or violate any other prohibition under this part.

7A person that violates this part may be assessed a civil penalty by the Secretary of not more than $50,000 per violation.

8In determining the amount of a civil penalty under this section, the Secretary shall consider—

9(1) the nature and circumstances of the violation;

10(2) with respect to the person who commits the violation, any history of prior violations, the ability to pay the penalty, and any effect the penalty is likely to have on the ability of such person to do business; and

11(3) any other matter that the Secretary determines that justice requires.

12No civil penalty may be assessed under this part unless the person liable for the penalty has been given notice and an opportunity for a hearing on the violation for which the penalty is to be assessed in the county, parish, or incorporated city of residence of that person.

13Paragraphs (1) and (2) of subsection (a) shall apply on and after the date that is 6 months after the date that the Secretary issues a final rule implementing this part.

488f.

Protection from civil liability

1Notwithstanding any other provision of law, an owner of an ammonium nitrate facility that in good faith refuses to sell or transfer ammonium nitrate to any person, or that in good faith discloses to the Department or to appropriate law enforcement authorities an actual or attempted purchase or transfer of ammonium nitrate, based upon a reasonable belief that the person seeking purchase or transfer of ammonium nitrate may use the ammonium nitrate to create an explosive device to be employed in an act of terrorism (as defined in section 3077 of title 18), or to use ammonium nitrate for any other unlawful purpose, shall not be liable in any civil action relating to that refusal to sell ammonium nitrate or that disclosure.

2A reasonable belief that a person may use ammonium nitrate to create an explosive device to be employed in an act of terrorism under subsection (a) may not solely be based on the race, sex, national origin, creed, religion, status as a veteran, or status as a member of the Armed Forces of the United States of that person.

488g.

Preemption of other laws

1Except as provided in section 488f of this title, nothing in this part affects any regulation issued by any agency other than an agency of the Department.

2Subject to section 488f of this title, this part preempts the laws of any State to the extent that such laws are inconsistent with this part, except that this part shall not preempt any State law that provides additional protection against the acquisition of ammonium nitrate by terrorists or the use of ammonium nitrate in explosives in acts of terrorism or for other illicit purposes, as determined by the Secretary.

488h.

Deadlines for regulations

1The Secretary—

2(1) shall issue a proposed rule implementing this part not later than 6 months after December 26, 2007; and

3(2) issue a final rule implementing this part not later than 1 year after December 26, 2007.

488i.

Authorization of appropriations

1There are authorized to be appropriated to the Secretary—

2(1) $2,000,000 for fiscal year 2008; and

3(2) $10,750,000 for each of fiscal years 2009 through 2012.

491.

National Homeland Security Council

1There is established within the Executive Office of the President a council to be known as the "Homeland Security Council" (in this subchapter referred to as the "Council").

492.

Function

1The function of the Council shall be to advise the President on homeland security matters.

493.

Membership

1The members of the Council shall be the following:

2(1) The President.

3(2) The Vice President.

4(3) The Secretary of Homeland Security.

5(4) The Attorney General.

6(5) The Secretary of Defense.

7(6) Such other individuals as may be designated by the President.

8The Chairman of the Joint Chiefs of Staff (or, in the absence of the Chairman, the Vice Chairman of the Joint Chiefs of Staff) may, in the role of the Chairman of the Joint Chiefs of Staff as principal military adviser to the Council and subject to the direction of the President, attend and participate in meetings of the Council.

494.

Other functions and activities

1For the purpose of more effectively coordinating the policies and functions of the United States Government relating to homeland security, the Council shall—

2(1) assess the objectives, commitments, and risks of the United States in the interest of homeland security and to 1 make resulting recommendations to the President;

3(2) oversee and review homeland security policies of the Federal Government and to 1 make resulting recommendations to the President; and

4(3) perform such other functions as the President may direct.

495.

Staff composition

1The Council shall have a staff, the head of which shall be a civilian Executive Secretary, who shall be appointed by the President. The President is authorized to fix the pay of the Executive Secretary at a rate not to exceed the rate of pay payable to the Executive Secretary of the National Security Council.

496.

Relation to the National Security Council

1The President may convene joint meetings of the Homeland Security Council and the National Security Council with participation by members of either Council or as the President may otherwise direct.

511.

Information security responsibilities of certain agencies

1(A) Nothing in this chapter (including any amendment made by this chapter) shall supersede any authority of the Secretary of Defense, the Director of Central Intelligence, or other agency head, as authorized by law and as directed by the President, with regard to the operation, control, or management of national security systems, as defined by section 3552(b)(5) 1 of title 44.

2(B) Omitted

3Nothing in this chapter shall supersede any requirement made by or under the Atomic Energy Act of 1954 (42 U.S.C. 2011 et seq.). Restricted Data or Formerly Restricted Data shall be handled, protected, classified, downgraded, and declassified in conformity with the Atomic Energy Act of 1954 (42 U.S.C. 2011 et seq.).

512.

Construction

1Nothing in this chapter, or the amendments made by this chapter, affects the authority of the National Institute of Standards and Technology or the Department of Commerce relating to the development and promulgation of standards or guidelines under paragraphs (1) and (2) of section 278g–3(a) of title 15.

513.

Federal air marshal program

1It is the sense of Congress that the Federal air marshal program is critical to aviation security.

2Nothing in this chapter, including any amendment made by this chapter, shall be construed as preventing the Under Secretary of Transportation for Security from implementing and training Federal air marshals.

521.

Legal status of EOIR

1There is in the Department of Justice the Executive Office for Immigration Review, which shall be subject to the direction and regulation of the Attorney General under section 1103(g) of title 8.

522.

Statutory construction

1Nothing in this chapter, any amendment made by this chapter, or in section 1103 of title 8, shall be construed to limit judicial deference to regulations, adjudications, interpretations, orders, decisions, judgments, or any other actions of the Secretary of Homeland Security or the Attorney General.

531.

Bureau of Alcohol, Tobacco, Firearms, and Explosives

1There shall be retained within the Department of the Treasury the authorities, functions, personnel, and assets of the Bureau of Alcohol, Tobacco and Firearms relating to the administration and enforcement of chapters 51 and 52 of title 26, sections 4181 and 4182 of title 26, and title 27.

2There is established within the Department of the Treasury the Tax and Trade Bureau.

3The Tax and Trade Bureau shall be headed by an Administrator, who shall perform such duties as assigned by the Under Secretary for Enforcement of the Department of the Treasury. The Administrator shall occupy a career-reserved position within the Senior Executive Service.

4The authorities, functions, personnel, and assets of the Bureau of Alcohol, Tobacco and Firearms that are not transferred to the Department of Justice under this section shall be retained and administered by the Tax and Trade Bureau.

532.

Explosives Training and Research Facility

1There is established within the Bureau an Explosives Training and Research Facility at Fort AP Hill, Fredericksburg, Virginia.

2The facility established under subsection (a) shall be utilized to train Federal, State, and local law enforcement officers to—

3(1) investigate bombings and explosions;

4(2) properly handle, utilize, and dispose of explosive materials and devices;

5(3) train canines on explosive detection; and

6(4) conduct research on explosives.

7There are authorized to be appropriated such sums as may be necessary to establish and maintain the facility established under subsection (a).

8Any amounts appropriated pursuant to paragraph (1) shall remain available until expended.

533.

Transferred

541.

Definitions

1For purposes of this subchapter:

2(1) The term "agency" includes any entity, organizational unit, program, or function.

3(2) The term "transition period" means the 12-month period beginning on the effective date of this chapter.

542.

Reorganization plan

1Not later than 60 days after November 25, 2002, the President shall transmit to the appropriate congressional committees a reorganization plan regarding the following:

2(1) The transfer of agencies, personnel, assets, and obligations to the Department pursuant to this chapter.

3(2) Any consolidation, reorganization, or streamlining of agencies transferred to the Department pursuant to this chapter.

4The plan transmitted under subsection (a) shall contain, consistent with this chapter, such elements as the President deems appropriate, including the following:

5(1) Identification of any functions of agencies transferred to the Department pursuant to this chapter that will not be transferred to the Department under the plan.

6(2) Specification of the steps to be taken by the Secretary to organize the Department, including the delegation or assignment of functions transferred to the Department among officers of the Department in order to permit the Department to carry out the functions transferred under the plan.

7(3) Specification of the funds available to each agency that will be transferred to the Department as a result of transfers under the plan.

8(4) Specification of the proposed allocations within the Department of unexpended funds transferred in connection with transfers under the plan.

9(5) Specification of any proposed disposition of property, facilities, contracts, records, and other assets and obligations of agencies transferred under the plan.

10(6) Specification of the proposed allocations within the Department of the functions of the agencies and subdivisions that are not related directly to securing the homeland.

11The President may, on the basis of consultations with the appropriate congressional committees, modify or revise any part of the plan until that part of the plan becomes effective in accordance with subsection (d).

12The reorganization plan described in this section, including any modifications or revisions of the plan under subsection (d), shall become effective for an agency on the earlier of—

13(A) the date specified in the plan (or the plan as modified pursuant to subsection (d)), except that such date may not be earlier than 90 days after the date the President has transmitted the reorganization plan to the appropriate congressional committees pursuant to subsection (a); or

14(B) the end of the transition period.

15Nothing in this subsection may be construed to require the transfer of functions, personnel, records, balances of appropriations, or other assets of an agency on a single date.

16Paragraph (1) shall apply notwithstanding section 905(b) of title 5.

543.

Review of congressional committee structures

1It is the sense of Congress that each House of Congress should review its committee structure in light of the reorganization of responsibilities within the executive branch by the establishment of the Department.

551.

Transitional authorities

1Until the transfer of an agency to the Department, any official having authority over or functions relating to the agency immediately before the effective date of this chapter shall provide to the Secretary such assistance, including the use of personnel and assets, as the Secretary may request in preparing for the transfer and integration of the agency into the Department.

2During the transition period, upon the request of the Secretary, the head of any executive agency may, on a reimbursable basis, provide services or detail personnel to assist with the transition.

3(1) During the transition period, pending the advice and consent of the Senate to the appointment of an officer required by this chapter to be appointed by and with such advice and consent, the President may designate any officer whose appointment was required to be made by and with such advice and consent and who was such an officer immediately before the effective date of this chapter (and who continues in office) or immediately before such designation, to act in such office until the same is filled as provided in this chapter. While so acting, such officers shall receive compensation at the higher of—

4(A) the rates provided by this chapter for the respective offices in which they act; or

5(B) the rates provided for the offices held at the time of designation.

6(2) Nothing in this chapter shall be understood to require the advice and consent of the Senate to the appointment by the President to a position in the Department of any officer whose agency is transferred to the Department pursuant to this chapter and whose duties following such transfer are germane to those performed before such transfer.

7Upon the transfer of an agency to the Department—

8(1) the personnel, assets, and obligations held by or available in connection with the agency shall be transferred to the Secretary for appropriate allocation, subject to the approval of the Director of the Office of Management and Budget and in accordance with the provisions of section 1531(a)(2) of title 31; and

9(2) the Secretary shall have all functions relating to the agency that any other official could by law exercise in relation to the agency immediately before such transfer, and shall have in addition all functions vested in the Secretary by this chapter or other law.

10Notwithstanding any other provision of this chapter, no funds derived from the Highway Trust Fund, Airport and Airway Trust Fund, Inland Waterway Trust Fund, or Harbor Maintenance Trust Fund, may be transferred to, made available to, or obligated by the Secretary or any other official in the Department.

11This subsection shall not apply to security-related funds provided to the Federal Aviation Administration for fiscal years preceding fiscal year 2003 for (A) operations, (B) facilities and equipment, or (C) research, engineering, and development, and to any funds provided to the Coast Guard from the Sport Fish Restoration and Boating Trust Fund for boating safety programs.

552.

Savings provisions

1(1) Completed administrative actions of an agency shall not be affected by the enactment of this chapter or the transfer of such agency to the Department, but shall continue in effect according to their terms until amended, modified, superseded, terminated, set aside, or revoked in accordance with law by an officer of the United States or a court of competent jurisdiction, or by operation of law.

2(2) For purposes of paragraph (1), the term "completed administrative action" includes orders, determinations, rules, regulations, personnel actions, permits, agreements, grants, contracts, certificates, licenses, registrations, and privileges.

3Subject to the authority of the Secretary under this chapter—

4(1) pending proceedings in an agency, including notices of proposed rulemaking, and applications for licenses, permits, certificates, grants, and financial assistance, shall continue notwithstanding the enactment of this chapter or the transfer of the agency to the Department, unless discontinued or modified under the same terms and conditions and to the same extent that such discontinuance could have occurred if such enactment or transfer had not occurred; and

5(2) orders issued in such proceedings, and appeals therefrom, and payments made pursuant to such orders, shall issue in the same manner and on the same terms as if this chapter had not been enacted or the agency had not been transferred, and any such orders shall continue in effect until amended, modified, superseded, terminated, set aside, or revoked by an officer of the United States or a court of competent jurisdiction, or by operation of law.

6Subject to the authority of the Secretary under this chapter, pending civil actions shall continue notwithstanding the enactment of this chapter or the transfer of an agency to the Department, and in such civil actions, proceedings shall be had, appeals taken, and judgments rendered and enforced in the same manner and with the same effect as if such enactment or transfer had not occurred.

7References relating to an agency that is transferred to the Department in statutes, Executive orders, rules, regulations, directives, or delegations of authority that precede such transfer or the effective date of this chapter shall be deemed to refer, as appropriate, to the Department, to its officers, employees, or agents, or to its corresponding organizational units or functions. Statutory reporting requirements that applied in relation to such an agency immediately before the effective date of this chapter shall continue to apply following such transfer if they refer to the agency by name.

8(1) Notwithstanding the generality of the foregoing (including subsections (a) and (d)), in and for the Department the Secretary may, in regulations prescribed jointly with the Director of the Office of Personnel Management, adopt the rules, procedures, terms, and conditions, established by statute, rule, or regulation before the effective date of this chapter, relating to employment in any agency transferred to the Department pursuant to this chapter; and

9(2) except as otherwise provided in this chapter, or under authority granted by this chapter, the transfer pursuant to this chapter of personnel shall not alter the terms and conditions of employment, including compensation, of any employee so transferred.

10Any statutory reporting requirement that applied to an agency, transferred to the Department under this chapter, immediately before the effective date of this chapter shall continue to apply following that transfer if the statutory requirement refers to the agency by name.

552a.

Savings provision of certain transfers made under the Homeland Security Act of 2002

1The transfer of functions under subtitle B of title XI of the Homeland Security Act of 2002 (Public Law 107–296) [6 U.S.C. 531 et seq.] shall not affect any pending or completed administrative actions, including orders, determinations, rules, regulations, personnel actions, permits, agreements, grants, contracts, certificates, licenses, or registrations, in effect on the date immediately prior to the date of such transfer, or any proceeding, unless and until amended, modified, superseded, terminated, set aside, or revoked. Pending civil actions shall not be affected by such transfer of functions.

553.

Terminations

1Except as otherwise provided in this chapter, whenever all the functions vested by law in any agency have been transferred pursuant to this chapter, each position and office the incumbent of which was authorized to receive compensation at the rates prescribed for an office or position at level II, III, IV, or V, of the Executive Schedule, shall terminate.

554.

National identification system not authorized

1Nothing in this chapter shall be construed to authorize the development of a national identification system or card.

555.

Continuity of Inspector General oversight

1Notwithstanding the transfer of an agency to the Department pursuant to this chapter, the Inspector General that exercised oversight of such agency prior to such transfer shall continue to exercise oversight of such agency during the period of time, if any, between the transfer of such agency to the Department pursuant to this chapter and the appointment of the Inspector General of the Department of Homeland Security in accordance with section 113(b) of this title.

556.

Incidental transfers

1The Director of the Office of Management and Budget, in consultation with the Secretary, is authorized and directed to make such additional incidental dispositions of personnel, assets, and liabilities held, used, arising from, available, or to be made available, in connection with the functions transferred by this chapter, as the Director may determine necessary to accomplish the purposes of this chapter.

557.

Reference

1With respect to any function transferred by or under this chapter (including under a reorganization plan that becomes effective under section 542 of this title) and exercised on or after the effective date of this chapter, reference in any other Federal law to any department, commission, or agency or any officer or office the functions of which are so transferred shall be deemed to refer to the Secretary, other official, or component of the Department to which such function is so transferred.

561.

Definitions

1In this subchapter:

2The term "Administration" means the Transportation Security Administration.

3The term "Administrator" means the Administrator of the Transportation Security Administration.

4The term "Plan" means the strategic 5-year technology investment plan developed by the Administrator under section 563 of this title.

5The term "security-related technology" means any technology that assists the Administration in the prevention of, or defense against, threats to United States transportation systems, including threats to people, property, and information.

563.

5-year technology investment plan

1The Administrator shall—

2(1) not later than 180 days after December 18, 2014, develop and submit to Congress a strategic 5-year technology investment plan, that may include a classified addendum to report sensitive transportation security risks, technology vulnerabilities, or other sensitive security information; and

3(2) to the extent possible, publish the Plan in an unclassified format in the public domain.

4The Administrator shall develop the Plan in consultation with—

5(1) the Under Secretary for Management;

6(2) the Under Secretary for Science and Technology;

7(3) the Chief Information Officer; and

8(4) the aviation industry stakeholder advisory committee established by the Administrator.

9The Administrator may not publish the Plan under subsection (a)(2) until it has been approved by the Secretary.

10The Plan shall include—

11(1) an analysis of transportation security risks and the associated capability gaps that would be best addressed by security-related technology, including consideration of the most recent quadrennial homeland security review under section 347 of this title;

12(2) a set of security-related technology acquisition needs that—

13(A) is prioritized based on risk and associated capability gaps identified under paragraph (1); and

14(B) includes planned technology programs and projects with defined objectives, goals, timelines, and measures;

15(3) an analysis of current and forecast trends in domestic and international passenger travel;

16(4) an identification of currently deployed security-related technologies that are at or near the end of their lifecycles;

17(5) an identification of test, evaluation, modeling, and simulation capabilities, including target methodologies, rationales, and timelines necessary to support the acquisition of the security-related technologies expected to meet the needs under paragraph (2);

18(6) an identification of opportunities for public-private partnerships, small and disadvantaged company participation, intragovernment collaboration, university centers of excellence, and national laboratory technology transfer;

19(7) an identification of the Administration's acquisition workforce needs for the management of planned security-related technology acquisitions, including consideration of leveraging acquisition expertise of other Federal agencies;

20(8) an identification of the security resources, including information security resources, that will be required to protect security-related technology from physical or cyber theft, diversion, sabotage, or attack;

21(9) an identification of initiatives to streamline the Administration's acquisition process and provide greater predictability and clarity to small, medium, and large businesses, including the timeline for testing and evaluation;

22(10) an assessment of the impact to commercial aviation passengers;

23(11) a strategy for consulting airport management, air carrier representatives, and Federal security directors whenever an acquisition will lead to the removal of equipment at airports, and how the strategy for consulting with such officials of the relevant airports will address potential negative impacts on commercial passengers or airport operations; and

24(12) in consultation with the National Institutes of Standards and Technology, an identification of security-related technology interface standards, in existence or if implemented, that could promote more interoperable passenger, baggage, and cargo screening systems.

25To the extent possible, and in a manner that is consistent with fair and equitable practices, the Plan shall—

26(1) leverage emerging technology trends and research and development investment trends within the public and private sectors;

27(2) incorporate private sector input, including from the aviation industry stakeholder advisory committee established by the Administrator, through requests for information, industry days, and other innovative means consistent with the Federal Acquisition Regulation; and

28(3) in consultation with the Under Secretary for Science and Technology, identify technologies in existence or in development that, with or without adaptation, are expected to be suitable to meeting mission needs.

29The Administrator shall include with the Plan a list of nongovernment persons that contributed to the writing of the Plan.

30The Administrator shall, in collaboration with relevant industry and government stakeholders, annually submit to Congress in an appendix to the budget request and publish in an unclassified format in the public domain—

31(1) an update of the Plan;

32(2) a report on the extent to which each security-related technology acquired by the Administration since the last issuance or update of the Plan is consistent with the planned technology programs and projects identified under subsection (d)(2) for that security-related technology; and

33(3) information about acquisitions completed during the fiscal year preceding the fiscal year during which the report is submitted.

34Updates and reports under subsection (g) shall—

35(1) be prepared in consultation with—

36(A) the persons described in subsection (b); and

37(B) the Surface Transportation Security Advisory Committee established under section 204 of this title; and

38(2) include—

39(A) information relating to technology investments by the Transportation Security Administration and the private sector that the Department supports with research, development, testing, and evaluation for aviation, including air cargo, and surface transportation security;

40(B) information about acquisitions completed during the fiscal year preceding the fiscal year during which the report is submitted;

41(C) information relating to equipment of the Transportation Security Administration that is in operation after the end of the life-cycle of the equipment specified by the manufacturer of the equipment; and

42(D) to the extent practicable, a classified addendum to report sensitive transportation security risks and associated capability gaps that would be best addressed by security-related technology described in subparagraph (A).

43The Administrator shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Homeland Security of the House of Representatives notice of any covered change to the Plan not later than 90 days after the date that the covered change is made.

44In this subsection, the term "covered change" means—

45(A) an increase or decrease in the dollar amount allocated to the procurement of a technology; or

46(B) an increase or decrease in the number of a technology.

563a.

Acquisition justification and reports

1Before the Administration implements any security-related technology acquisition, the Administrator, in accordance with the Department's policies and directives, shall determine whether the acquisition is justified by conducting an analysis that includes—

2(1) an identification of the scenarios and level of risk to transportation security from those scenarios that would be addressed by the security-related technology acquisition;

3(2) an assessment of how the proposed acquisition aligns to the Plan;

4(3) a comparison of the total expected lifecycle cost against the total expected quantitative and qualitative benefits to transportation security;

5(4) an analysis of alternative security solutions, including policy or procedure solutions, to determine if the proposed security-related technology acquisition is the most effective and cost-efficient solution based on cost-benefit considerations;

6(5) an assessment of the potential privacy and civil liberties implications of the proposed acquisition that includes, to the extent practicable, consultation with organizations that advocate for the protection of privacy and civil liberties;

7(6) a determination that the proposed acquisition is consistent with fair information practice principles issued by the Privacy Officer of the Department;

8(7) confirmation that there are no significant risks to human health or safety posed by the proposed acquisition; and

9(8) an estimate of the benefits to commercial aviation passengers.

10Not later than the end of the 30-day period preceding the award by the Administration of a contract for any security-related technology acquisition exceeding $30,000,000, the Administrator shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Homeland Security of the House of Representatives—

11(A) the results of the comprehensive acquisition justification under subsection (a); and

12(B) a certification by the Administrator that the benefits to transportation security justify the contract cost.

13If there is a known or suspected imminent threat to transportation security, the Administrator—

14(A) may reduce the 30-day period under paragraph (1) to 5 days to rapidly respond to the threat; and

15(B) shall immediately notify the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Homeland Security of the House of Representatives of the known or suspected imminent threat.

563b.

Acquisition baseline establishment and reports

1Before the Administration implements any security-related technology acquisition, the appropriate acquisition official of the Department shall establish and document a set of formal baseline requirements.

2The baseline requirements under paragraph (1) shall—

3(A) include the estimated costs (including lifecycle costs), schedule, and performance milestones for the planned duration of the acquisition;

4(B) identify the acquisition risks and a plan for mitigating those risks; and

5(C) assess the personnel necessary to manage the acquisition process, manage the ongoing program, and support training and other operations as necessary.

6In establishing the performance milestones under paragraph (2)(A), the appropriate acquisition official of the Department, to the extent possible and in consultation with the Under Secretary for Science and Technology, shall ensure that achieving those milestones is technologically feasible.

7The Administrator, in consultation with the Under Secretary for Science and Technology, shall develop a test and evaluation plan that describes—

8(A) the activities that are expected to be required to assess acquired technologies against the performance milestones established under paragraph (2)(A);

9(B) the necessary and cost-effective combination of laboratory testing, field testing, modeling, simulation, and supporting analysis to ensure that such technologies meet the Administration's mission needs;

10(C) an efficient planning schedule to ensure that test and evaluation activities are completed without undue delay; and

11(D) if commercial aviation passengers are expected to interact with the security-related technology, methods that could be used to measure passenger acceptance of and familiarization with the security-related technology.

12The appropriate acquisition official of the Department—

13(A) subject to subparagraph (B), shall utilize independent reviewers to verify and validate the performance milestones and cost estimates developed under paragraph (2) for a security-related technology that pursuant to section 563(d)(2) of this title has been identified as a high priority need in the most recent Plan; and

14(B) shall ensure that the use of independent reviewers does not unduly delay the schedule of any acquisition.

15The Administrator shall establish a streamlined process for an interested vendor of a security-related technology to request and receive appropriate access to the baseline requirements and test and evaluation plans that are necessary for the vendor to participate in the acquisitions process for that technology.

16The appropriate acquisition official of the Department shall review and assess each implemented acquisition to determine if the acquisition is meeting the baseline requirements established under subsection (a).

17The review shall include an assessment of whether—

18(i) the planned testing and evaluation activities have been completed; and

19(ii) the results of that testing and evaluation demonstrate that the performance milestones are technologically feasible.

20Not later than 30 days after making a finding described in clause (i), (ii), or (iii) of subparagraph (A), the Administrator shall submit a report to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Homeland Security of the House of Representatives that includes—

21(A) the results of any assessment that finds that—

22(i) the actual or planned costs exceed the baseline costs by more than 10 percent;

23(ii) the actual or planned schedule for delivery has been delayed by more than 180 days; or

24(iii) there is a failure to meet any performance milestone that directly impacts security effectiveness;

25(B) the cause for such excessive costs, delay, or failure; and

26(C) a plan for corrective action.

563c.

Inventory utilization

1Before the procurement of additional quantities of equipment to fulfill a mission need, the Administrator, to the extent practicable, shall utilize any existing units in the Administration's inventory to meet that need.

2The Administrator shall establish a process for tracking—

3(A) the location of security-related equipment in the inventory under subsection (a);

4(B) the utilization status of security-related technology in the inventory under subsection (a); and

5(C) the quantity of security-related equipment in the inventory under subsection (a).

6The Administrator shall implement internal controls to ensure up-to-date accurate data on security-related technology owned, deployed, and in use.

7The Administrator shall establish logistics principles for managing inventory in an effective and efficient manner.

8The Administrator may not use just-in-time logistics if doing so—

9(A) would inhibit necessary planning for large-scale delivery of equipment to airports or other facilities; or

10(B) would unduly diminish surge capacity for response to a terrorist threat.

563d.

Small business contracting goals

1Not later than 90 days after December 18, 2014, and annually thereafter, the Administrator shall submit a report to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Homeland Security of the House of Representatives that includes—

2(1) the Administration's performance record with respect to meeting its published small-business contracting goals during the preceding fiscal year;

3(2) if the goals described in paragraph (1) were not met or the Administration's performance was below the published small-business contracting goals of the Department—

4(A) a list of challenges, including deviations from the Administration's subcontracting plans, and factors that contributed to the level of performance during the preceding fiscal year;

5(B) an action plan, with benchmarks, for addressing each of the challenges identified in subparagraph (A) that—

6(i) is prepared after consultation with the Secretary of Defense and the heads of Federal departments and agencies that achieved their published goals for prime contracting with small and minority-owned businesses, including small and disadvantaged businesses, in prior fiscal years; and

7(ii) identifies policies and procedures that could be incorporated by the Administration in furtherance of achieving the Administration's published goal for such contracting; and

8(3) a status report on the implementation of the action plan that was developed in the preceding fiscal year in accordance with paragraph (2)(B), if such a plan was required.

563e.

Consistency with the Federal Acquisition Regulation and departmental policies and directives

1The Administrator shall execute the responsibilities set forth in this part in a manner consistent with, and not duplicative of, the Federal Acquisition Regulation and the Department's policies and directives.

563f.

Diversified security technology industry marketplace

1Not later than 120 days after October 5, 2018, the Administrator shall develop and submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Homeland Security of the House of Representatives a strategy to promote a diverse security technology industry marketplace upon which the Administrator can rely to acquire advanced transportation security technologies or capabilities, including by increased participation of small business innovators.

2The strategy required under subsection (a) shall include the following:

3(1) Information on how existing Administration solicitation, testing, evaluation, piloting, acquisition, and procurement processes impact the Administrator's ability to acquire from the security technology industry marketplace, including small business innovators that have not previously provided technology to the Administration, innovative technologies or capabilities with the potential to enhance transportation security.

4(2) Specific actions that the Administrator will take, including modifications to the processes described in paragraph (1), to foster diversification within the security technology industry marketplace.

5(3) Projected timelines for implementing the actions described in paragraph (2).

6(4) Plans for how the Administrator could, to the extent practicable, assist a small business innovator periodically during such processes, including when such an innovator lacks adequate resources to participate in such processes, to facilitate an advanced transportation security technology or capability being developed and acquired by the Administrator.

7(5) An assessment of the feasibility of partnering with an organization described in section 501(c)(3) of title 26 and exempt from tax under section 501(a) of title 26 to provide venture capital to businesses, particularly small business innovators, for commercialization of innovative transportation security technologies that are expected to be ready for commercialization in the near term and within 36 months.

8In conducting the feasibility assessment under subsection (b)(5), the Administrator shall consider the following:

9(1) Establishing an organization described in section 501(c)(3) of title 26 and exempt from tax under section 501(a) of title 26 as a venture capital partnership between the private sector and the intelligence community to help businesses, particularly small business innovators, commercialize innovative security-related technologies.

10(2) Enhanced engagement through the Science and Technology Directorate of the Department of Homeland Security.

11Nothing in this section may be construed as requiring changes to the Transportation Security Administration standards for security technology.

12In this section:

13The term "intelligence community" has the meaning given the term in section 3003 of title 50.

14The term "small business concern" has the meaning described under section 632 of title 15.

15The term "small business innovator" means a small business concern that has an advanced transportation security technology or capability.

565.

Maintenance validation and oversight

1Not later than 180 days after October 5, 2018, the Administrator shall develop and implement a preventive maintenance validation process for security-related technology deployed to airports.

2For maintenance to be carried out by Administration personnel at airports, the process referred to in subsection (a) shall include the following:

3(1) Guidance to Administration personnel at airports specifying how to conduct and document preventive maintenance actions.

4(2) Mechanisms for the Administrator to verify compliance with the guidance issued pursuant to paragraph (1).

5For maintenance to be carried by a contractor at airports, the process referred to in subsection (a) shall require the following:

6(1) Provision of monthly preventative maintenance schedules to appropriate Administration personnel at each airport that includes information on each action to be completed by contractor.1

7(2) Notification to appropriate Administration personnel at each airport when maintenance action is completed by a contractor.

8(3) A process for independent validation by a third party of contractor maintenance.

9The Administrator shall require maintenance for any contracts entered into 60 days after October 5, 2018, or later for security-related technology deployed to airports to include penalties for noncompliance when it is determined that either preventive or corrective maintenance has not been completed according to contractual requirements and manufacturers' specifications.

571.

Emergency Communications Division

1There is established in the Department an Emergency Communications Division. The Division shall be located in the Cybersecurity and Infrastructure Security Agency.

2The head of the Division shall be the Executive Assistant Director for Emergency Communications (in this section referred to as the "Executive Assistant Director"). The Executive Assistant Director shall report to the Director of the Cybersecurity and Infrastructure Security Agency. All decisions of the Executive Assistant Director that entail the exercise of significant authority shall be subject to the approval of the Director of the Cybersecurity and Infrastructure Security Agency.

3The Executive Assistant Director shall—

4(1) assist the Secretary in developing and implementing the program described in section 194(a)(1) of this title, except as provided in section 195 of this title;

5(2) administer the Department's responsibilities and authorities relating to the SAFECOM Program, excluding elements related to research, development, testing, and evaluation and standards;

6(3) administer the Department's responsibilities and authorities relating to the Integrated Wireless Network program;

7(4) conduct extensive, nationwide outreach to support and promote the ability of emergency response providers and relevant government officials to continue to communicate in the event of natural disasters, acts of terrorism, and other man-made disasters;

8(5) conduct extensive, nationwide outreach and foster the development of interoperable emergency communications capabilities by State, regional, local, and tribal governments and public safety agencies, and by regional consortia thereof;

9(6) provide technical assistance to State, regional, local, and tribal government officials with respect to use of interoperable emergency communications capabilities;

10(7) coordinate with the Regional Administrators regarding the activities of Regional Emergency Communications Coordination Working Groups under section 575 of this title;

11(8) promote the development of standard operating procedures and best practices with respect to use of interoperable emergency communications capabilities for incident response, and facilitate the sharing of information on such best practices for achieving, maintaining, and enhancing interoperable emergency communications capabilities for such response;

12(9) coordinate, in cooperation with the National Communications System, the establishment of a national response capability with initial and ongoing planning, implementation, and training for the deployment of communications equipment for relevant State, local, and tribal governments and emergency response providers in the event of a catastrophic loss of local and regional emergency communications services;

13(10) assist the President, the National Security Council, the Homeland Security Council, and the Director of the Office of Management and Budget in ensuring the continued operation of the telecommunications functions and responsibilities of the Federal Government, excluding spectrum management;

14(11) establish, in coordination with the Director of the Office for Interoperability and Compatibility, requirements for interoperable emergency communications capabilities, which shall be nonproprietary where standards for such capabilities exist, for all public safety radio and data communications systems and equipment purchased using homeland security assistance administered by the Department, excluding any alert and warning device, technology, or system;

15(12) review, in consultation with the Assistant Secretary for Grants and Training, all interoperable emergency communications plans of Federal, State, local, and tribal governments, including Statewide and tactical interoperability plans, developed pursuant to homeland security assistance administered by the Department, but excluding spectrum allocation and management related to such plans;

16(13) develop and update periodically, as appropriate, a National Emergency Communications Plan under section 572 of this title;

17(14) perform such other duties of the Department necessary to support and promote the ability of emergency response providers and relevant government officials to continue to communicate in the event of natural disasters, acts of terrorism, and other man-made disasters;

18(15) perform other duties of the Department necessary to achieve the goal of and maintain and enhance interoperable emergency communications capabilities; and

19(16) fully participate in the mechanisms required under section 652(c)(7) of this title.

20The Secretary shall transfer to, and administer through, the Executive Assistant Director the following programs and responsibilities:

21(1) The SAFECOM Program, excluding elements related to research, development, testing, and evaluation and standards.

22(2) The responsibilities of the Chief Information Officer related to the implementation of the Integrated Wireless Network.

23(3) The Interoperable Communications Technical Assistance Program.

24The Executive Assistant Director shall coordinate—

25(1) as appropriate, with the Director of the Office for Interoperability and Compatibility with respect to the responsibilities described in section 195 of this title; and

26(2) with the Administrator of the Federal Emergency Management Agency with respect to the responsibilities described in this subchapter.

27Not later than 120 days after October 4, 2006, the Secretary shall submit to Congress a report on the resources and staff necessary to carry out fully the responsibilities under this subchapter.

28The Comptroller General shall review the validity of the report submitted by the Secretary under paragraph (1). Not later than 60 days after the date on which such report is submitted, the Comptroller General shall submit to Congress a report containing the findings of such review.

29Any reference to the Assistant Director for Emergency Communications in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Executive Assistant Director for Emergency Communications.

572.

National Emergency Communications Plan

1The Secretary, acting through the Assistant Director for Emergency Communications, and in cooperation with the Department of National Communications System (as appropriate), shall, in cooperation with State, local, and tribal governments, Federal departments and agencies, emergency response providers, and the private sector, develop not later than 180 days after the completion of the baseline assessment under section 573 of this title, and periodically update, a National Emergency Communications Plan to provide recommendations regarding how the United States should—

2(1) support and promote the ability of emergency response providers and relevant government officials to continue to communicate in the event of natural disasters, acts of terrorism, and other man-made disasters; and

3(2) ensure, accelerate, and attain interoperable emergency communications nationwide.

4The Emergency Communications Preparedness Center under section 576 of this title shall coordinate the development of the Federal aspects of the National Emergency Communications Plan.

5The National Emergency Communications Plan shall—

6(1) include recommendations developed in consultation with the Federal Communications Commission and the National Institute of Standards and Technology for a process for expediting national voluntary consensus standards for emergency communications equipment for the purchase and use by public safety agencies of interoperable emergency communications equipment and technologies;

7(2) identify the appropriate capabilities necessary for emergency response providers and relevant government officials to continue to communicate in the event of natural disasters, acts of terrorism, and other man-made disasters;

8(3) identify the appropriate interoperable emergency communications capabilities necessary for Federal, State, local, and tribal governments in the event of natural disasters, acts of terrorism, and other man-made disasters;

9(4) recommend both short-term and long-term solutions for ensuring that emergency response providers and relevant government officials can continue to communicate in the event of natural disasters, acts of terrorism, and other man-made disasters;

10(5) recommend both short-term and long-term solutions for deploying interoperable emergency communications systems for Federal, State, local, and tribal governments throughout the Nation, including through the provision of existing and emerging technologies;

11(6) identify how Federal departments and agencies that respond to natural disasters, acts of terrorism, and other man-made disasters can work effectively with State, local, and tribal governments, in all States, and with other entities;

12(7) identify obstacles to deploying interoperable emergency communications capabilities nationwide and recommend short-term and long-term measures to overcome those obstacles, including recommendations for multijurisdictional coordination among Federal, State, local, and tribal governments;

13(8) recommend goals and timeframes for the deployment of emergency, command-level communications systems based on new and existing equipment across the United States and develop a timetable for the deployment of interoperable emergency communications systems nationwide;

14(9) recommend appropriate measures that emergency response providers should employ to ensure the continued operation of relevant governmental communications infrastructure in the event of natural disasters, acts of terrorism, or other man-made disasters; and

15(10) set a date, including interim benchmarks, as appropriate, by which State, local, and tribal governments, Federal departments and agencies, and emergency response providers expect to achieve a baseline level of national interoperable communications, as that term is defined under section 194(g)(1) of this title.

573.

Assessments and reports

1Not later than 1 year after October 4, 2006, and not less than every 5 years thereafter, the Secretary, acting through the Assistant Director for Emergency Communications, shall conduct an assessment of Federal, State, local, and tribal governments that—

2(1) defines the range of capabilities needed by emergency response providers and relevant government officials to continue to communicate in the event of natural disasters, acts of terrorism, and other man-made disasters;

3(2) defines the range of interoperable emergency communications capabilities needed for specific events;

4(3) assesses the current available capabilities to meet such communications needs;

5(4) identifies the gap between such current capabilities and defined requirements; and

6(5) includes a national interoperable emergency communications inventory to be completed by the Secretary of Homeland Security, the Secretary of Commerce, and the Chairman of the Federal Communications Commission that—

7(A) identifies for each Federal department and agency—

8(i) the channels and frequencies used;

9(ii) the nomenclature used to refer to each channel or frequency used; and

10(iii) the types of communications systems and equipment used; and

11(B) identifies the interoperable emergency communications systems in use by public safety agencies in the United States.

12The baseline assessment under this section may include a classified annex including information provided under subsection (a)(5)(A).

13In conducting the baseline assessment under this section, the Secretary may incorporate findings from assessments conducted before, or ongoing on, October 4, 2006.

14Not later than one year after October 4, 2006, and biennially thereafter, the Secretary, acting through the Assistant Director for Emergency Communications, shall submit to Congress a report on the progress of the Department in achieving the goals of, and carrying out its responsibilities under, this subchapter, including—

15(1) a description of the findings of the most recent baseline assessment conducted under subsection (a);

16(2) a determination of the degree to which interoperable emergency communications capabilities have been attained to date and the gaps that remain for interoperability to be achieved;

17(3) an evaluation of the ability to continue to communicate and to provide and maintain interoperable emergency communications by emergency managers, emergency response providers, and relevant government officials in the event of—

18(A) natural disasters, acts of terrorism, or other man-made disasters, including Incidents of National Significance declared by the Secretary under the National Response Plan; and

19(B) a catastrophic loss of local and regional communications services;

20(4) a list of best practices relating to the ability to continue to communicate and to provide and maintain interoperable emergency communications in the event of natural disasters, acts of terrorism, or other man-made disasters; and

21(A) 1 an evaluation of the feasibility and desirability of the Department developing, on its own or in conjunction with the Department of Defense, a mobile communications capability, modeled on the Army Signal Corps, that could be deployed to support emergency communications at the site of natural disasters, acts of terrorism, or other man-made disasters.

574.

Coordination of Department emergency communications grant programs

1The Secretary, acting through the Assistant Director for Emergency Communications, shall ensure that grant guidelines for the use of homeland security assistance administered by the Department relating to interoperable emergency communications are coordinated and consistent with the goals and recommendations in the National Emergency Communications Plan under section 572 of this title.

2The Secretary, acting through the Assistant Secretary for Grants and Planning, and in consultation with the Assistant Director for Emergency Communications, may prohibit any State, local, or tribal government from using homeland security assistance administered by the Department to achieve, maintain, or enhance emergency communications capabilities, if—

3(A) such government has not complied with the requirement to submit a Statewide Interoperable Communications Plan as required by section 194(f) of this title;

4(B) such government has proposed to upgrade or purchase new equipment or systems that do not meet or exceed any applicable national voluntary consensus standards and has not provided a reasonable explanation of why such equipment or systems will serve the needs of the applicant better than equipment or systems that meet or exceed such standards; and

5(C) as of the date that is 3 years after the date of the completion of the initial National Emergency Communications Plan under section 572 of this title, national voluntary consensus standards for interoperable emergency communications capabilities have not been developed and promulgated.

6The Secretary, in coordination with the Federal Communications Commission, the National Institute of Standards and Technology, and other Federal departments and agencies with responsibility for standards, shall support the development, promulgation, and updating as necessary of national voluntary consensus standards for interoperable emergency communications.

575.

Regional emergency communications coordination

1There is established in each Regional Office a Regional Emergency Communications Coordination Working Group (in this section referred to as an "RECC Working Group"). Each RECC Working Group shall report to the relevant Regional Administrator and coordinate its activities with the relevant Regional Advisory Council.

2Each RECC Working Group shall consist of the following:

3Organizations representing the interests of the following:

4(A) State officials.

5(B) Local government officials, including sheriffs.

6(C) State police departments.

7(D) Local police departments.

8(E) Local fire departments.

9(F) Public safety answering points (9–1–1 services).

10(G) State emergency managers, homeland security directors, or representatives of State Administrative Agencies.

11(H) Local emergency managers or homeland security directors.

12(I) Other emergency response providers as appropriate.

13Representatives from the Department, the Federal Communications Commission, and other Federal departments and agencies with responsibility for coordinating interoperable emergency communications with or providing emergency support services to State, local, and tribal governments.

14Each RECC Working Group shall coordinate its activities with the following:

15(1) Communications equipment manufacturers and vendors (including broadband data service providers).

16(2) Local exchange carriers.

17(3) Local broadcast media.

18(4) Wireless carriers.

19(5) Satellite communications services.

20(6) Cable operators.

21(7) Hospitals.

22(8) Public utility services.

23(9) Emergency evacuation transit services.

24(10) Ambulance services.

25(11) HAM and amateur radio operators.

26(12) Representatives from other private sector entities and nongovernmental organizations as the Regional Administrator determines appropriate.

27The duties of each RECC Working Group shall include—

28(1) assessing the survivability, sustainability, and interoperability of local emergency communications systems to meet the goals of the National Emergency Communications Plan;

29(2) reporting annually to the relevant Regional Administrator, the Assistant Director for Emergency Communications, the Chairman of the Federal Communications Commission, and the Assistant Secretary for Communications and Information of the Department of Commerce on the status of its region in building robust and sustainable interoperable voice and data emergency communications networks and, not later than 60 days after the completion of the initial National Emergency Communications Plan under section 572 of this title, on the progress of the region in meeting the goals of such plan;

30(3) ensuring a process for the coordination of effective multijurisdictional, multi-agency emergency communications networks for use during natural disasters, acts of terrorism, and other man-made disasters through the expanded use of emergency management and public safety communications mutual aid agreements; and

31(4) coordinating the establishment of Federal, State, local, and tribal support services and networks designed to address the immediate and critical human needs in responding to natural disasters, acts of terrorism, and other man-made disasters.

576.

Emergency Communications Preparedness Center

1There is established the Emergency Communications Preparedness Center (in this section referred to as the "Center").

2The Secretary, the Chairman of the Federal Communications Commission, the Secretary of Defense, the Secretary of Commerce, the Attorney General of the United States, and the heads of other Federal departments and agencies or their designees shall jointly operate the Center in accordance with the Memorandum of Understanding entitled, "Emergency Communications Preparedness Center (ECPC) Charter".

3The Center shall—

4(1) serve as the focal point for interagency efforts and as a clearinghouse with respect to all relevant intergovernmental information to support and promote (including specifically by working to avoid duplication, hindrances, and counteractive efforts among the participating Federal departments and agencies)—

5(A) the ability of emergency response providers and relevant government officials to continue to communicate in the event of natural disasters, acts of terrorism, and other man-made disasters; and

6(B) interoperable emergency communications;

7(2) prepare and submit to Congress, on an annual basis, a strategic assessment regarding the coordination efforts of Federal departments and agencies to advance—

8(A) the ability of emergency response providers and relevant government officials to continue to communicate in the event of natural disasters, acts of terrorism, and other man-made disasters; and

9(B) interoperable emergency communications;

10(3) consider, in preparing the strategic assessment under paragraph (2), the goals stated in the National Emergency Communications Plan under section 572 of this title; and

11(4) perform such other functions as are provided in the Emergency Communications Preparedness Center (ECPC) Charter described in subsection (b)(1).1

577.

Urban and other high risk area communications capabilities

1The Secretary, in consultation with the Chairman of the Federal Communications Commission and the Secretary of Defense, and with appropriate State, local, and tribal government officials, shall provide technical guidance, training, and other assistance, as appropriate, to support the rapid establishment of consistent, secure, and effective interoperable emergency communications capabilities in the event of an emergency in urban and other areas determined by the Secretary to be at consistently high levels of risk from natural disasters, acts of terrorism, and other man-made disasters.

2The interoperable emergency communications capabilities established under subsection (a) shall ensure the ability of all levels of government, emergency response providers, the private sector, and other organizations with emergency response capabilities—

3(1) to communicate with each other in the event of an emergency;

4(2) to have appropriate and timely access to the Information Sharing Environment described in section 485 of this title; and

5(3) to be consistent with any applicable State or Urban Area homeland strategy or plan.

578.

Definition

1In this subchapter, the term "interoperable" has the meaning given the term "interoperable communications" under section 194(g)(1) of this title.

579.

Interoperable Emergency Communications Grant Program

1The Secretary shall establish the Interoperable Emergency Communications Grant Program to make grants to States to carry out initiatives to improve local, tribal, statewide, regional, national and, where appropriate, international interoperable emergency communications, including communications in collective response to natural disasters, acts of terrorism, and other man-made disasters.

2The Assistant Director for Emergency Communications shall ensure that a grant awarded to a State under this section is consistent with the policies established pursuant to the responsibilities and authorities of the Emergency Communications Division under this subchapter, including ensuring that activities funded by the grant—

3(1) comply with the statewide plan for that State required by section 194(f) of this title; and

4(2) comply with the National Emergency Communications Plan under section 572 of this title, when completed.

5The Administrator of the Federal Emergency Management Agency shall administer the Interoperable Emergency Communications Grant Program pursuant to the responsibilities and authorities of the Administrator under subchapter V.

6In administering the grant program, the Administrator shall ensure that the use of grants is consistent with guidance established by the Assistant Director for Emergency Communications pursuant to section 194(a)(1)(H) of this title.

7A State that receives a grant under this section shall use the grant to implement that State's Statewide Interoperability Plan required under section 194(f) of this title and approved under subsection (e), and to assist with activities determined by the Secretary to be integral to interoperable emergency communications.

8Before a State may receive a grant under this section, the Assistant Director for Emergency Communications shall approve the State's Statewide Interoperable Communications Plan required under section 194(f) of this title.

9In approving a plan under this subsection, the Assistant Director for Emergency Communications shall ensure that the plan—

10(A) is designed to improve interoperability at the city, county, regional, State and interstate level;

11(B) considers any applicable local or regional plan; and

12(C) complies, to the maximum extent practicable, with the National Emergency Communications Plan under section 572 of this title.

13The Assistant Director for Emergency Communications may approve revisions to a State's plan if the Assistant Director determines that doing so is likely to further interoperability.

14The recipient of a grant under this section may not use the grant—

15(A) to supplant State or local funds;

16(B) for any State or local government cost-sharing contribution; or

17(C) for recreational or social purposes.

18In addition to other remedies currently available, the Secretary may take such actions as necessary to ensure that recipients of grant funds are using the funds for the purpose for which they were intended.

19The Secretary may not award a grant under this section before the date on which the Secretary completes and submits to Congress the National Emergency Communications Plan required under section 572 of this title.

20The Secretary may not award a grant to a State under this section for the purchase of equipment that does not meet applicable voluntary consensus standards, unless the State demonstrates that there are compelling reasons for such purchase.

21In approving applications and awarding grants under this section, the Secretary shall consider—

22(1) the risk posed to each State by natural disasters, acts of terrorism, or other manmade disasters, including—

23(A) the likely need of a jurisdiction within the State to respond to such risk in nearby jurisdictions;

24(B) the degree of threat, vulnerability, and consequences related to critical infrastructure (from all critical infrastructure sectors) or key resources identified by the Administrator or the State homeland security and emergency management plans, including threats to, vulnerabilities of, and consequences from damage to critical infrastructure and key resources in nearby jurisdictions;

25(C) the size of the population and density of the population of the State, including appropriate consideration of military, tourist, and commuter populations;

26(D) whether the State is on or near an international border;

27(E) whether the State encompasses an economically significant border crossing; and

28(F) whether the State has a coastline bordering an ocean, a major waterway used for interstate commerce, or international waters; and

29(2) the anticipated effectiveness of the State's proposed use of grant funds to improve interoperability.

30In considering applications for grants under this section, the Administrator shall provide applicants with a reasonable opportunity to correct defects in the application, if any, before making final awards.

31In awarding grants under this section, the Secretary shall ensure that for each fiscal year, except as provided in paragraph (2), no State receives a grant in an amount that is less than the following percentage of the total amount appropriated for grants under this section for that fiscal year:

32(A) For fiscal year 2008, 0.50 percent.

33(B) For fiscal year 2009, 0.50 percent.

34(C) For fiscal year 2010, 0.45 percent.

35(D) For fiscal year 2011, 0.40 percent.

36(E) For fiscal year 2012 and each subsequent fiscal year, 0.35 percent.

37In awarding grants under this section, the Secretary shall ensure that for each fiscal year, American Samoa, the Commonwealth of the Northern Mariana Islands, Guam, and the Virgin Islands each receive grants in amounts that are not less than 0.08 percent of the total amount appropriated for grants under this section for that fiscal year.

38Each State that receives a grant under this section shall certify that the grant is used for the purpose for which the funds were intended and in compliance with the State's approved Statewide Interoperable Communications Plan.

39Not later than 45 days after receiving grant funds, any State that receives a grant under this section shall obligate or otherwise make available to local and tribal governments—

40(A) not less than 80 percent of the grant funds;

41(B) with the consent of local and tribal governments, eligible expenditures having a value of not less than 80 percent of the amount of the grant; or

42(C) grant funds combined with other eligible expenditures having a total value of not less than 80 percent of the amount of the grant.

43A State that receives a grant under this section shall allocate grant funds to tribal governments in the State to assist tribal communities in improving interoperable communications, in a manner consistent with the Statewide Interoperable Communications Plan. A State may not impose unreasonable or unduly burdensome requirements on a tribal government as a condition of providing grant funds or resources to the tribal government.

44If a State violates the requirements of this subsection, in addition to other remedies available to the Secretary, the Secretary may terminate or reduce the amount of the grant awarded to that State or transfer grant funds previously awarded to the State directly to the appropriate local or tribal government.

45A State that receives a grant under this section shall annually submit to the Assistant Director for Emergency Communications a report on the progress of the State in implementing that State's Statewide Interoperable Communications Plans required under section 194(f) of this title and achieving interoperability at the city, county, regional, State, and interstate levels. The Assistant Director shall make the reports publicly available, including by making them available on the Internet website of the Cybersecurity and Infrastructure Security Agency, subject to any redactions that the Assistant Director determines are necessary to protect classified or other sensitive information.

46At least once each year, the Assistant Director for Emergency Communications shall submit to Congress a report on the use of grants awarded under this section and any progress in implementing Statewide Interoperable Communications Plans and improving interoperability at the city, county, regional, State, and interstate level, as a result of the award of such grants.

47Nothing in this section shall be construed or interpreted to preclude a State from using a grant awarded under this section for interim or long-term Internet Protocol-based interoperable solutions.

48There are authorized to be appropriated for grants under this section—

49(1) for fiscal year 2008, such sums as may be necessary;

50(2) for each of fiscal years 2009 through 2012, $400,000,000; and

51(3) for each subsequent fiscal year, such sums as may be necessary.

580.

Border interoperability demonstration project

1The Secretary, acting through the Assistant Director for Emergency Communications (referred to in this section as the "Assistant Director"), and in coordination with the Federal Communications Commission and the Secretary of Commerce, shall establish an International Border Community Interoperable Communications Demonstration Project (referred to in this section as the "demonstration project").

2The Assistant Director shall select no fewer than 6 communities to participate in a demonstration project.

3No fewer than 3 of the communities selected under paragraph (2) shall be located on the northern border of the United States and no fewer than 3 of the communities selected under paragraph (2) shall be located on the southern border of the United States.

4The Assistant Director, in coordination with the Federal Communications Commission and the Secretary of Commerce, shall ensure that the project is carried out as soon as adequate spectrum is available as a result of the 800 megahertz rebanding process in border areas, and shall ensure that the border projects do not impair or impede the rebanding process, but under no circumstances shall funds be distributed under this section unless the Federal Communications Commission and the Secretary of Commerce agree that these conditions have been met.

5Consistent with the responsibilities of the Emergency Communications Division under section 571 of this title, the Assistant Director shall foster local, tribal, State, and Federal interoperable emergency communications, as well as interoperable emergency communications with appropriate Canadian and Mexican authorities in the communities selected for the demonstration project. The Assistant Director shall—

6(1) identify solutions to facilitate interoperable communications across national borders expeditiously;

7(2) help ensure that emergency response providers can communicate with each other in the event of natural disasters, acts of terrorism, and other man-made disasters;

8(3) provide technical assistance to enable emergency response providers to deal with threats and contingencies in a variety of environments;

9(4) identify appropriate joint-use equipment to ensure communications access;

10(5) identify solutions to facilitate communications between emergency response providers in communities of differing population densities; and

11(6) take other actions or provide equipment as the Assistant Director deems appropriate to foster interoperable emergency communications.

12The Secretary shall distribute funds under this section to each community participating in the demonstration project through the State, or States, in which each community is located.

13A State shall make the funds available promptly to the local and tribal governments and emergency response providers selected by the Secretary to participate in the demonstration project.

14Not later than 90 days after a State receives funds under this subsection the State shall report to the Assistant Director on the status of the distribution of such funds to local and tribal governments.

15The Assistant Director may not fund any participant under the demonstration project for more than 3 years.

16The Assistant Director shall establish mechanisms to ensure that the information and knowledge gained by participants in the demonstration project are transferred among the participants and to other interested parties, including other communities that submitted applications to the participant in the project.

17There is authorized to be appropriated for grants under this section such sums as may be necessary.

590.

Definitions

1In this subchapter:

2The term "Assistant Secretary" means the Assistant Secretary for the Countering Weapons of Mass Destruction Office.

3The term "intelligence community" has the meaning given such term in section 3003(4) of title 50.

4The term "Office" means the Countering Weapons of Mass Destruction Office established under section 591(a) of this title.

5The term "weapon of mass destruction" has the meaning given the term in section 1801 of title 50.

591.

Countering Weapons of Mass Destruction Office

1There is established in the Department a Countering Weapons of Mass Destruction Office.

2The Office shall be headed by an Assistant Secretary for the Countering Weapons of Mass Destruction Office, who shall be appointed by the President.

3The Assistant Secretary shall serve as the Secretary's principal advisor on—

4(1) weapons of mass destruction matters and strategies; and

5(2) coordinating the efforts of the Department to counter weapons of mass destruction.

6The Secretary may request that the Secretary of Defense, the Secretary of Energy, the Secretary of State, the Attorney General, the Nuclear Regulatory Commission, and the heads of other Federal agencies, including elements of the intelligence community, provide for the reimbursable detail of personnel with relevant expertise to the Office.

7The Office shall terminate on the date that is 5 years after December 21, 2018.

591g.

Mission of the Office

1The Office shall be responsible for coordinating with other Federal efforts and developing a strategy and policy for the Department to plan for, detect, and protect against the importation, possession, storage, transportation, development, or use of unauthorized chemical, biological, radiological, or nuclear materials, devices, or agents in the United States and to protect against an attack using such materials, devices, or agents against the people, territory, or interests of the United States.

591h.

Relationship to other Department components and Federal agencies

1The authority of the Assistant Secretary under this subchapter shall not affect or diminish the authority or the responsibility of any officer of the Department or any officer of any other Federal agency with respect to the command, control, or direction of the functions, personnel, funds, assets, or liabilities of any component of the Department or any other Federal agency.

2Not later than one year after December 21, 2018, the Assistant Secretary shall, in coordination with the Under Secretary for Strategy, Policy, and Plans, submit to the appropriate congressional committees a strategy and implementation plan to direct programs within the Office and to integrate those programs with other programs and activities of the Department.

3Nothing in this subchapter or any other provision of law may be construed to affect or reduce the responsibilities of the Federal Emergency Management Agency or the Administrator of the Agency, including the diversion of any asset, function, or mission of the Agency or the Administrator of the Agency.

592.

Responsibilities

1The Office shall be responsible for coordinating Federal efforts to detect and protect against the unauthorized importation, possession, storage, transportation, development, or use of a nuclear explosive device, fissile material, or radiological material in the United States, and to protect against attack using such devices or materials against the people, territory, or interests of the United States and, to this end, shall—

2(1) serve as the primary entity of the United States Government to further develop, acquire, and support the deployment of an enhanced domestic system to detect and report on attempts to import, possess, store, transport, develop, or use an unauthorized nuclear explosive device, fissile material, or radiological material in the United States, and improve that system over time;

3(2) enhance and coordinate the nuclear detection efforts of Federal, State, local, and tribal governments and the private sector to ensure a managed, coordinated response;

4(3) establish, with the approval of the Secretary and in coordination with the Attorney General, the Secretary of Defense, and the Secretary of Energy, additional protocols and procedures for use within the United States to ensure that the detection of unauthorized nuclear explosive devices, fissile material, or radiological material is promptly reported to the Attorney General, the Secretary, the Secretary of Defense, the Secretary of Energy, and other appropriate officials or their respective designees for appropriate action by law enforcement, military, emergency response, or other authorities;

5(4) develop, with the approval of the Secretary and in coordination with the Attorney General, the Secretary of State, the Secretary of Defense, and the Secretary of Energy, an enhanced global nuclear detection architecture with implementation under which—

6(A) the Office will be responsible for the implementation of the domestic portion of the global architecture;

7(B) the Secretary of Defense will retain responsibility for implementation of Department of Defense requirements within and outside the United States; and

8(C) the Secretary of State, the Secretary of Defense, and the Secretary of Energy will maintain their respective responsibilities for policy guidance and implementation of the portion of the global architecture outside the United States, which will be implemented consistent with applicable law and relevant international arrangements;

9(5) ensure that the expertise necessary to accurately interpret detection data is made available in a timely manner for all technology deployed by the Office to implement the global nuclear detection architecture;

10(6) conduct, support, coordinate, and encourage an aggressive, expedited, evolutionary, and transformational program of research and development to generate and improve technologies to detect and prevent the illicit entry, transport, assembly, or potential use within the United States of a nuclear explosive device or fissile or radiological material, and coordinate with the Under Secretary for Science and Technology on basic and advanced or transformational research and development efforts relevant to the mission of both organizations;

11(7) carry out a program to test and evaluate technology for detecting a nuclear explosive device and fissile or radiological material, in coordination with the Secretary of Defense and the Secretary of Energy, as appropriate, and establish performance metrics for evaluating the effectiveness of individual detectors and detection systems in detecting such devices or material—

12(A) under realistic operational and environmental conditions; and

13(B) against realistic adversary tactics and countermeasures;

14(8) support and enhance the effective sharing and use of appropriate information generated by the intelligence community, law enforcement agencies, counterterrorism community, other government agencies, and foreign governments, as well as provide appropriate information to such entities;

15(9) further enhance and maintain continuous awareness by analyzing information from all Office mission-related detection systems;

16(10) lead the development and implementation of the national strategic five-year plan for improving the nuclear forensic and attribution capabilities of the United States required under section 1036 of the National Defense Authorization Act for Fiscal Year 2010;

17(11) establish, within the Office, the National Technical Nuclear Forensics Center to provide centralized stewardship, planning, assessment, gap analysis, exercises, improvement, and integration for all Federal nuclear forensics and attribution activities—

18(A) to ensure an enduring national technical nuclear forensics capability to strengthen the collective response of the United States to nuclear terrorism or other nuclear attacks; and

19(B) to coordinate and implement the national strategic five-year plan referred to in paragraph (10);

20(12) establish a National Nuclear Forensics Expertise Development Program, which—

21(A) is devoted to developing and maintaining a vibrant and enduring academic pathway from undergraduate to post-doctorate study in nuclear and geochemical science specialties directly relevant to technical nuclear forensics, including radiochemistry, geochemistry, nuclear physics, nuclear engineering, materials science, and analytical chemistry;

22(B) shall—

23(i) make available for undergraduate study student scholarships, with a duration of up to 4 years per student, which shall include, if possible, at least 1 summer internship at a national laboratory or appropriate Federal agency in the field of technical nuclear forensics during the course of the student's undergraduate career;

24(ii) make available for doctoral study student fellowships, with a duration of up to 5 years per student, which shall—

25(I) include, if possible, at least 2 summer internships at a national laboratory or appropriate Federal agency in the field of technical nuclear forensics during the course of the student's graduate career; and

26(II) require each recipient to commit to serve for 2 years in a post-doctoral position in a technical nuclear forensics-related specialty at a national laboratory or appropriate Federal agency after graduation;

27(iii) make available to faculty awards, with a duration of 3 to 5 years each, to ensure faculty and their graduate students have a sustained funding stream; and

28(iv) place a particular emphasis on reinvigorating technical nuclear forensics programs while encouraging the participation of undergraduate students, graduate students, and university faculty from historically Black colleges and universities, Hispanic-serving institutions, Tribal Colleges and Universities, Asian American and Native American Pacific Islander-serving institutions, Alaska Native-serving institutions, and Hawaiian Native-serving institutions; and

29(C) shall—

30(i) provide for the selection of individuals to receive scholarships or fellowships under this section through a competitive process primarily on the basis of academic merit and the nuclear forensics and attribution needs of the United States Government;

31(ii) provide for the setting aside of up to 10 percent of the scholarships or fellowships awarded under this section for individuals who are Federal employees to enhance the education of such employees in areas of critical nuclear forensics and attribution needs of the United States Government, for doctoral education under the scholarship on a full-time or part-time basis;

32(iii) provide that the Secretary may enter into a contractual agreement with an institution of higher education under which the amounts provided for a scholarship under this section for tuition, fees, and other authorized expenses are paid directly to the institution with respect to which such scholarship is awarded;

33(iv) require scholarship recipients to maintain satisfactory academic progress; and

34(v) require that—

35(I) a scholarship recipient who fails to maintain a high level of academic standing, as defined by the Secretary, who is dismissed for disciplinary reasons from the educational institution such recipient is attending, or who voluntarily terminates academic training before graduation from the educational program for which the scholarship was awarded shall be liable to the United States for repayment within 1 year after the date of such default of all scholarship funds paid to such recipient and to the institution of higher education on the behalf of such recipient, provided that the repayment period may be extended by the Secretary if the Secretary determines it necessary, as established by regulation; and

36(II) a scholarship recipient who, for any reason except death or disability, fails to begin or complete the post-doctoral service requirements in a technical nuclear forensics-related specialty at a national laboratory or appropriate Federal agency after completion of academic training shall be liable to the United States for an amount equal to—

37(aa) the total amount of the scholarship received by such recipient under this section; and

38(bb) the interest on such amounts which would be payable if at the time the scholarship was received such scholarship was a loan bearing interest at the maximum legally prevailing rate;

39(13) provide an annual report to Congress on the activities carried out under paragraphs (10), (11), and (12); and

40(14) perform other duties as assigned by the Secretary.

41In this section:

42The term "Alaska Native-serving institution" has the meaning given the term in section 1059d of title 20.

43The term "Asian American and Native American Pacific Islander-serving institution" has the meaning given the term in section 1059g of title 20.

44The term "Hawaiian native-serving institution" 1 has the meaning given the term in section 1059d of title 20.

45The term "Hispanic-serving institution" has the meaning given that term in section 1101a of title 20.

46The term "historically Black college or university" has the meaning given the term "part B institution" in section 1061(2) of title 20.

47The term "Tribal College or University" has the meaning given that term in section 1059c(b) of title 20.

592a.

Technology research and development investment strategy for nuclear and radiological detection

1Not later than 1 year after October 13, 2006, the Secretary, the Secretary of Energy, the Secretary of Defense, and the Director of National Intelligence shall submit to Congress a research and development investment strategy for nuclear and radiological detection.

2The strategy under subsection (a) shall include—

3(1) a long term technology roadmap for nuclear and radiological detection applicable to the mission needs of the Department, the Department of Energy, the Department of Defense, and the Office of the Director of National Intelligence;

4(2) budget requirements necessary to meet the roadmap; and

5(3) documentation of how the Department, the Department of Energy, the Department of Defense, and the Office of the Director of National Intelligence will execute this strategy.

6Not later than 1 year after October 13, 2006, the Secretary shall submit a report to the appropriate congressional committees on—

7(1) the impact of this title,1 and the amendments made by this title, on the responsibilities under section 182 of this title; and

8(2) the efforts of the Department to coordinate, integrate, and establish priorities for conducting all basic and applied research, development, testing, and evaluation of technology and systems to detect, prevent, protect, and respond to chemical, biological, radiological, and nuclear terrorist attacks.

9The Director for Domestic Nuclear Detection 2 and the Under Secretary for Science and Technology shall jointly and annually notify Congress that the strategy and technology road map for nuclear and radiological detection developed under subsections (a) and (b) is consistent with the national policy and strategic plan for identifying priorities, goals, objectives, and policies for coordinating the Federal Government's civilian efforts to identify and develop countermeasures to terrorist threats from weapons of mass destruction that are required under section 182(2) of this title.

593.

Hiring authority

1In hiring personnel for the Office, the Secretary shall have the hiring and management authorities provided in section 1101 1 of the Strom Thurmond National Defense Authorization Act for Fiscal Year 1999 (5 U.S.C. 3104 note). The term of appointments for employees under subsection (c)(1) of such section may not exceed 5 years before granting any extension under subsection (c)(2) of such section.

594.

Testing authority

1The Director shall coordinate with the responsible Federal agency or other entity to facilitate the use by the Office, by its contractors, or by other persons or entities, of existing Government laboratories, centers, ranges, or other testing facilities for the testing of materials, equipment, models, computer software, and other items as may be related to the missions identified in section 592 of this title. Any such use of Government facilities shall be carried out in accordance with all applicable laws, regulations, and contractual provisions, including those governing security, safety, and environmental protection, including, when applicable, the provisions of section 189 of this title. The Office may direct that private sector entities utilizing Government facilities in accordance with this section pay an appropriate fee to the agency that owns or operates those facilities to defray additional costs to the Government resulting from such use.

2The results of tests performed with services made available shall be confidential and shall not be disclosed outside the Federal Government without the consent of the persons for whom the tests are performed.

3Fees for services made available under this section shall not exceed the amount necessary to recoup the direct and indirect costs involved, such as direct costs of utilities, contractor support, and salaries of personnel that are incurred by the United States to provide for the testing.

4Fees received for services made available under this section may be credited to the appropriation from which funds were expended to provide such services.

595.

Repealed. Pub. L. 115–387, §2(a)(4), Dec. 21, 2018, 132 Stat. 5163

596.

Contracting and grant making authorities

1The Secretary, acting through the Assistant Secretary, in carrying out the responsibilities under section 592 of this title, shall—

2(1) operate extramural and intramural programs and distribute funds through grants, cooperative agreements, and other transactions and contracts;

3(2) ensure that activities under section 592 of this title include investigations of radiation detection equipment in configurations suitable for deployment at seaports, which may include underwater or water surface detection equipment and detection equipment that can be mounted on cranes and straddle cars used to move shipping containers; and

4(3) have the authority to establish or contract with 1 or more federally funded research and development centers to provide independent analysis of homeland security issues and carry out other responsibilities under this subchapter.

596a.

Joint annual interagency review of global nuclear detection architecture

1The Secretary, the Attorney General, the Secretary of State, the Secretary of Defense, the Secretary of Energy, and the Director of National Intelligence shall jointly ensure interagency coordination on the development and implementation of the global nuclear detection architecture by ensuring that, not less frequently than once each year—

2(A) each relevant agency, office, or entity—

3(i) assesses its involvement, support, and participation in the development, revision, and implementation of the global nuclear detection architecture; and

4(ii) examines and evaluates components of the global nuclear detection architecture (including associated strategies and acquisition plans) relating to the operations of that agency, office, or entity, to determine whether such components incorporate and address current threat assessments, scenarios, or intelligence analyses developed by the Director of National Intelligence or other agencies regarding threats relating to nuclear or radiological weapons of mass destruction;

5(B) each agency, office, or entity deploying or operating any nuclear or radiological detection technology under the global nuclear detection architecture—

6(i) evaluates the deployment and operation of nuclear or radiological detection technologies under the global nuclear detection architecture by that agency, office, or entity;

7(ii) identifies performance deficiencies and operational or technical deficiencies in nuclear or radiological detection technologies deployed under the global nuclear detection architecture; and

8(iii) assesses the capacity of that agency, office, or entity to implement the responsibilities of that agency, office, or entity under the global nuclear detection architecture; and

9(C) the Assistant Secretary and each of the relevant departments that are partners in the National Technical Forensics Center—

10(i) include, as part of the assessments, evaluations, and reviews required under this paragraph, each office's or department's activities and investments in support of nuclear forensics and attribution activities and specific goals and objectives accomplished during the previous year pursuant to the national strategic five-year plan for improving the nuclear forensic and attribution capabilities of the United States required under section 1036 of the National Defense Authorization Act for Fiscal Year 2010;

11(ii) attaches, as an appendix to the Joint Interagency Annual Review, the most current version of such strategy and plan; and

12(iii) includes a description of new or amended bilateral and multilateral agreements and efforts in support of nuclear forensics and attribution activities accomplished during the previous year.

13Not less frequently than once each year, the Secretary shall examine and evaluate the development, assessment, and acquisition of radiation detection technologies deployed or implemented in support of the domestic portion of the global nuclear detection architecture.

14Not later than March 31 of each year, the Secretary, the Attorney General, the Secretary of State, the Secretary of Defense, the Secretary of Energy, and the Director of National Intelligence, shall jointly submit a report regarding the implementation of this section and the results of the reviews required under subsection (a) to—

15(A) the President;

16(B) the Committee on Appropriations, the Committee on Armed Services, the Select Committee on Intelligence, and the Committee on Homeland Security and Governmental Affairs of the Senate; and

17(C) the Committee on Appropriations, the Committee on Armed Services, the Permanent Select Committee on Intelligence, the Committee on Homeland Security, and the Committee on Science and Technology of the House of Representatives.

18The annual report submitted under paragraph (1) shall be submitted in unclassified form to the maximum extent practicable, but may include a classified annex.

19In this section, the term "global nuclear detection architecture" means the global nuclear detection architecture developed under section 592 of this title.

596b.

Securing the Cities program

1The Secretary, through the Assistant Secretary, shall establish a program, to be known as the "Securing the Cities" or "STC" program, to enhance the ability of the United States to detect and prevent terrorist attacks and other high-consequence events utilizing nuclear or other radiological materials that pose a high risk to homeland security in high-risk urban areas.

2Through the STC program the Secretary shall—

3(1) assist State, local, Tribal, and territorial governments in designing and implementing, or enhancing existing, architectures for coordinated and integrated detection and interdiction of nuclear or other radiological materials that are out of regulatory control;

4(2) support the development of an operating capability to detect and report on nuclear and other radiological materials out of regulatory control;

5(3) provide resources to enhance detection, analysis, communication, and coordination to better integrate State, local, Tribal, and territorial assets into Federal operations;

6(4) facilitate alarm adjudication and provide subject matter expertise and technical assistance on concepts of operations, training, exercises, and alarm response protocols;

7(5) communicate with, and promote sharing of information about the presence or detection of nuclear or other radiological materials among appropriate Federal, State, local, Tribal, and territorial government agencies, in a manner that ensures transparency with the jurisdictions designated under subsection (c);

8(6) provide augmenting resources, as appropriate, to enable State, local, Tribal, and territorial governments to sustain and refresh their capabilities developed under the STC program;

9(7) monitor expenditures under the STC program and track performance in meeting the goals of the STC program; and

10(8) provide any other assistance the Secretary determines appropriate.

11In carrying out the STC program under subsection (a), the Secretary shall designate jurisdictions from among high-risk urban areas under section 604 of this title.

12The Secretary shall notify the Committee on Homeland Security and the Committee on Appropriations of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Appropriations of the Senate not later than 3 days before the designation of a new jurisdiction under paragraph (1) or any change to a jurisdiction previously designated under that paragraph.

13The Secretary shall develop, in consultation with relevant stakeholders, an implementation plan for carrying out the STC program that includes—

14(i) a discussion of the goals of the STC program and a strategy to achieve those goals;

15(ii) performance metrics and milestones for the STC program;

16(iii) measures for achieving and sustaining capabilities under the STC program; and

17(iv) costs associated with achieving the goals of the STC program.

18Not later than one year after December 21, 2018, the Secretary shall submit to the appropriate congressional committees and the Comptroller General of the United States the implementation plan required by subparagraph (A).

19Not later than one year after the submission of the implementation plan under paragraph (1)(B), the Secretary shall submit to the appropriate congressional committees and the Comptroller General a report that includes—

20(A) an assessment of the effectiveness of the STC program, based on the performance metrics and milestones required by paragraph (1)(A)(ii); and

21(B) proposals for any changes to the STC program, including an explanation of how those changes align with the strategy and goals of the STC program and, as appropriate, address any challenges faced by the STC program.

22Not later than 18 months after the submission of the report required by paragraph (2), the Comptroller General of the United States shall submit to the appropriate congressional committees a report evaluating the implementation plan required by paragraph (1) and the report required by paragraph (2), including an assessment of progress made with respect to the performance metrics and milestones required by paragraph (1)(A)(ii) and the sustainment of the capabilities of the STC program.

23Before making any changes to the structure or requirements of the STC program, the Assistant Secretary shall—

24(A) consult with the appropriate congressional committees; and

25(B) provide to those committees—

26(i) a briefing on the proposed changes, including a justification for the changes;

27(ii) documentation relating to the changes, including plans, strategies, and resources to implement the changes; and

28(iii) an assessment of the effect of the changes on the capabilities of the STC program, taking into consideration previous resource allocations and stakeholder input.

597.

Chief Medical Officer

1There is in the Office a Chief Medical Officer, who shall be appointed by the President. The Chief Medical Officer shall report to the Assistant Secretary.

2The individual appointed as Chief Medical Officer shall be a licensed physician possessing a demonstrated ability in and knowledge of medicine and public health.

3The Chief Medical Officer shall have the responsibility within the Department for medical issues related to natural disasters, acts of terrorism, and other man-made disasters, including—

4(1) serving as the principal advisor on medical and public health issues to the Secretary, the Administrator of the Federal Emergency Management Agency, the Assistant Secretary, and other Department officials;

5(2) providing operational medical support to all components of the Department;

6(3) as appropriate, providing medical liaisons to the components of the Department, on a reimbursable basis, to provide subject matter expertise on operational medical issues;

7(4) coordinating with Federal, State, local, and Tribal governments, the medical community, and others within and outside the Department, including the Centers for Disease Control and Prevention and the Office of the Assistant Secretary for Preparedness and Response of the Department of Health and Human Services, with respect to medical and public health matters; and

8(5) performing such other duties relating to such responsibilities as the Secretary may require.

597a.

Medical countermeasures

1Subject to the availability of appropriations, the Secretary shall, as appropriate, establish a medical countermeasures program within the components of the Department to—

2(1) facilitate personnel readiness and protection for the employees and working animals of the Department in the event of a chemical, biological, radiological, nuclear, or explosives attack, naturally occurring disease outbreak, other event impacting health, or pandemic; and

3(2) support the mission continuity of the Department.

4The Secretary, acting through the Chief Medical Officer of the Department, shall—

5(1) provide programmatic oversight of the medical countermeasures program established under subsection (a); and

6(2) develop standards for—

7(A) medical countermeasure storage, security, dispensing, and documentation;

8(B) maintaining a stockpile of medical countermeasures, including antibiotics, antivirals, antidotes, therapeutics, and radiological countermeasures, as appropriate;

9(C) ensuring adequate partnerships with manufacturers and executive agencies that enable advance prepositioning by vendors of inventories of appropriate medical countermeasures in strategic locations nationwide, based on risk and employee density, in accordance with applicable Federal statutes and regulations;

10(D) providing oversight and guidance regarding the dispensing of stockpiled medical countermeasures;

11(E) ensuring rapid deployment and dispensing of medical countermeasures in a chemical, biological, radiological, nuclear, or explosives attack, naturally occurring disease outbreak, other event impacting health, or pandemic;

12(F) providing training to employees of the Department on medical countermeasures; and

13(G) supporting dispensing exercises.

14The Secretary, acting through the Chief Medical Officer of the Department, shall establish a medical countermeasures working group comprised of representatives from appropriate components and offices of the Department to ensure that medical countermeasures standards are maintained and guidance is consistent.

15Not later than 120 days after the date on which appropriations are made available to carry out subsection (a), the Chief Medical Officer shall develop and submit to the Secretary an integrated logistics support plan for medical countermeasures, including—

16(1) a methodology for determining the ideal types and quantities of medical countermeasures to stockpile and how frequently such methodology shall be reevaluated;

17(2) a replenishment plan; and

18(3) inventory tracking, reporting, and reconciliation procedures for existing stockpiles and new medical countermeasure purchases.

19Not later than 120 days after December 27, 2021, the Secretary shall transfer all medical countermeasures-related programmatic and personnel resources from the Under Secretary for Management to the Chief Medical Officer.

20In determining the types and quantities of medical countermeasures to stockpile under subsection (d), the Secretary, acting through the Chief Medical Officer of the Department—

21(1) shall use a risk-based methodology for evaluating types and quantities of medical countermeasures required; and

22(2) may use, if available—

23(A) chemical, biological, radiological, and nuclear risk assessments of the Department; and

24(B) guidance on medical countermeasures of the Office of the Assistant Secretary for Preparedness and Response and the Centers for Disease Control and Prevention.

25Not later than 180 days after December 27, 2021, the Secretary shall provide a briefing to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives regarding—

26(1) the plan developed under subsection (d); and

27(2) implementation of the requirements of this section.

28In this section, the term "medical countermeasures" means antibiotics, antivirals, antidotes, therapeutics, radiological countermeasures, and other countermeasures that may be deployed to protect the employees and working animals of the Department in the event of a chemical, biological, radiological, nuclear, or explosives attack, naturally occurring disease outbreak, other event impacting health, or pandemic.

601.

Definitions

1In this subchapter, the following definitions shall apply:

2The term "Administrator" means the Administrator of the Federal Emergency Management Agency.

3The term "appropriate committees of Congress" means—

4(A) the Committee on Homeland Security and Governmental Affairs of the Senate; and

5(B) those committees of the House of Representatives that the Speaker of the House of Representatives determines appropriate.

6The term "critical infrastructure sectors" means the following sectors, in both urban and rural areas:

7(A) Agriculture and food.

8(B) Banking and finance.

9(C) Chemical industries.

10(D) Commercial facilities.

11(E) Commercial nuclear reactors, materials, and waste.

12(F) Dams.

13(G) The defense industrial base.

14(H) Emergency services.

15(I) Energy.

16(J) Government facilities.

17(K) Information technology.

18(L) National monuments and icons.

19(M) Postal and shipping.

20(N) Public health and health care.

21(O) Telecommunications.

22(P) Transportation systems.

23(Q) Water.

24The term "directly eligible tribe" means—

25(A) any Indian tribe—

26(i) that is located in the continental United States;

27(ii) that operates a law enforcement or emergency response agency with the capacity to respond to calls for law enforcement or emergency services;

28(iii)(I) that is located on or near an international border or a coastline bordering an ocean (including the Gulf of Mexico) or international waters;

29(II) that is located within 10 miles of a system or asset included on the prioritized critical infrastructure list established under section 664(a)(2) of this title or has such a system or asset within its territory;

30(III) that is located within or contiguous to 1 of the 50 most populous metropolitan statistical areas in the United States; or

31(IV) the jurisdiction of which includes not less than 1,000 square miles of Indian country, as that term is defined in section 1151 of title 18; and

32(iv) that certifies to the Secretary that a State has not provided funds under section 604 or 605 of this title to the Indian tribe or consortium of Indian tribes for the purpose for which direct funding is sought; and

33(B) a consortium of Indian tribes, if each tribe satisfies the requirements of subparagraph (A).

34The term "eligible metropolitan area" means any of the 100 most populous metropolitan statistical areas in the United States.

35The term "high-risk urban area" means a high-risk urban area designated under section 604(b)(3)(A) of this title.

36The term "Indian tribe" has the meaning given that term in section 5304(e) of title 25.

37The term "metropolitan statistical area" means a metropolitan statistical area, as defined by the Office of Management and Budget.

38The term "National Special Security Event" means a designated event that, by virtue of its political, economic, social, or religious significance, may be the target of terrorism or other criminal activity.

39The term "population" means population according to the most recent United States census population estimates available at the start of the relevant fiscal year.

40The term "population density" means population divided by land area in square miles.

41The term "qualified intelligence analyst" means an intelligence analyst (as that term is defined in section 124h(j) of this title), including law enforcement personnel—

42(A) who has successfully completed training to ensure baseline proficiency in intelligence analysis and production, as determined by the Secretary, which may include training using a curriculum developed under section 124f of this title; or

43(B) whose experience ensures baseline proficiency in intelligence analysis and production equivalent to the training required under subparagraph (A), as determined by the Secretary.

44The term "target capabilities" means the target capabilities for Federal, State, local, and tribal government preparedness for which guidelines are required to be established under section 746(a) of this title.

45The term "tribal government" means the government of an Indian tribe.

603.

Homeland security grant programs

1The Secretary, through the Administrator, may award grants under sections 604, 605, and 609a of this title to State, local, and tribal governments.

2This part shall not be construed to affect any of the following Federal programs:

3(1) Firefighter and other assistance programs authorized under the Federal Fire Prevention and Control Act of 1974 (15 U.S.C. 2201 et seq.).

4(2) Grants authorized under the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.).

5(3) Emergency Management Performance Grants under the amendments made by title II of the Implementing Recommendations of the 9/11 Commission Act of 2007.

6(4) Grants to protect critical infrastructure, including port security grants authorized under section 70107 of title 46 and the grants authorized under title 1 XIV and XV of the Implementing Recommendations of the 9/11 Commission Act of 2007 [6 U.S.C. 1131 et seq., 1151 et seq.] and the amendments made by such titles.

7(5) The Metropolitan Medical Response System authorized under section 723 of this title.

8(6) The Interoperable Emergency Communications Grant Program authorized under subchapter XIII.

9(7) Grant programs other than those administered by the Department.

10The grant programs authorized under sections 604 and 605 of this title shall supercede all grant programs authorized under section 1014 of the USA PATRIOT Act (42 U.S.C. 3714).2

11The allocation of grants authorized under section 604 or 605 of this title shall be governed by the terms of this part and not by any other provision of law.

604.

Urban Area Security Initiative

1There is established an Urban Area Security Initiative to provide grants to assist high-risk urban areas in preventing, preparing for, protecting against, and responding to acts of terrorism.

2The Administrator shall designate high-risk urban areas to receive grants under this section based on procedures under this subsection.

3For each fiscal year, the Administrator shall conduct an initial assessment of the relative threat, vulnerability, and consequences from acts of terrorism faced by each eligible metropolitan area, including consideration of—

4(i) the factors set forth in subparagraphs (A) through (H) and (K) of section 608(a)(1) of this title; and

5(ii) information and materials submitted under subparagraph (B).

6Prior to conducting each initial assessment under subparagraph (A), the Administrator shall provide each eligible metropolitan area with, and shall notify each eligible metropolitan area of, the opportunity to—

7(i) submit information that the eligible metropolitan area believes to be relevant to the determination of the threat, vulnerability, and consequences it faces from acts of terrorism; and

8(ii) review the risk assessment conducted by the Department of that eligible metropolitan area, including the bases for the assessment by the Department of the threat, vulnerability, and consequences from acts of terrorism faced by that eligible metropolitan area, and remedy erroneous or incomplete information.

9For each fiscal year, after conducting the initial assessment under paragraph (2), and based on that assessment, the Administrator shall designate high-risk urban areas that may submit applications for grants under this section.

10Notwithstanding paragraph (2), the Administrator may—

11(I) in any case where an eligible metropolitan area consists of more than 1 metropolitan division (as that term is defined by the Office of Management and Budget) designate more than 1 high-risk urban area within a single eligible metropolitan area; and

12(II) designate an area that is not an eligible metropolitan area as a high-risk urban area based on the assessment by the Administrator of the relative threat, vulnerability, and consequences from acts of terrorism faced by the area.

13Nothing in this subsection may be construed to require the Administrator to—

14(I) designate all eligible metropolitan areas that submit information to the Administrator under paragraph (2)(B)(i) as high-risk urban areas; or

15(II) designate all areas within an eligible metropolitan area as part of the high-risk urban area.

16In designating high-risk urban areas under subparagraph (A), the Administrator shall determine which jurisdictions, at a minimum, shall be included in each high-risk urban area.

17A high-risk urban area designated by the Administrator may, in consultation with the State or States in which such high-risk urban area is located, add additional jurisdictions to the high-risk urban area.

18An area designated as a high-risk urban area under subsection (b) may apply for a grant under this section.

19In an application for a grant under this section, a high-risk urban area shall submit—

20(A) a plan describing the proposed division of responsibilities and distribution of funding among the local and tribal governments in the high-risk urban area;

21(B) the name of an individual to serve as a high-risk urban area liaison with the Department and among the various jurisdictions in the high-risk urban area; and

22(C) such information in support of the application as the Administrator may reasonably require.

23Applicants for grants under this section shall apply or reapply on an annual basis.

24To ensure consistency with State homeland security plans, a high-risk urban area applying for a grant under this section shall submit its application to each State within which any part of that high-risk urban area is located for review before submission of such application to the Department.

25Not later than 30 days after receiving an application from a high-risk urban area under subparagraph (A), a State shall transmit the application to the Department.

26If the Governor of a State determines that an application of a high-risk urban area is inconsistent with the State homeland security plan of that State, or otherwise does not support the application, the Governor shall—

27(i) notify the Administrator, in writing, of that fact; and

28(ii) provide an explanation of the reason for not supporting the application at the time of transmission of the application.

29In considering applications for grants under this section, the Administrator shall provide applicants with a reasonable opportunity to correct defects in the application, if any, before making final awards.

30If the Administrator approves the application of a high-risk urban area for a grant under this section, the Administrator shall distribute the grant funds to the State or States in which that high-risk urban area is located.

31Not later than 45 days after the date that a State receives grant funds under paragraph (1), that State shall provide the high-risk urban area awarded that grant not less than 80 percent of the grant funds. Any funds retained by a State shall be expended on items, services, or activities that benefit the high-risk urban area.

32A State shall provide each relevant high-risk urban area with an accounting of the items, services, or activities on which any funds retained by the State under subparagraph (A) were expended.

33If parts of a high-risk urban area awarded a grant under this section are located in 2 or more States, the Administrator shall distribute to each such State—

34(A) a portion of the grant funds in accordance with the proposed distribution set forth in the application; or

35(B) if no agreement on distribution has been reached, a portion of the grant funds determined by the Administrator to be appropriate.

36A State that receives grant funds under paragraph (1) shall certify to the Administrator that the State has made available to the applicable high-risk urban area the required funds under paragraph (2).

37There are authorized to be appropriated for grants under this section—

38(1) $850,000,000 for fiscal year 2008;

39(2) $950,000,000 for fiscal year 2009;

40(3) $1,050,000,000 for fiscal year 2010;

41(4) $1,150,000,000 for fiscal year 2011;

42(5) $1,300,000,000 for fiscal year 2012; and

43(6) such sums as are necessary for fiscal year 2013, and each fiscal year thereafter.

605.

State Homeland Security Grant Program

1There is established a State Homeland Security Grant Program to assist State, local, and tribal governments in preventing, preparing for, protecting against, and responding to acts of terrorism.

2Each State may apply for a grant under this section, and shall submit such information in support of the application as the Administrator may reasonably require.

3The Administrator shall require that each State include in its application, at a minimum—

4(A) the purpose for which the State seeks grant funds and the reasons why the State needs the grant to meet the target capabilities of that State;

5(B) a description of how the State plans to allocate the grant funds to local governments and Indian tribes; and

6(C) a budget showing how the State intends to expend the grant funds.

7Applicants for grants under this section shall apply or reapply on an annual basis.

8Not later than 45 days after receiving grant funds, any State receiving a grant under this section shall make available to local and tribal governments, consistent with the applicable State homeland security plan—

9(A) not less than 80 percent of the grant funds;

10(B) with the consent of local and tribal governments, items, services, or activities having a value of not less than 80 percent of the amount of the grant; or

11(C) with the consent of local and tribal governments, grant funds combined with other items, services, or activities having a total value of not less than 80 percent of the amount of the grant.

12A State shall certify to the Administrator that the State has made the distribution to local and tribal governments required under paragraph (1).

13The Governor of a State may request in writing that the Administrator extend the period under paragraph (1) for an additional period of time. The Administrator may approve such a request if the Administrator determines that the resulting delay in providing grant funding to the local and tribal governments is necessary to promote effective investments to prevent, prepare for, protect against, or respond to acts of terrorism.

14Paragraph (1) shall not apply to the District of Columbia, the Commonwealth of Puerto Rico, American Samoa, the Commonwealth of the Northern Mariana Islands, Guam, or the Virgin Islands.

15If a State fails to make the distribution to local or tribal governments required under paragraph (1) in a timely fashion, a local or tribal government entitled to receive such distribution may petition the Administrator to request that grant funds be provided directly to the local or tribal government.

16Instead of, or in addition to, any application for a grant under subsection (b), 2 or more States may submit an application for a grant under this section in support of multistate efforts to prevent, prepare for, protect against, and respond to acts of terrorism.

17If a group of States applies for a grant under this section, such States shall submit to the Administrator at the time of application a plan describing—

18(A) the division of responsibilities for administering the grant; and

19(B) the distribution of funding among the States that are parties to the application.

20In allocating funds under this section, the Administrator shall ensure that—

21(A) except as provided in subparagraph (B), each State receives, from the funds appropriated for the State Homeland Security Grant Program established under this section, not less than an amount equal to—

22(i) 0.375 percent of the total funds appropriated for grants under this section and section 604 of this title in fiscal year 2008;

23(ii) 0.365 percent of the total funds appropriated for grants under this section and section 604 of this title in fiscal year 2009;

24(iii) 0.36 percent of the total funds appropriated for grants under this section and section 604 of this title in fiscal year 2010;

25(iv) 0.355 percent of the total funds appropriated for grants under this section and section 604 of this title in fiscal year 2011; and

26(v) 0.35 percent of the total funds appropriated for grants under this section and section 604 of this title in fiscal year 2012 and in each fiscal year thereafter; and

27(B) for each fiscal year, American Samoa, the Commonwealth of the Northern Mariana Islands, Guam, and the Virgin Islands each receive, from the funds appropriated for the State Homeland Security Grant Program established under this section, not less than an amount equal to 0.08 percent of the total funds appropriated for grants under this section and section 604 of this title.

28Any portion of a multistate award provided to a State under subsection (d) shall be considered in calculating the minimum State allocation under this subsection.

29There are authorized to be appropriated for grants under this section—

30(1) $950,000,000 for each of fiscal years 2008 through 2012; and

31(2) such sums as are necessary for fiscal year 2013, and each fiscal year thereafter.

606.

Grants to directly eligible tribes

1Notwithstanding section 605(b) of this title, the Administrator may award grants to directly eligible tribes under section 605 of this title.

2A directly eligible tribe may apply for a grant under section 605 of this title by submitting an application to the Administrator that includes, as appropriate, the information required for an application by a State under section 605(b) of this title.

3To ensure consistency with any applicable State homeland security plan, a directly eligible tribe applying for a grant under section 605 of this title shall provide a copy of its application to each State within which any part of the tribe is located for review before the tribe submits such application to the Department.

4If the Governor of a State determines that the application of a directly eligible tribe is inconsistent with the State homeland security plan of that State, or otherwise does not support the application, not later than 30 days after the date of receipt of that application the Governor shall—

5(A) notify the Administrator, in writing, of that fact; and

6(B) provide an explanation of the reason for not supporting the application.

7The Administrator shall have final authority to approve any application of a directly eligible tribe. The Administrator shall notify each State within the boundaries of which any part of a directly eligible tribe is located of the approval of an application by the tribe.

8The Administrator shall allocate funds to directly eligible tribes in accordance with the factors applicable to allocating funds among States under section 608 of this title.

9If the Administrator awards funds to a directly eligible tribe under this section, the Administrator shall distribute the grant funds directly to the tribe and not through any State.

10In allocating funds under this section, the Administrator shall ensure that, for each fiscal year, directly eligible tribes collectively receive, from the funds appropriated for the State Homeland Security Grant Program established under section 605 of this title, not less than an amount equal to 0.1 percent of the total funds appropriated for grants under sections 604 and 605 of this title.

11This subsection shall not apply in any fiscal year in which the Administrator—

12(A) receives fewer than 5 applications under this section; or

13(B) does not approve at least 2 applications under this section.

14A directly eligible tribe applying for a grant under section 605 of this title shall designate an individual to serve as a tribal liaison with the Department and other Federal, State, local, and regional government officials concerning preventing, preparing for, protecting against, and responding to acts of terrorism.

15A directly eligible tribe that receives a grant under section 605 of this title may receive funds for other purposes under a grant from the State or States within the boundaries of which any part of such tribe is located and from any high-risk urban area of which it is a part, consistent with the homeland security plan of the State or high-risk urban area.

16States shall be responsible for allocating grant funds received under section 605 of this title to tribal governments in order to help those tribal communities achieve target capabilities not achieved through grants to directly eligible tribes.

17With respect to a grant to a State under section 605 of this title, an Indian tribe shall be eligible for funding directly from that State, and shall not be required to seek funding from any local government.

18A State may not impose unreasonable or unduly burdensome requirements on an Indian tribe as a condition of providing the Indian tribe with grant funds or resources under section 605 of this title.

19Nothing in this section shall be construed to affect the authority of an Indian tribe that receives funds under this part.

607.

Terrorism prevention

1The Administrator shall ensure that not less than 25 percent of the total combined funds appropriated for grants under sections 604 and 605 of this title is used for law enforcement terrorism prevention activities.

2Law enforcement terrorism prevention activities include—

3(A) information sharing and analysis;

4(B) target hardening;

5(C) threat recognition;

6(D) terrorist interdiction;

7(E) training exercises to enhance preparedness for and response to mass casualty and active shooter incidents and security events at public locations, including airports and mass transit systems;

8(F) overtime expenses consistent with a State homeland security plan, including for the provision of enhanced law enforcement operations in support of Federal agencies, including for increased border security and border crossing enforcement;

9(G) establishing, enhancing, and staffing with appropriately qualified personnel State, local, and regional fusion centers that comply with the guidelines established under section 124h(i) of this title;

10(H) paying salaries and benefits for personnel, including individuals employed by the grant recipient on the date of the relevant grant application, to serve as qualified intelligence analysts;

11(I) any other activity permitted under the Fiscal Year 2007 Program Guidance of the Department for the Law Enforcement Terrorism Prevention Program; and

12(J) any other terrorism prevention activity authorized by the Administrator.

13The Administrator shall ensure that grant funds described in paragraph (1) are used to support the participation, as appropriate, of law enforcement and other emergency response providers from rural and other underrepresented communities at risk from acts of terrorism in fusion centers.

14There is established in the Policy Directorate of the Department an Office for State and Local Law Enforcement, which shall be headed by an Assistant Secretary for State and Local Law Enforcement.

15The Assistant Secretary for State and Local Law Enforcement shall have an appropriate background with experience in law enforcement, intelligence, and other counterterrorism functions.

16The Secretary shall assign to the Office for State and Local Law Enforcement permanent staff and, as appropriate and consistent with sections 316(c)(2), 381, and 468(d) of this title, other appropriate personnel detailed from other components of the Department to carry out the responsibilities under this subsection.

17The Assistant Secretary for State and Local Law Enforcement shall—

18(A) lead the coordination of Department-wide policies relating to the role of State and local law enforcement in preventing, preparing for, protecting against, and responding to natural disasters, acts of terrorism, and other man-made disasters within the United States;

19(B) serve as a liaison between State, local, and tribal law enforcement agencies and the Department;

20(C) coordinate with the Office of Intelligence and Analysis to ensure the intelligence and information sharing requirements of State, local, and tribal law enforcement agencies are being addressed;

21(D) work with the Administrator to ensure that law enforcement and terrorism-focused grants to State, local, and tribal government agencies, including grants under sections 604 and 605 of this title, the Commercial Equipment Direct Assistance Program, and other grants administered by the Department to support fusion centers and law enforcement-oriented programs, are appropriately focused on terrorism prevention activities;

22(E) coordinate with the Science and Technology Directorate, the Federal Emergency Management Agency, the Department of Justice, the National Institute of Justice, law enforcement organizations, and other appropriate entities to support the development, promulgation, and updating, as necessary, of national voluntary consensus standards for training and personal protective equipment to be used in a tactical environment by law enforcement officers; and

23(F) conduct, jointly with the Administrator, a study to determine the efficacy and feasibility of establishing specialized law enforcement deployment teams to assist State, local, and tribal governments in responding to natural disasters, acts of terrorism, or other man-made disasters and report on the results of that study to the appropriate committees of Congress.

24Nothing in this subsection shall be construed to diminish, supercede, or replace the responsibilities, authorities, or role of the Administrator.

608.

Prioritization

1In allocating funds among States and high-risk urban areas applying for grants under section 604 or 605 of this title, the Administrator shall consider, for each State or high-risk urban area—

2(1) its relative threat, vulnerability, and consequences from acts of terrorism, including consideration of—

3(A) its population, including appropriate consideration of military, tourist, and commuter populations;

4(B) its population density;

5(C) its history of threats, including whether it has been the target of a prior act of terrorism;

6(D) its degree of threat, vulnerability, and consequences related to critical infrastructure (for all critical infrastructure sectors) or key resources identified by the Administrator or the State homeland security plan, including threats, vulnerabilities, and consequences related to critical infrastructure or key resources in nearby jurisdictions;

7(E) the most current threat assessments available to the Department;

8(F) whether the State has, or the high-risk urban area is located at or near, an international border;

9(G) whether it has a coastline bordering an ocean (including the Gulf of Mexico) or international waters;

10(H) its likely need to respond to acts of terrorism occurring in nearby jurisdictions;

11(I) the extent to which it has unmet target capabilities;

12(J) in the case of a high-risk urban area, the extent to which that high-risk urban area includes—

13(i) those incorporated municipalities, counties, parishes, and Indian tribes within the relevant eligible metropolitan area, the inclusion of which will enhance regional efforts to prevent, prepare for, protect against, and respond to acts of terrorism; and

14(ii) other local and tribal governments in the surrounding area that are likely to be called upon to respond to acts of terrorism within the high-risk urban area; and

15(K) such other factors as are specified in writing by the Administrator; and

16(2) the anticipated effectiveness of the proposed use of the grant by the State or high-risk urban area in increasing the ability of that State or high-risk urban area to prevent, prepare for, protect against, and respond to acts of terrorism, to meet its target capabilities, and to otherwise reduce the overall risk to the high-risk urban area, the State, or the Nation.

17In assessing threat under this section, the Administrator shall consider the following types of threat to critical infrastructure sectors and to populations in all areas of the United States, urban and rural:

18(1) Biological.

19(2) Chemical.

20(3) Cyber.

21(4) Explosives.

22(5) Incendiary.

23(6) Nuclear.

24(7) Radiological.

25(8) Suicide bombers.

26(9) Such other types of threat determined relevant by the Administrator.

609.

Use of funds

1The Administrator shall permit the recipient of a grant under section 604 or 605 of this title to use grant funds to achieve target capabilities related to preventing, preparing for, protecting against, and responding to acts of terrorism, consistent with a State homeland security plan and relevant local, tribal, and regional homeland security plans, including by working in conjunction with a National Laboratory (as defined in section 15801(3) of title 42), through—

2(1) developing and enhancing homeland security, emergency management, or other relevant plans, assessments, or mutual aid agreements;

3(2) designing, conducting, and evaluating training and exercises, including training and exercises conducted under section 321a of this title and section 748 of this title;

4(3) protecting a system or asset included on the prioritized critical infrastructure list established under section 664(a)(2) of this title;

5(4) purchasing, upgrading, storing, or maintaining equipment, including computer hardware and software;

6(5) ensuring operability and achieving interoperability of emergency communications;

7(6) responding to an increase in the threat level under the Homeland Security Advisory System, or to the needs resulting from a National Special Security Event;

8(7) establishing, enhancing, and staffing with appropriately qualified personnel State, local, and regional fusion centers that comply with the guidelines established under section 124h(i) of this title;

9(8) enhancing school preparedness;

10(9) enhancing the security and preparedness of secure and nonsecure areas of eligible airports and surface transportation systems;

11(10) supporting public safety answering points;

12(11) paying salaries and benefits for personnel, including individuals employed by the grant recipient on the date of the relevant grant application, to serve as qualified intelligence analysts, regardless of whether such analysts are current or new full-time employees or contract employees;

13(12) paying expenses directly related to administration of the grant, except that such expenses may not exceed 3 percent of the amount of the grant;

14(13) any activity permitted under the Fiscal Year 2007 Program Guidance of the Department for the State Homeland Security Grant Program, the Urban Area Security Initiative (including activities permitted under the full-time counterterrorism staffing pilot), or the Law Enforcement Terrorism Prevention Program;

15(14) migrating any online service (as defined in section 3 of the DOTGOV Online Trust in Government Act of 2020) 1 to the .gov internet domain; and

16(15) any other appropriate activity, as determined by the Administrator.

17Funds provided under section 604 or 605 of this title may not be used—

18(A) to supplant State or local funds, except that nothing in this paragraph shall prohibit the use of grant funds provided to a State or high-risk urban area for otherwise permissible uses under subsection (a) on the basis that a State or high-risk urban area has previously used State or local funds to support the same or similar uses; or

19(B) for any State or local government cost-sharing contribution.

20Not more than 50 percent of the amount awarded to a grant recipient under section 604 or 605 of this title in any fiscal year may be used to pay for personnel, including overtime and backfill costs, in support of the permitted uses under subsection (a).

21At the request of the recipient of a grant under section 604 or 605 of this title, the Administrator may grant a waiver of the limitation under subparagraph (A).

22With respect to the use of amounts awarded to a grant recipient under section 604 or 605 of this title for personnel costs in accordance with paragraph (2) of this subsection, the Administrator may not—

23(i) impose a limit on the amount of the award that may be used to pay for personnel, or personnel-related, costs that is higher or lower than the percent limit imposed in paragraph (2)(A); or

24(ii) impose any additional limitation on the portion of the funds of a recipient that may be used for a specific type, purpose, or category of personnel, or personnel-related, costs.

25If amounts awarded to a grant recipient under section 604 or 605 of this title are used for paying salary or benefits of a qualified intelligence analyst under subsection (a)(10),1 the Administrator shall make such amounts available without time limitations placed on the period of time that the analyst can serve under the grant.

26A grant awarded under section 604 or 605 of this title may not be used to acquire land or to construct buildings or other physical facilities.

27Notwithstanding subparagraph (A), nothing in this paragraph shall prohibit the use of a grant awarded under section 604 or 605 of this title to achieve target capabilities related to preventing, preparing for, protecting against, or responding to acts of terrorism, including through the alteration or remodeling of existing buildings for the purpose of making such buildings secure against acts of terrorism.

28No grant awarded under section 604 or 605 of this title may be used for a purpose described in clause (i) unless—

29(I) specifically approved by the Administrator;

30(II) any construction work occurs under terms and conditions consistent with the requirements under section 5196(j)(9) of title 42; and

31(III) the amount allocated for purposes under clause (i) does not exceed the greater of $1,000,000 or 15 percent of the grant award.

32Grants awarded under this part may not be used for recreational or social purposes.

33Nothing in this part shall be construed to prohibit State, local, or tribal governments from using grant funds under sections 604, 605, and 609a of this title in a manner that enhances preparedness for disasters unrelated to acts of terrorism, if such use assists such governments in achieving target capabilities related to preventing, preparing for, protecting against, or responding to acts of terrorism.

34In addition to the activities described in subsection (a), a grant under section 604 or 605 of this title may be used to provide a reasonable stipend to paid-on-call or volunteer emergency response providers who are not otherwise compensated for travel to or participation in training or exercises related to the purposes of this part. Any such reimbursement shall not be considered compensation for purposes of rendering an emergency response provider an employee under the Fair Labor Standards Act of 1938 (29 U.S.C. 201 et seq.).

35An applicant for a grant under section 604 or 605 of this title may petition the Administrator to use the funds from its grants under those sections for the reimbursement of the cost of any activity relating to preventing, preparing for, protecting against, or responding to acts of terrorism that is a Federal duty and usually performed by a Federal agency, and that is being performed by a State or local government under agreement with a Federal agency.

36Upon request by the recipient of a grant under section 604, 605, or 609a of this title, the Administrator may authorize the grant recipient to transfer all or part of the grant funds from uses specified in the grant agreement to other uses authorized under this section, if the Administrator determines that such transfer is in the interests of homeland security.

37If an applicant for a grant under section 604 or 605 of this title proposes to upgrade or purchase, with assistance provided under that grant, new equipment or systems that do not meet or exceed any applicable national voluntary consensus standards developed under section 747 of this title, the applicant shall include in its application an explanation of why such equipment or systems will serve the needs of the applicant better than equipment or systems that meet or exceed such standards.

38The Administrator shall implement a uniform process for reviewing applications that, in accordance with paragraph (1), contain explanations to use grants provided under section 604 or 605 of this title to purchase equipment or systems that do not meet or exceed any applicable national voluntary consensus standards developed under section 747 of this title.

39In carrying out the review process under paragraph (2), the Administrator shall consider the following:

40(A) Current or past use of proposed equipment or systems by Federal agencies or the Armed Forces.

41(B) The absence of a national voluntary consensus standard for such equipment or systems.

42(C) The existence of an international consensus standard for such equipment or systems, and whether such equipment or systems meets such standard.

43(D) The nature of the capability gap identified by the applicant and how such equipment or systems will address such gap.

44(E) The degree to which such equipment or systems will serve the needs of the applicant better than equipment or systems that meet or exceed existing consensus standards.

45(F) Any other factor determined appropriate by the Administrator.

46The Administrator shall implement a uniform process for reviewing applications to use grants provided under section 604 or 605 of this title to purchase equipment or systems not included on the Authorized Equipment List maintained by the Administrator.

609a.

Nonprofit Security Grant Program

1There is established in the Department a program to be known as the "Nonprofit Security Grant Program" (in this section referred to as the "Program"). Under the Program, the Secretary, acting through the Administrator, shall make grants to eligible nonprofit organizations described in subsection (b), through the State in which such organizations are located, for target hardening and other security enhancements to protect against terrorist attacks or other threats.

2Eligible nonprofit organizations described in this subsection are organizations that are—

3(1) described in section 501(c)(3) of title 26 and exempt from tax under section 501(a) of such title; and

4(2) determined by the Secretary to be at risk of terrorist attacks or other threats.

5The recipient of a grant under this section may use such grant for any of the following uses:

6(A) Target hardening activities, including physical security enhancement equipment, inspection and screening systems, and alteration or remodeling of existing buildings or physical facilities.

7(B) Fees for security training relating to physical security and cybersecurity, target hardening, terrorism awareness, and employee awareness.

8(C) Facility security personnel costs.

9(D) Expenses directly related to the administration of the grant, except that those expenses may not exceed 5 percent of the amount of the grant.

10(E) Any other appropriate activity, including cybersecurity resilience activities, as determined by the Administrator.

11Each State through which a recipient receives a grant under this section may retain not more than 5 percent of each grant for expenses directly related to the administration of the grant.

12If the Administrator establishes target allocations in determining award amounts under the Program, a State may request a project to use a portion of the target allocation for outreach and technical assistance if the State does not receive enough eligible applications from nonprofit organizations located outside high-risk urban areas.

13Any outreach or technical assistance described in subparagraph (A) should prioritize underserved communities and nonprofit organizations that are traditionally underrepresented in the Program.

14In determining grant guidelines under subsection (g), the Administrator may determine the parameters for outreach and technical assistance.

15The Administrator shall make funds provided under this section available for use by a recipient of a grant for a period of not less than 36 months.

16The Administrator shall annually for each of fiscal years 2022 through 2028 submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report containing information on the following:

17(1) The expenditure by each grant recipient of grant funds made under this section.

18(2) The number of applications submitted by eligible nonprofit organizations to each State.

19(3) The number of applications submitted by each State to the Administrator.

20(4) The operations of the program office of the Program, including staffing resources and efforts with respect to subparagraphs (A) through (D) of subsection (c)(1).

21Not later than 120 days after December 23, 2022, the Administrator shall ensure that within the Federal Emergency Management Agency a program office for the Program (in this subsection referred to as the "program office") shall—

22(1) be headed by a senior official of the Agency; and

23(2) administer the Program (including, where appropriate, in coordination with States), including relating to—

24(A) outreach, engagement, education, and technical assistance and support to eligible nonprofit organizations described in subsection (b), with particular attention to those organizations in underserved communities, before, during, and after the awarding of grants, including web-based training videos for eligible nonprofit organizations that provide guidance on preparing an application and the environmental planning and historic preservation process;

25(B) the establishment of mechanisms to ensure program office processes are conducted in accordance with constitutional, statutory, and regulatory requirements that protect civil rights and civil liberties and advance equal access for members of underserved communities;

26(C) the establishment of mechanisms for the Administrator to provide feedback to eligible nonprofit organizations that do not receive grants;

27(D) the establishment of mechanisms to identify and collect data to measure the effectiveness of grants under the Program;

28(E) the establishment and enforcement of standardized baseline operational requirements for States, including requirements for States to eliminate or prevent any administrative or operational obstacles that may impact eligible nonprofit organizations described in subsection (b) from receiving grants under the Program;

29(F) carrying out efforts to prevent waste, fraud, and abuse, including through audits of grantees; and

30(G) promoting diversity in the types and locations of eligible nonprofit organizations that are applying for grants under the Program.

31For each fiscal year, before awarding grants under this section, the Administrator—

32(1) shall publish guidelines, including a notice of funding opportunity or similar announcement, as the Administrator determines appropriate; and

33(2) may prohibit States from closing application processes before the publication of those guidelines.

34Chapter 35 of title 44 (commonly known as the "Paperwork Reduction Act") shall not apply to any changes to the application materials, Program forms, or other core Program documentation intended to enhance participation by eligible nonprofit organizations in the Program.

35There is authorized to be appropriated $360,000,000 for each of fiscal years 2023 through 2028 for grants under this section, of which—

36(A) $180,000,000 each such fiscal year shall be for recipients in high-risk urban areas that receive funding under section 2003; and

37(B) $180,000,000 each such fiscal year shall be for recipients in jurisdictions that do not so receive such funding.

38There is authorized to be appropriated $18,000,000 for each of fiscal years 2023 through 2028 for Operations and Support at the Federal Emergency Management Agency for costs incurred for the management and administration (including evaluation) of this section.

611.

Administration and coordination

1The Administrator shall ensure that—

2(1) all recipients of grants administered by the Department to prevent, prepare for, protect against, or respond to natural disasters, acts of terrorism, or other man-made disasters (excluding assistance provided under section 203, title IV, or title V of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5133, 5170 et seq., and 5191 et seq.)) coordinate, as appropriate, their prevention, preparedness, and protection efforts with neighboring State, local, and tribal governments; and

3(2) all high-risk urban areas and other recipients of grants administered by the Department to prevent, prepare for, protect against, or respond to natural disasters, acts of terrorism, or other man-made disasters (excluding assistance provided under section 203, title IV, or title V of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5133, 5170 et seq., and 5191 et seq.)) that include or substantially affect parts or all of more than 1 State coordinate, as appropriate, across State boundaries, including, where appropriate, through the use of regional working groups and requirements for regional plans.

4Any State or high-risk urban area receiving a grant under section 604 or 605 of this title shall establish a State planning committee or urban area working group to assist in preparation and revision of the State, regional, or local homeland security plan or the threat and hazard identification and risk assessment, as the case may be, and to assist in determining effective funding priorities for grants under such sections.

5The State planning committees and urban area working groups referred to in paragraph (1) shall include at least one representative from each of the following significant stakeholders:

6(i) Local or tribal government officials.

7(ii) Emergency response providers, which shall include representatives of the fire service, law enforcement, emergency medical services, and emergency managers.

8(iii) Public health officials and other appropriate medical practitioners.

9(iv) Individuals representing educational institutions, including elementary schools, community colleges, and other institutions of higher education.

10(v) State and regional interoperable communications coordinators, as appropriate.

11(vi) State and major urban area fusion centers, as appropriate.

12The members of the State planning committee or urban area working group, as the case may be, shall be a representative group of individuals from the counties, cities, towns, and Indian tribes within the State or high-risk urban area, including, as appropriate, representatives of rural, high-population, and high-threat jurisdictions.

13Nothing in this subsection may be construed to require that any State or high-risk urban area create a State planning committee or urban area working group, as the case may be, if that State or high-risk urban area has established and uses a multijurisdictional planning committee or commission that meets the requirements of this subsection.

14It is the sense of Congress that, in order to ensure that the Nation is most effectively able to prevent, prepare for, protect against, and respond to all hazards, including natural disasters, acts of terrorism, and other man-made disasters—

15(1) the Department should administer a coherent and coordinated system of both terrorism-focused and all-hazards grants;

16(2) there should be a continuing and appropriate balance between funding for terrorism-focused and all-hazards preparedness, as reflected in the authorizations of appropriations for grants under the amendments made by titles I and II, as applicable, of the Implementing Recommendations of the 9/11 Commission Act of 2007; and

17(3) with respect to terrorism-focused grants, it is necessary to ensure both that the target capabilities of the highest risk areas are achieved quickly and that basic levels of preparedness, as measured by the attainment of target capabilities, are achieved nationwide.

612.

Accountability

1Each recipient of a grant administered by the Department that expends not less than $500,000 in Federal funds during its fiscal year shall submit to the Administrator a copy of the organization-wide financial and compliance audit report required under chapter 75 of title 31.

2The Department and each recipient of a grant administered by the Department shall provide the Comptroller General and any officer or employee of the Government Accountability Office with full access to information regarding the activities carried out related to any grant administered by the Department.

3Consistent with subchapter IV of chapter 33 of title 31, for each of the grant programs under sections 604 and 605 of this title and section 762 of this title, the Administrator shall specify policies and procedures for—

4(i) identifying activities funded under any such grant program that are susceptible to significant improper payments; and

5(ii) reporting any improper payments to the Department.

6Not less than once every 2 years, the Administrator shall conduct, for each State and high-risk urban area receiving a grant administered by the Department, a programmatic and financial review of all grants awarded by the Department to prevent, prepare for, protect against, or respond to natural disasters, acts of terrorism, or other man-made disasters, excluding assistance provided under section 203, title IV, or title V of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5133, 5170 et seq., and 5191 et seq.).

7Each review under subparagraph (A) shall, at a minimum, examine—

8(i) whether the funds awarded were used in accordance with the law, program guidance, and State homeland security plans or other applicable plans; and

9(ii) the extent to which funds awarded enhanced the ability of a grantee to prevent, prepare for, protect against, and respond to natural disasters, acts of terrorism, and other man-made disasters.

10In addition to any other amounts authorized to be appropriated to the Administrator, there are authorized to be appropriated to the Administrator for reviews under this paragraph—

11(i) $8,000,000 for each of fiscal years 2008, 2009, and 2010; and

12(ii) such sums as are necessary for fiscal year 2011, and each fiscal year thereafter.

13In order to ensure that States and high-risk urban areas are using grants administered by the Department appropriately to meet target capabilities and preparedness priorities, the Administrator shall—

14(A) ensure that any such State or high-risk urban area conducts or participates in exercises under section 748(b) of this title;

15(B) use performance metrics in accordance with the comprehensive assessment system under section 749 of this title and ensure that any such State or high-risk urban area regularly tests its progress against such metrics through the exercises required under subparagraph (A);

16(C) use the remedial action management program under section 750 of this title; and

17(D) ensure that each State receiving a grant administered by the Department submits a report to the Administrator on its level of preparedness, as required by section 752(c) of this title.

18In conducting program reviews and performance audits under paragraph (2), the Administrator and the Inspector General of the Department shall take into account the performance assessment elements required under paragraph (3).

19The Administrator shall conduct a recovery audit under section 3352(i) of title 31 for any grant administered by the Department with a total value of not less than $1,000,000, if the Administrator finds that—

20(A) a financial audit has identified improper payments that can be recouped; and

21(B) it is cost effective to conduct a recovery audit to recapture the targeted funds.

22If, as a result of a review or audit under this subsection or otherwise, the Administrator finds that a recipient of a grant under this subchapter has failed to substantially comply with any provision of law or with any regulations or guidelines of the Department regarding eligible expenditures, the Administrator shall—

23(i) reduce the amount of payment of grant funds to the recipient by an amount equal to the amount of grants funds that were not properly expended by the recipient;

24(ii) limit the use of grant funds to programs, projects, or activities not affected by the failure to comply;

25(iii) refer the matter to the Inspector General of the Department for further investigation;

26(iv) terminate any payment of grant funds to be made to the recipient; or

27(v) take such other action as the Administrator determines appropriate.

28The Administrator shall apply an appropriate penalty under subparagraph (A) until such time as the Administrator determines that the grant recipient is in full compliance with the law and with applicable guidelines or regulations of the Department.

29As a condition of receiving a grant under section 604 or 605 of this title, a State, high-risk urban area, or directly eligible tribe shall, not later than 30 days after the end of each Federal fiscal quarter, submit to the Administrator a report on activities performed using grant funds during that fiscal quarter.

30Each report submitted under subparagraph (A) shall at a minimum include, for the applicable State, high-risk urban area, or directly eligible tribe, and each subgrantee thereof—

31(i) the amount obligated to that recipient under section 604 or 605 of this title in that quarter;

32(ii) the amount of funds received and expended under section 604 or 605 of this title by that recipient in that quarter; and

33(iii) a summary description of expenditures made by that recipient using such funds, and the purposes for which such expenditures were made.

34The report submitted under subparagraph (A) by a State, high-risk urban area, or directly eligible tribe relating to the last quarter of any fiscal year shall include—

35(i) the amount and date of receipt of all funds received under the grant during that fiscal year;

36(ii) the identity of, and amount provided to, any subgrantee for that grant during that fiscal year;

37(iii) the amount and the dates of disbursements of all such funds expended in compliance with section 611(a)(1) of this title or under mutual aid agreements or other sharing arrangements that apply within the State, high-risk urban area, or directly eligible tribe, as applicable, during that fiscal year; and

38(iv) how the funds were used by each recipient or subgrantee during that fiscal year.

39Any State applying for a grant under section 605 of this title shall submit to the Administrator annually a State preparedness report, as required by section 752(c) of this title.

40The Administrator shall submit to the appropriate committees of Congress annually the Federal Preparedness Report required under section 752(a) of this title.

41For each fiscal year, the Administrator shall provide to the appropriate committees of Congress a detailed and comprehensive explanation of the methodologies used to calculate risk and compute the allocation of funds for grants administered by the Department, including—

42(i) all variables included in the risk assessment and the weights assigned to each such variable;

43(ii) an explanation of how each such variable, as weighted, correlates to risk, and the basis for concluding there is such a correlation; and

44(iii) any change in the methodologies from the previous fiscal year, including changes in variables considered, weighting of those variables, and computational methods.

45The information required under subparagraph (A) shall be provided in unclassified form to the greatest extent possible, and may include a classified annex if necessary.

46For each fiscal year, the information required under subparagraph (A) shall be provided on the earlier of—

47(i) October 31; or

48(ii) 30 days before the issuance of any program guidance for grants administered by the Department.

49At the end of each fiscal year, the Administrator shall submit to the appropriate committees of Congress a report setting forth the amount of funding provided during that fiscal year to Indian tribes under any grant program administered by the Department, whether provided directly or through a subgrant from a State or high-risk urban area.

613.

Identification of reporting redundancies and development of performance metrics

1In this section, the term "covered grants" means grants awarded under section 604 of this title, grants awarded under section 605 of this title, and any other grants specified by the Administrator.

2Not later than 90 days after October 12, 2010, the Administrator shall submit to the appropriate committees of Congress a report that includes—

3(1) an assessment of redundant reporting requirements imposed by the Administrator on State, local, and tribal governments in connection with the awarding of grants, including—

4(A) a list of each discrete item of data requested by the Administrator from grant recipients as part of the process of administering covered grants;

5(B) identification of the items of data from the list described in subparagraph (A) that are required to be submitted by grant recipients on multiple occasions or to multiple systems; and

6(C) identification of the items of data from the list described in subparagraph (A) that are not necessary to be collected in order for the Administrator to effectively and efficiently administer the programs under which covered grants are awarded;

7(2) a plan, including a specific timetable, for eliminating any redundant and unnecessary reporting requirements identified under paragraph (1); and

8(3) a plan, including a specific timetable, for promptly developing a set of quantifiable performance measures and metrics to assess the effectiveness of the programs under which covered grants are awarded.

9Not later than 1 year after the date on which the initial report is required to be submitted under subsection (b), and once every 2 years thereafter, the Administrator shall submit to the appropriate committees of Congress a grants management report that includes—

10(1) the status of efforts to eliminate redundant and unnecessary reporting requirements imposed on grant recipients, including—

11(A) progress made in implementing the plan required under subsection (b)(2);

12(B) a reassessment of the reporting requirements to identify and eliminate redundant and unnecessary requirements;

13(2) the status of efforts to develop quantifiable performance measures and metrics to assess the effectiveness of the programs under which the covered grants are awarded, including—

14(A) progress made in implementing the plan required under subsection (b)(3);

15(B) progress made in developing and implementing additional performance metrics and measures for grants, including as part of the comprehensive assessment system required under section 749 of this title; and

16(3) a performance assessment of each program under which the covered grants are awarded, including—

17(A) a description of the objectives and goals of the program;

18(B) an assessment of the extent to which the objectives and goals described in subparagraph (A) have been met, based on the quantifiable performance measures and metrics required under this section, section 612(a)(4) 1 of this title, and section 749 of this title;

19(C) recommendations for any program modifications to improve the effectiveness of the program, to address changed or emerging conditions; and

20(D) an assessment of the experience of recipients of covered grants, including the availability of clear and accurate information, the timeliness of reviews and awards, and the provision of technical assistance, and recommendations for improving that experience.

21Not later than 30 days after October 12, 2010, the Administrator shall enter into a contract with the National Academy of Public Administration under which the National Academy of Public Administration shall assist the Administrator in studying, developing, and implementing—

22(A) quantifiable performance measures and metrics to assess the effectiveness of grants administered by the Department, as required under this section and section 749 of this title; and

23(B) the plan required under subsection (b)(3).

24Not later than 1 year after the date on which the contract described in paragraph (1) is awarded, the Administrator shall submit to the appropriate committees of Congress a report that describes the findings and recommendations of the study conducted under paragraph (1).

25There are authorized to be appropriated to the Administrator such sums as may be necessary to carry out this subsection.

621

to 629. Omitted

641.

Definitions

1In this subchapter:

2The term "Department" means the Department of Homeland Security.

3The term "human trafficking" means an act or practice described in paragraph (9) or (10) 1 of section 7102 of title 22.

4The term "Secretary" means the Secretary of Homeland Security.

642.

Training for Department personnel to identify human trafficking

1Not later than 180 days after May 29, 2015, the Secretary shall implement a program to—

2(1) train and periodically retrain relevant Transportation Security Administration, U.S. Customs and Border Protection, and other Department personnel that the Secretary considers appropriate, with respect to how to effectively deter, detect, and disrupt human trafficking, and, where appropriate, interdict a suspected perpetrator of human trafficking, during the course of their primary roles and responsibilities; and

3(2) ensure that the personnel referred to in paragraph (1) regularly receive current information on matters related to the detection of human trafficking, including information that becomes available outside of the Department's initial or periodic retraining schedule, to the extent relevant to their official duties and consistent with applicable information and privacy laws.

4The training referred to in subsection (a) may be conducted through in-class or virtual learning capabilities, and shall include—

5(1) methods for identifying suspected victims of human trafficking and, where appropriate, perpetrators of human trafficking;

6(2) for appropriate personnel, methods to approach a suspected victim of human trafficking, where appropriate, in a manner that is sensitive to the suspected victim and is not likely to alert a suspected perpetrator of human trafficking;

7(3) training that is most appropriate for a particular location or environment in which the personnel receiving such training perform their official duties;

8(4) other topics determined by the Secretary to be appropriate; and

9(5) a post-training evaluation for personnel receiving the training.

10The Secretary shall annually reassess the training program established under subsection (a) to ensure it is consistent with current techniques, patterns, and trends associated with human trafficking.

643.

Certification and report to Congress

1Not later than 1 year after May 29, 2015, the Secretary shall certify to Congress that all personnel referred to in section 402(a) 1 have successfully completed the training required under that section.

2Not later than 1 year after May 29, 2015, and annually thereafter, the Secretary shall report to Congress with respect to the overall effectiveness of the program required by this subchapter, the number of cases reported by Department personnel in which human trafficking was suspected, and, of those cases, the number of cases that were confirmed cases of human trafficking.

644.

Assistance to non-Federal entities

1The Secretary may provide training curricula to any State, local, or tribal government or private organization to assist the government or organization in establishing a program of training to identify human trafficking, upon request from the government or organization.

645.

Victim protection training for the Department of Homeland Security

1Not later than 180 days after December 21, 2018, the Secretary shall issue a directive to—

2(A) all Federal law enforcement officers and relevant personnel employed by the Department who may be involved in the investigation of human trafficking offenses; and

3(B) members of all task forces led by the Department that participate in the investigation of human trafficking offenses.

4The directive required to be issued under paragraph (1) shall include instructions on—

5(A) the investigation of individuals who patronize or solicit human trafficking victims as being engaged in severe trafficking in persons and how such individuals should be investigated for their roles in severe trafficking in persons; and

6(B) how victims of sex or labor trafficking often engage in criminal acts as a direct result of severe trafficking in persons and such individuals are victims of a crime and affirmative measures should be taken to avoid arresting, charging, or prosecuting such individuals for any offense that is the direct result of their victimization.

7Not later than 180 days after December 21, 2018, the Secretary shall issue a screening protocol for use during all anti-trafficking law enforcement operations in which the Department is involved.

8The protocol required to be issued under paragraph (1) shall—

9(A) require the individual screening of all adults and children who are suspected of engaging in commercial sex acts, child labor that is a violation of law, or work in violation of labor standards to determine whether each individual screened is a victim of human trafficking;

10(B) require affirmative measures to avoid arresting, charging, or prosecuting human trafficking victims for any offense that is the direct result of their victimization;

11(C) be developed in consultation with relevant interagency partners and nongovernmental organizations that specialize in the prevention of human trafficking or in the identification and support of victims of human trafficking and survivors of human trafficking; and

12(D) include—

13(i) procedures and practices to ensure that the screening process minimizes trauma or revictimization of the person being screened; and

14(ii) guidelines on assisting victims of human trafficking in identifying and receiving restorative services.

15The training described in sections 642 and 644 of this title shall include training necessary to implement—

16(1) the directive required under subsection (a); and

17(2) the protocol required under subsection (b).

645a.

Human trafficking assessment

1Not later than 1 year after December 21, 2018, and annually thereafter, the Executive Associate Director of Homeland Security Investigations shall submit to the Committee on Homeland Security and Governmental Affairs and the Committee on the Judiciary of the Senate, and the Committee on Homeland Security and the Committee on the Judiciary of the House of Representatives a report on human trafficking investigations undertaken by Homeland Security Investigations that includes—

2(1) the number of confirmed human trafficking investigations by category, including labor trafficking, sex trafficking, and transnational and domestic human trafficking;

3(2) the number of victims by category, including—

4(A) whether the victim is a victim of sex trafficking or a victim of labor trafficking; and

5(B) whether the victim is a minor or an adult; and

6(3) an analysis of the data described in paragraphs (1) and (2) and other data available to Homeland Security Investigations that indicates any general human trafficking or investigatory trends.

650.

Definitions

1Except as otherwise specifically provided, in this subchapter:

2The term "Agency" means the Cybersecurity and Infrastructure Security Agency.

3The term "appropriate congressional committees" means—

4(A) the Committee on Homeland Security and Governmental Affairs of the Senate; and

5(B) the Committee on Homeland Security of the House of Representatives.

6The term "cloud service provider" means an entity offering products or services related to cloud computing, as defined by the National Institute of Standards and Technology in NIST Special Publication 800–145 and any amendatory or superseding document relating thereto.

7The term "critical infrastructure information" means information not customarily in the public domain and related to the security of critical infrastructure or protected systems—

8(A) actual, potential, or threatened interference with, attack on, compromise of, or incapacitation of critical infrastructure or protected systems by either physical or computer-based attack or other similar conduct (including the misuse of or unauthorized access to all types of communications and data transmission systems) that violates Federal, State, or local law, harms interstate commerce of the United States, or threatens public health or safety;

9(B) the ability of any critical infrastructure or protected system to resist such interference, compromise, or incapacitation, including any planned or past assessment, projection, or estimate of the vulnerability of critical infrastructure or a protected system, including security testing, risk evaluation thereto, risk management planning, or risk audit; or

10(C) any planned or past operational problem or solution regarding critical infrastructure or protected systems, including repair, recovery, reconstruction, insurance, or continuity, to the extent it is related to such interference, compromise, or incapacitation.

11The term "cyber threat indicator" means information that is necessary to describe or identify—

12(A) malicious reconnaissance, including anomalous patterns of communications that appear to be transmitted for the purpose of gathering technical information related to a cybersecurity threat or security vulnerability;

13(B) a method of defeating a security control or exploitation of a security vulnerability;

14(C) a security vulnerability, including anomalous activity that appears to indicate the existence of a security vulnerability;

15(D) a method of causing a user with legitimate access to an information system or information that is stored on, processed by, or transiting an information system to unwittingly enable the defeat of a security control or exploitation of a security vulnerability;

16(E) malicious cyber command and control;

17(F) the actual or potential harm caused by an incident, including a description of the information exfiltrated as a result of a particular cybersecurity threat;

18(G) any other attribute of a cybersecurity threat, if disclosure of such attribute is not otherwise prohibited by law; or

19(H) any combination thereof.

20The term "cybersecurity purpose" means the purpose of protecting an information system or information that is stored on, processed by, or transiting an information system from a cybersecurity threat or security vulnerability.

21The term "cybersecurity risk"—

22(A) means threats to and vulnerabilities of information or information systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information or information systems, including such related consequences caused by an act of terrorism; and

23(B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.

24Except as provided in subparagraph (B), the term "cybersecurity threat" means an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system.

25The term "cybersecurity threat" does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.

26Except as provided in subparagraph (B), the term "defensive measure" means an action, device, procedure, signature, technique, or other measure applied to an information system or information that is stored on, processed by, or transiting an information system that detects, prevents, or mitigates a known or suspected cybersecurity threat or security vulnerability.

27The term "defensive measure" does not include a measure that destroys, renders unusable, provides unauthorized access to, or substantially harms an information system or information stored on, processed by, or transiting such information system not owned by—

28(i) the private entity, as defined in section 1501 of this title, operating the measure; or

29(ii) another entity or Federal entity that is authorized to provide consent and has provided consent to that private entity for operation of such measure.

30The term "Director" means the Director of the Cybersecurity and Infrastructure Security Agency.

31The term "Homeland Security Enterprise" means relevant governmental and nongovernmental entities involved in homeland security, including Federal, State, local, and Tribal government officials, private sector representatives, academics, and other policy experts.

32The term "incident" means an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or actually or imminently jeopardizes, without lawful authority, an information system.

33The term "Information Sharing and Analysis Organization" means any formal or informal entity or collaboration created or employed by public or private sector organizations, for purposes of—

34(A) gathering and analyzing critical infrastructure information, including information related to cybersecurity risks and incidents, in order to better understand security problems and interdependencies related to critical infrastructure, including cybersecurity risks and incidents, and protected systems, so as to ensure the availability, integrity, and reliability thereof;

35(B) communicating or disclosing critical infrastructure information, including cybersecurity risks and incidents, to help prevent, detect, mitigate, or recover from the effects of an interference, a compromise, or an incapacitation problem related to critical infrastructure, including cybersecurity risks and incidents, or protected systems; and

36(C) voluntarily disseminating critical infrastructure information, including cybersecurity risks and incidents, to its members, State, local, and Federal Governments, or any other entities that may be of assistance in carrying out the purposes specified in subparagraphs (A) and (B).

37The term "information system"—

38(A) has the meaning given the term in section 3502 of title 44; and

39(B) includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers.

40The term "intelligence community" has the meaning given the term in section 3003(4) of title 50.

41The term "malicious cyber command and control" means a method for unauthorized remote identification of, access to, or use of, an information system or information that is stored on, processed by, or transiting an information system.

42The term "malicious reconnaissance" 1 a method for actively probing or passively monitoring an information system for the purpose of discerning security vulnerabilities of the information system, if such method is associated with a known or suspected cybersecurity threat.

43The term "managed service provider" means an entity that delivers services, such as network, application, infrastructure, or security services, via ongoing and regular support and active administration on the premises of a customer, in the data center of the entity (such as hosting), or in a third party data center.

44The term "monitor" means to acquire, identify, or scan, or to possess, information that is stored on, processed by, or transiting an information system.

45The term "national cybersecurity asset response activities" means—

46(A) furnishing cybersecurity technical assistance to entities affected by cybersecurity risks to protect assets, mitigate vulnerabilities, and reduce impacts of cyber incidents;

47(B) identifying other entities that may be at risk of an incident and assessing risk to the same or similar vulnerabilities;

48(C) assessing potential cybersecurity risks to a sector or region, including potential cascading effects, and developing courses of action to mitigate such risks;

49(D) facilitating information sharing and operational coordination with threat response; and

50(E) providing guidance on how best to utilize Federal resources and capabilities in a timely, effective manner to speed recovery from cybersecurity risks.

51The term "national security system" has the meaning given the term in section 11103 of title 40.

52The term "ransomware attack"—

53(A) means an incident that includes the use or threat of use of unauthorized or malicious code on an information system, or the use or threat of use of another digital mechanism such as a denial of service attack, to interrupt or disrupt the operations of an information system or compromise the confidentiality, availability, or integrity of electronic data stored on, processed by, or transiting an information system to extort a demand for a ransom payment; and

54(B) does not include any such event in which the demand for payment is—

55(i) not genuine; or

56(ii) made in good faith by an entity in response to a specific request by the owner or operator of the information system.

57The term "Sector Risk Management Agency" means a Federal department or agency, designated by law or Presidential directive, with responsibility for providing institutional knowledge and specialized expertise of a sector, as well as leading, facilitating, or supporting programs and associated activities of its designated critical infrastructure sector in the all hazards environment in coordination with the Department.

58The term "security control" means the management, operational, and technical controls used to protect against an unauthorized effort to adversely affect the confidentiality, integrity, and availability of an information system or its information.

59The term "security vulnerability" means any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control.

60The term "sharing" (including all conjugations thereof) means providing, receiving, and disseminating (including all conjugations of each such terms).

61The term "SLTT entity" means a domestic government entity that is a State government, local government, Tribal government, territorial government, or any subdivision thereof.

62The term "supply chain compromise" means an incident within the supply chain of an information system that an adversary can leverage, or does leverage, to jeopardize the confidentiality, integrity, or availability of the information system or the information the system processes, stores, or transmits, and can occur at any point during the life cycle.

651.

Definition

1In this part, the term "Cybersecurity Advisory Committee" means the advisory committee established under section 665e(a) of this title.

652.

Cybersecurity and Infrastructure Security Agency

1The National Protection and Programs Directorate of the Department shall, on and after November 16, 2018, be known as the "Cybersecurity and Infrastructure Security Agency".

2Any reference to the National Protection and Programs Directorate of the Department in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Cybersecurity and Infrastructure Security Agency of the Department.

3The Agency shall be headed by the Director, who shall report to the Secretary.

4The Director shall be appointed from among individuals who have—

5(i) extensive knowledge in at least two of the areas specified in subparagraph (B); and

6(ii) not fewer than five years of demonstrated experience in efforts to foster coordination and collaboration between the Federal Government, the private sector, and other entities on issues related to cybersecurity, infrastructure security, or security risk management.

7The areas specified in this subparagraph are the following:

8(i) Cybersecurity.

9(ii) Infrastructure security.

10(iii) Security risk management.

11Any reference to an Under Secretary responsible for overseeing critical infrastructure protection, cybersecurity, and any other related program of the Department as described in section 113(a)(1)(H) of this title as in effect on the day before November 16, 2018, in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Director of the Cybersecurity and Infrastructure Security Agency.

12The Director shall—

13(1) lead cybersecurity and critical infrastructure security programs, operations, and associated policy for the Agency, including national cybersecurity asset response activities;

14(2) coordinate with Federal entities, including Sector-Specific Agencies, and non-Federal entities, including international entities, to carry out the cybersecurity and critical infrastructure activities of the Agency, as appropriate;

15(3) carry out the responsibilities of the Secretary to secure Federal information and information systems consistent with law, including subchapter II of chapter 35 of title 44 and the Cybersecurity Act of 2015 (contained in division N of the Consolidated Appropriations Act, 2016 (Public Law 114–113)), including by carrying out a periodic strategic assessment of the related programs and activities of the Agency to ensure such programs and activities contemplate the innovation of information systems and changes in cybersecurity risks and cybersecurity threats;

16(4) coordinate a national effort to secure and protect against critical infrastructure risks, consistent with subsection (e)(1)(E);

17(5) upon request, provide analyses, expertise, and other technical assistance to critical infrastructure owners and operators and, where appropriate, provide those analyses, expertise, and other technical assistance in coordination with Sector-Specific Agencies and other Federal departments and agencies;

18(6) develop and utilize mechanisms for active and frequent collaboration between the Agency and Sector-Specific Agencies to ensure appropriate coordination, situational awareness, and communications with Sector-Specific Agencies;

19(7) maintain and utilize mechanisms for the regular and ongoing consultation and collaboration among the Divisions of the Agency to further operational coordination, integrated situational awareness, and improved integration across the Agency in accordance with this chapter;

20(8) develop, coordinate, and implement—

21(A) comprehensive strategic plans for the activities of the Agency; and

22(B) risk assessments by and for the Agency;

23(9) carry out emergency communications responsibilities, in accordance with subchapter XIII;

24(10) carry out cybersecurity, infrastructure security, and emergency communications stakeholder outreach and engagement and coordinate that outreach and engagement with critical infrastructure Sector-Specific Agencies, as appropriate;

25(11) provide education, training, and capacity development to Federal and non-Federal entities to enhance the security and resiliency of domestic and global cybersecurity and infrastructure security;

26(12) appoint a Cybersecurity State Coordinator in each State, as described in section 665c of this title;

27(13) carry out the duties and authorities relating to the .gov internet domain, as described in section 665 of this title; and

28(14) carry out such other duties and powers prescribed by law or delegated by the Secretary.

29There shall be in the Agency a Deputy Director of the Cybersecurity and Infrastructure Security Agency who shall—

30(1) assist the Director in the management of the Agency; and

31(2) report to the Director.

32The responsibilities of the Secretary relating to cybersecurity and infrastructure security shall include the following:

33(A) To access, receive, and analyze law enforcement information, intelligence information, and other information from Federal Government agencies, State, local, tribal, and territorial government agencies, including law enforcement agencies, and private sector entities, and to integrate that information, in support of the mission responsibilities of the Department, in order to—

34(i) identify and assess the nature and scope of terrorist threats to the homeland;

35(ii) detect and identify threats of terrorism against the United States; and

36(iii) understand those threats in light of actual and potential vulnerabilities of the homeland.

37(B) To carry out comprehensive assessments of the vulnerabilities of the key resources and critical infrastructure of the United States, including the performance of risk assessments to determine the risks posed by particular types of terrorist attacks within the United States, including an assessment of the probability of success of those attacks and the feasibility and potential efficacy of various countermeasures to those attacks. At the discretion of the Secretary, such assessments may be carried out in coordination with Sector-Specific Agencies.

38(C) To integrate relevant information, analysis, and vulnerability assessments, regardless of whether the information, analysis, or assessments are provided or produced by the Department, in order to make recommendations, including prioritization, for protective and support measures by the Department, other Federal Government agencies, State, local, tribal, and territorial government agencies and authorities, the private sector, and other entities regarding terrorist and other threats to homeland security.

39(D) To ensure, pursuant to section 122 of this title, the timely and efficient access by the Department to all information necessary to discharge the responsibilities under this subchapter, including obtaining that information from other Federal Government agencies.

40(E) To develop, in coordination with the Sector-Specific Agencies with available expertise, a comprehensive national plan for securing the key resources and critical infrastructure of the United States, including power production, generation, and distribution systems, information technology and telecommunications systems (including satellites), electronic financial and property record storage and transmission systems, emergency communications systems, and the physical and technological assets that support those systems.

41(F) To recommend measures necessary to protect the key resources and critical infrastructure of the United States in coordination with other Federal Government agencies, including Sector-Specific Agencies, and in cooperation with State, local, tribal, and territorial government agencies and authorities, the private sector, and other entities.

42(G) To review, analyze, and make recommendations for improvements to the policies and procedures governing the sharing of information relating to homeland security within the Federal Government and between Federal Government agencies and State, local, tribal, and territorial government agencies and authorities.

43(H) To disseminate, as appropriate, information analyzed by the Department within the Department to other Federal Government agencies with responsibilities relating to homeland security and to State, local, tribal, and territorial government agencies and private sector entities with those responsibilities in order to assist in the deterrence, prevention, or preemption of, or response to, terrorist attacks against the United States.

44(I) To consult with State, local, tribal, and territorial government agencies and private sector entities to ensure appropriate exchanges of information, including law enforcement-related information, relating to threats of terrorism against the United States.

45(J) To ensure that any material received pursuant to this chapter is protected from unauthorized disclosure and handled and used only for the performance of official duties.

46(K) To request additional information from other Federal Government agencies, State, local, tribal, and territorial government agencies, and the private sector relating to threats of terrorism in the United States, or relating to other areas of responsibility assigned by the Secretary, including the entry into cooperative agreements through the Secretary to obtain such information.

47(L) To establish and utilize, in conjunction with the Chief Information Officer of the Department, a secure communications and information technology infrastructure, including data-mining and other advanced analytical tools, in order to access, receive, and analyze data and information in furtherance of the responsibilities under this section, and to disseminate information acquired and analyzed by the Department, as appropriate.

48(M) To coordinate training and other support to the elements and personnel of the Department, other Federal Government agencies, and State, local, tribal, and territorial government agencies that provide information to the Department, or are consumers of information provided by the Department, in order to facilitate the identification and sharing of information revealed in their ordinary duties and the optimal utilization of information received from the Department.

49(N) To coordinate with Federal, State, local, tribal, and territorial law enforcement agencies, and the private sector, as appropriate.

50(O) To exercise the authorities and oversight of the functions, personnel, assets, and liabilities of those components transferred to the Department pursuant to section 121(g) of this title.

51(P) To carry out the functions of the national cybersecurity and communications integration center under section 659 of this title.

52(Q) To carry out the requirements of the Chemical Facility Anti-Terrorism Standards Program established under subchapter XVI and the secure handling of ammonium nitrate program established under part J of subchapter VIII, or any successor programs.

53(R) To encourage and build cybersecurity awareness and competency across the United States and to develop, attract, and retain the cybersecurity workforce necessary for the cybersecurity related missions of the Department, including by—

54(i) overseeing elementary and secondary cybersecurity education and awareness related programs at the Agency;

55(ii) leading efforts to develop, attract, and retain the cybersecurity workforce necessary for the cybersecurity related missions of the Department;

56(iii) encouraging and building cybersecurity awareness and competency across the United States; and

57(iv) carrying out cybersecurity related workforce development activities, including through—

58(I) increasing the pipeline of future cybersecurity professionals through programs focused on elementary and secondary education, postsecondary education, and workforce development; and

59(II) building awareness of and competency in cybersecurity across the civilian Federal Government workforce.

60The Secretary may reallocate within the Agency the functions specified in sections 653(b) and 654(b) of this title, consistent with the responsibilities provided in paragraph (1), upon certifying to and briefing the appropriate congressional committees, and making available to the public, at least 60 days prior to the reallocation that the reallocation is necessary for carrying out the activities of the Agency.

61The Secretary shall provide the Agency with a staff of analysts having appropriate expertise and experience to assist the Agency in discharging the responsibilities of the Agency under this section.

62Analysts under this subsection may include analysts from the private sector.

63Analysts under this subsection shall possess security clearances appropriate for their work under this section.

64In order to assist the Agency in discharging the responsibilities of the Agency under this section, personnel of the Federal agencies described in subparagraph (B) may be detailed to the Agency for the performance of analytic functions and related duties.

65The Federal agencies described in this subparagraph are—

66(i) the Department of State;

67(ii) the Central Intelligence Agency;

68(iii) the Federal Bureau of Investigation;

69(iv) the National Security Agency;

70(v) the National Geospatial-Intelligence Agency;

71(vi) the Defense Intelligence Agency;

72(vii) Sector-Specific Agencies; and

73(viii) any other agency of the Federal Government that the President considers appropriate.

74The Secretary and the head of a Federal agency described in subparagraph (B) may enter into agreements for the purpose of detailing personnel under this paragraph.

75The detail of personnel under this paragraph may be on a reimbursable or non-reimbursable basis.

76The Agency shall be composed of the following divisions:

77(1) The Cybersecurity Division, headed by an Executive Assistant Director.

78(2) The Infrastructure Security Division, headed by an Executive Assistant Director.

79(3) The Emergency Communications Division under subchapter XIII, headed by an Executive Assistant Director.

80To the maximum extent practicable, the Director shall examine the establishment of central locations in geographical regions with a significant Agency presence.

81When establishing the central locations described in paragraph (1), the Director shall coordinate with component heads and the Under Secretary for Management to co-locate or partner on any new real property leases, renewing any occupancy agreements for existing leases, or agreeing to extend or newly occupy any Federal space or new construction.

82There shall be a Privacy Officer of the Agency with primary responsibility for privacy policy and compliance for the Agency.

83The responsibilities of the Privacy Officer of the Agency shall include—

84(A) assuring that the use of technologies by the Agency sustain, and do not erode, privacy protections relating to the use, collection, and disclosure of personal information;

85(B) assuring that personal information contained in systems of records of the Agency is handled in full compliance as specified in section 552a of title 5 (commonly known as the "Privacy Act of 1974");

86(C) evaluating legislative and regulatory proposals involving collection, use, and disclosure of personal information by the Agency; and

87(D) conducting a privacy impact assessment of proposed rules of the Agency on the privacy of personal information, including the type of personal information collected and the number of people affected.

88Nothing in this subchapter may be construed as affecting in any manner the authority, existing on the day before November 16, 2018, of any other component of the Department or any other Federal department or agency, including the authority provided to the Sector Risk Management Agency specified in section 61003(c) of division F of the Fixing America's Surface Transportation Act (6 U.S.C. 121 note; Public Law 114–94).

652a.

Sector Risk Management Agencies

1In this section:

2The term "appropriate congressional committees" means—

3(A) the Committee on Homeland Security and the Committee on Armed Services in the House of Representatives; and

4(B) the Committee on Homeland Security and Governmental Affairs and the Committee on Armed Services in the Senate.

5The term "critical infrastructure" has the meaning given that term in section 5195c(e) of title 42.

6The term "Department" means the Department of Homeland Security.

7The term "Director" means the Director of the Cybersecurity and Infrastructure Security Agency of the Department.

8The term "Secretary" means the Secretary of Homeland Security.

9The term "Sector Risk Management Agency" has the meaning given the term in section 650 of this title.

10Not later than 180 days after January 1, 2021, the Secretary, in consultation with the heads of Sector Risk Management Agencies, shall—

11(A) review the current framework for securing critical infrastructure, as described in section 652(c)(4) of this title and Presidential Policy Directive 21; and

12(B) submit to the President and appropriate congressional committees a report that includes—

13(i) information relating to—

14(I) the analysis framework or methodology used to—

15(aa) evaluate the current framework for securing critical infrastructure referred to in subparagraph (A); and

16(bb) develop recommendations to—

17(AA) revise the current list of critical infrastructure sectors designated pursuant to Presidential Policy Directive 21, any successor or related document, or policy; or

18(BB) identify and designate any subsectors of such sectors;

19(II) the data, metrics, and other information used to develop the recommendations required under clause (ii); and

20(ii) recommendations relating to—

21(I) revising—

22(aa) the current framework for securing critical infrastructure referred to in subparagraph (A);

23(bb) the current list of critical infrastructure sectors designated pursuant to Presidential Policy Directive 21, any successor or related document, or policy; or

24(cc) the identification and designation of any subsectors of such sectors; and

25(II) any revisions to the list of designated Federal departments or agencies that serve as the Sector Risk Management Agency for a sector or subsector of such section, necessary to comply with paragraph (3)(B).

26At least once every five years, the Secretary, in consultation with the Director and the heads of Sector Risk Management Agencies, shall—

27(A) evaluate the current list of designated critical infrastructure sectors and subsectors of such sectors and the appropriateness of Sector Risk Management Agency designations, as set forth in Presidential Policy Directive 21, any successor or related document, or policy; and

28(B) recommend, as appropriate, to the President—

29(i) revisions to the current list of designated critical infrastructure sectors or subsectors of such sectors; and

30(ii) revisions to the designation of any Federal department or agency designated as the Sector Risk Management Agency for a sector or subsector of such sector.

31Not later than 180 days after the Secretary submits a recommendation pursuant to paragraph (1) or (2), the President shall—

32(A) review the recommendation and revise, as appropriate, the designation of a critical infrastructure sector or subsector or the designation of a Sector Risk Management Agency; and

33(B) submit to the appropriate congressional committees, the Majority and Minority Leaders of the Senate, and the Speaker and Minority Leader of the House of Representatives, a report that includes—

34(i) an explanation with respect to the basis for accepting or rejecting the recommendations of the Secretary; and

35(ii) information relating to the analysis framework, methodology, metrics, and data used to—

36(I) evaluate the current framework for securing critical infrastructure referred to in paragraph (1)(A); and

37(II) develop—

38(aa) recommendations to revise—

39(AA) the list of critical infrastructure sectors designated pursuant to Presidential Policy Directive 21, any successor or related document, or policy; or

40(BB) the designation of any subsectors of such sectors; and

41(bb) the recommendations of the Secretary.

42Any designation of critical infrastructure sectors shall be published in the Federal Register.

43Any reference to a Sector Specific Agency (including any permutations or conjugations thereof) in any law, regulation, map, document, record, or other paper of the United States shall be deemed to—

44(A) be a reference to the Sector Risk Management Agency of the relevant critical infrastructure sector; and

45(B) have the meaning given such term in section 650 of this title.

46Not later than two years after January 1, 2021 and every four years thereafter for 12 years, the Comptroller General of the United States shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the effectiveness of Sector Risk Management Agencies in carrying out their responsibilities under section 665d of this title.

653.

Cybersecurity Division

1There is established in the Agency a Cybersecurity Division.

2The Cybersecurity Division shall be headed by an Executive Assistant Director for Cybersecurity (in this section referred to as "the Executive Assistant Director"), who shall—

3(A) be at the level of Assistant Secretary within the Department;

4(B) be appointed by the President without the advice and consent of the Senate; and

5(C) report to the Director.

6Any reference to the Assistant Secretary for Cybersecurity and Communications or Assistant Director for Cybersecurity in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Executive Assistant Director for Cybersecurity.

7The Executive Assistant Director shall—

8(1) direct the cybersecurity efforts of the Agency;

9(2) carry out activities, at the direction of the Director, related to the security of Federal information and Federal information systems consistent with law, including subchapter II of chapter 35 of title 44 and the Cybersecurity Act of 2015 (contained in division N of the Consolidated Appropriations Act, 2016 (Public Law 114–113));

10(3) fully participate in the mechanisms required under section 652(c)(7) of this title; and

11(4) carry out such other duties and powers as prescribed by the Director.

654.

Infrastructure Security Division

1There is established in the Agency an Infrastructure Security Division.

2The Infrastructure Security Division shall be headed by an Executive Assistant Director for Infrastructure Security (in this section referred to as "the Executive Assistant Director"), who shall—

3(A) be at the level of Assistant Secretary within the Department;

4(B) be appointed by the President without the advice and consent of the Senate; and

5(C) report to the Director.

6Any reference to the Assistant Secretary for Infrastructure Protection or Assistant Director for Infrastructure Security in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Executive Assistant Director for Infrastructure Security.

7The Executive Assistant Director shall—

8(1) direct the critical infrastructure security efforts of the Agency;

9(2) carry out, at the direction of the Director, the Chemical Facilities Anti-Terrorism Standards Program established under subchapter XVI and the secure handling of ammonium nitrate program established under part J of subchapter VIII, or any successor programs;

10(3) fully participate in the mechanisms required under section 652(c)(7) of this title; and

11(4) carry out such other duties and powers as prescribed by the Director.

655.

Enhancement of Federal and non-Federal cybersecurity

1In carrying out the responsibilities under section 652 of this title, the Director of the Cybersecurity and Infrastructure Security Agency shall—

2(1) as appropriate, provide to State and local government entities, and upon request to private entities that own or operate critical information systems—

3(A) analysis and warnings related to threats to, and vulnerabilities of, critical information systems; and

4(B) in coordination with the Under Secretary for Emergency Preparedness and Response, crisis management support in response to threats to, or attacks on, critical information systems;

5(2) as appropriate, provide technical assistance, upon request, to the private sector and other government entities, in coordination with the Under Secretary for Emergency Preparedness and Response, with respect to emergency recovery plans to respond to major failures of critical information systems; and

6(3) fulfill the responsibilities of the Secretary to protect Federal information systems under subchapter II of chapter 35 of title 44.

656.

NET Guard

1The Director of the Cybersecurity and Infrastructure Security Agency may establish a national technology guard, to be known as "NET Guard", comprised of local teams of volunteers with expertise in relevant areas of science and technology, to assist local communities to respond and recover from attacks on information systems and communications networks.

657.

Cyber Security Enhancement Act of 2002

1This section may be cited as the "Cyber Security Enhancement Act of 2002".

2Pursuant to its authority under section 994(p) of title 28 and in accordance with this subsection, the United States Sentencing Commission shall review and, if appropriate, amend its guidelines and its policy statements applicable to persons convicted of an offense under section 1030 of title 18.

3In carrying out this subsection, the Sentencing Commission shall—

4(A) ensure that the sentencing guidelines and policy statements reflect the serious nature of the offenses described in paragraph (1), the growing incidence of such offenses, and the need for an effective deterrent and appropriate punishment to prevent such offenses;

5(B) consider the following factors and the extent to which the guidelines may or may not account for them—

6(i) the potential and actual loss resulting from the offense;

7(ii) the level of sophistication and planning involved in the offense;

8(iii) whether the offense was committed for purposes of commercial advantage or private financial benefit;

9(iv) whether the defendant acted with malicious intent to cause harm in committing the offense;

10(v) the extent to which the offense violated the privacy rights of individuals harmed;

11(vi) whether the offense involved a computer used by the government in furtherance of national defense, national security, or the administration of justice;

12(vii) whether the violation was intended to or had the effect of significantly interfering with or disrupting a critical infrastructure; and

13(viii) whether the violation was intended to or had the effect of creating a threat to public health or safety, or injury to any person;

14(C) assure reasonable consistency with other relevant directives and with other sentencing guidelines;

15(D) account for any additional aggravating or mitigating circumstances that might justify exceptions to the generally applicable sentencing ranges;

16(E) make any necessary conforming changes to the sentencing guidelines; and

17(F) assure that the guidelines adequately meet the purposes of sentencing as set forth in section 3553(a)(2) of title 18.

18Not later than May 1, 2003, the United States Sentencing Commission shall submit a brief report to Congress that explains any actions taken by the Sentencing Commission in response to this section and includes any recommendations the Commission may have regarding statutory penalties for offenses under section 1030 of title 18.

19A government entity that receives a disclosure under section 2702(b) of title 18 shall file, not later than 90 days after such disclosure, a report to the Attorney General stating the paragraph of that section under which the disclosure was made, the date of the disclosure, the entity to which the disclosure was made, the number of customers or subscribers to whom the information disclosed pertained, and the number of communications, if any, that were disclosed. The Attorney General shall publish all such reports into a single report to be submitted to Congress 1 year after November 25, 2002.

658.

Cybersecurity recruitment and retention

1In this section:

2The term "appropriate committees of Congress" means the Committee on Homeland Security and Governmental Affairs and the Committee on Appropriations of the Senate and the Committee on Homeland Security and the Committee on Appropriations of the House of Representatives.

3The term "collective bargaining agreement" has the meaning given that term in section 7103(a)(8) of title 5.

4The term "excepted service" has the meaning given that term in section 2103 of title 5.

5The term "preference eligible" has the meaning given that term in section 2108 of title 5.

6The term "qualified position" means a position, designated by the Secretary for the purpose of this section, in which the incumbent performs, manages, or supervises functions that execute the responsibilities of the Department relating to cybersecurity.

7The term "Senior Executive Service" has the meaning given that term in section 2101a of title 5.

8The Secretary may—

9(i) establish, as positions in the excepted service, such qualified positions in the Department as the Secretary determines necessary to carry out the responsibilities of the Department relating to cybersecurity, including positions formerly identified as—

10(I) senior level positions designated under section 5376 of title 5; and

11(II) positions in the Senior Executive Service;

12(ii) appoint an individual to a qualified position (after taking into consideration the availability of preference eligibles for appointment to the position); and

13(iii) subject to the requirements of paragraphs (2) and (3), fix the compensation of an individual for service in a qualified position.

14The authority of the Secretary under this subsection applies without regard to the provisions of any other law relating to the appointment, number, classification, or compensation of employees.

15In accordance with this section, the Secretary shall fix the rates of basic pay for any qualified position established under paragraph (1) in relation to the rates of pay provided for employees in comparable positions in the Department of Defense and subject to the same limitations on maximum rates of pay established for such employees by law or regulation.

16The Secretary may, consistent with section 5341 of title 5, adopt such provisions of that title as provide for prevailing rate systems of basic pay and may apply those provisions to qualified positions for employees in or under which the Department may employ individuals described by section 5342(a)(2)(A) of that title.

17The Secretary may provide employees in qualified positions compensation (in addition to basic pay), including benefits, incentives, and allowances, consistent with, and not in excess of the level authorized for, comparable positions authorized by title 5.

18An employee in a qualified position whose rate of basic pay is fixed under paragraph (2)(A) shall be eligible for an allowance under section 5941 of title 5, on the same basis and to the same extent as if the employee was an employee covered by such section 5941, including eligibility conditions, allowance rates, and all other terms and conditions in law or regulation.

19Not later than 120 days after December 18, 2014, the Secretary shall submit a report to the appropriate committees of Congress with a plan for the use of the authorities provided under this subsection.

20Nothing in paragraph (1) may be construed to impair the continued effectiveness of a collective bargaining agreement with respect to an office, component, subcomponent, or equivalent of the Department that is a successor to an office, component, subcomponent, or equivalent of the Department covered by the agreement before the succession.

21The Secretary, in coordination with the Director of the Office of Personnel Management, shall prescribe regulations for the administration of this section.

22Not later than 1 year after December 18, 2014, and every year thereafter for 4 years, the Secretary shall submit to the appropriate committees of Congress a detailed report that—

23(1) discusses the process used by the Secretary in accepting applications, assessing candidates, ensuring adherence to veterans' preference, and selecting applicants for vacancies to be filled by an individual for a qualified position;

24(2) describes—

25(A) how the Secretary plans to fulfill the critical need of the Department to recruit and retain employees in qualified positions;

26(B) the measures that will be used to measure progress; and

27(C) any actions taken during the reporting period to fulfill such critical need;

28(3) discusses how the planning and actions taken under paragraph (2) are integrated into the strategic workforce planning of the Department;

29(4) provides metrics on actions occurring during the reporting period, including—

30(A) the number of employees in qualified positions hired by occupation and grade and level or pay band;

31(B) the placement of employees in qualified positions by directorate and office within the Department;

32(C) the total number of veterans hired;

33(D) the number of separations of employees in qualified positions by occupation and grade and level or pay band;

34(E) the number of retirements of employees in qualified positions by occupation and grade and level or pay band; and

35(F) the number and amounts of recruitment, relocation, and retention incentives paid to employees in qualified positions by occupation and grade and level or pay band; and

36(5) describes the training provided to supervisors of employees in qualified positions at the Department on the use of the new authorities.

37The probationary period for all employees hired under the authority established in this section shall be 3 years.

38An individual serving in a position on December 18, 2014, that is selected to be converted to a position in the excepted service under this section shall have the right to refuse such conversion.

39After the date on which an individual who refuses a conversion under paragraph (1) stops serving in the position selected to be converted, the position may be converted to a position in the excepted service.

40Not later than 120 days after December 18, 2014, the National Protection and Programs Directorate shall submit a report regarding the availability of, and benefits (including cost savings and security) of using, cybersecurity personnel and facilities outside of the National Capital Region (as defined in section 2674 of title 10) to serve the Federal and national need to—

41(1) the Subcommittee on Homeland Security of the Committee on Appropriations and the Committee on Homeland Security and Governmental Affairs of the Senate; and

42(2) the Subcommittee on Homeland Security of the Committee on Appropriations and the Committee on Homeland Security of the House of Representatives.

659.

National cybersecurity and communications integration center

1The term "cybersecurity vulnerability" has the meaning given the term "security vulnerability" in section 650 of this title.

2There is in the Department a national cybersecurity and communications integration center (referred to in this section as the "Center") to carry out certain responsibilities of the Director. The Center shall be located in the Cybersecurity and Infrastructure Security Agency. The head of the Center shall report to the Executive Assistant Director for Cybersecurity.

3The cybersecurity functions of the Center shall include—

4(1) being a Federal civilian interface for the multi-directional and cross-sector sharing of information related to cyber threat indicators, defensive measures, cybersecurity risks, incidents, analysis, and warnings for Federal and non-Federal entities, including the implementation of title I of the Cybersecurity Act of 2015 [6 U.S.C. 1501 et seq.];

5(2) providing shared situational awareness to enable real-time, integrated, and operational actions across the Federal Government and non-Federal entities to address cybersecurity risks and incidents to Federal and non-Federal entities;

6(3) coordinating the sharing of information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents across the Federal Government;

7(4) facilitating cross-sector coordination to address cybersecurity risks and incidents, including cybersecurity risks and incidents that may be related or could have consequential impacts across multiple sectors;

8(5)(A) conducting integration and analysis, including cross-sector integration and analysis, of cyber threat indicators, defensive measures, cybersecurity risks, and incidents;

9(B) sharing mitigation protocols to counter cybersecurity vulnerabilities pursuant to subsection (n), as appropriate; and

10(C) sharing the analysis conducted under subparagraph (A) and mitigation protocols to counter cybersecurity vulnerabilities in accordance with subparagraph (B), as appropriate, with Federal and non-Federal entities;

11(6) upon request, providing operational and timely technical assistance, risk management support, and incident response capabilities to Federal and non-Federal entities with respect to cyber threat indicators, defensive measures, cybersecurity risks, and incidents, which may include attribution, mitigation, and remediation, which may take the form of continuous monitoring and detection of cybersecurity risks to critical infrastructure entities that own or operate industrial control systems that support national critical functions;

12(7) providing information and recommendations on security and resilience measures to Federal and non-Federal entities, including information and recommendations to—

13(A) facilitate information security;

14(B) strengthen information systems against cybersecurity risks and incidents; and

15(C) share cyber threat indicators and defensive measures;

16(8) engaging with international partners, in consultation with other appropriate agencies, to—

17(A) collaborate on cyber threat indicators, defensive measures, and information related to cybersecurity risks and incidents; and

18(B) enhance the security and resilience of global cybersecurity;

19(9) sharing cyber threat indicators, defensive measures, mitigation protocols to counter cybersecurity vulnerabilities, as appropriate, and other information related to cybersecurity risks and incidents with Federal and non-Federal entities, including across sectors of critical infrastructure and with State and major urban area fusion centers, as appropriate;

20(10) participating, as appropriate, in national exercises run by the Department;

21(11) in coordination with the Emergency Communications Division of the Department, assessing and evaluating consequence, vulnerability, and threat information regarding cyber incidents to public safety communications to help facilitate continuous improvements to the security and resiliency of such communications;

22(12) detecting, identifying, and receiving information for a cybersecurity purpose about security vulnerabilities relating to critical infrastructure in information systems and devices; and

23(13) receiving, aggregating, and analyzing reports related to covered cyber incidents (as defined in section 681 of this title) submitted by covered entities (as defined in section 681 of this title) and reports related to ransom payments (as defined in section 681 of this title) submitted by covered entities (as defined in section 681 of this title) in furtherance of the activities specified in sections 652(e), 653, and 681a of this title, this subsection, and any other authorized activity of the Director, to enhance the situational awareness of cybersecurity threats across critical infrastructure sectors.

24The Center shall be composed of—

25(A) appropriate representatives of Federal entities, such as—

26(i) sector-specific agencies;

27(ii) civilian and law enforcement agencies; and

28(iii) elements of the intelligence community;

29(B) appropriate representatives of non-Federal entities, such as—

30(i) State, local, and tribal governments;

31(ii) Information Sharing and Analysis Organizations, including information sharing and analysis centers;

32(iii) owners and operators of critical information systems; and

33(iv) private entities, including cybersecurity specialists;

34(C) components within the Center that carry out cybersecurity and communications activities;

35(D) a designated Federal official for operational coordination with and across each sector;

36(E) an entity that collaborates with State and local governments, including an entity that collaborates with election officials, on cybersecurity risks and incidents, and has entered into a voluntary information sharing relationship with the Center; and

37(F) other appropriate representatives or entities, as determined by the Secretary.

38In the event of an incident, during exigent circumstances the Secretary may grant a Federal or non-Federal entity immediate temporary access to the Center.

39In carrying out the functions under subsection (c), the Center shall ensure—

40(1) to the extent practicable, that—

41(A) timely, actionable, and relevant cyber threat indicators, defensive measures, and information related to cybersecurity risks, incidents, and analysis is shared;

42(B) when appropriate, cyber threat indicators, defensive measures, and information related to cybersecurity risks, incidents, and analysis is integrated with other relevant information and tailored to the specific characteristics of a sector;

43(C) activities are prioritized and conducted based on the level of risk;

44(D) industry sector-specific, academic, and national laboratory expertise is sought and receives appropriate consideration;

45(E) continuous, collaborative, and inclusive coordination occurs—

46(i) across sectors; and

47(ii) with—

48(I) sector coordinating councils;

49(II) Information Sharing and Analysis Organizations; and

50(III) other appropriate non-Federal partners;

51(F) as appropriate, the Center works to develop and use mechanisms for sharing information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents that are technology-neutral, interoperable, real-time, cost-effective, and resilient;

52(G) the Center works with other agencies to reduce unnecessarily duplicative sharing of information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents;

53(H) the Center designates an agency contact for non-Federal entities; and

54(I) activities of the Center address the security of both information technology and operational technology, including industrial control systems;

55(2) that information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents is appropriately safeguarded against unauthorized access or disclosure; and

56(3) that activities conducted by the Center comply with all policies, regulations, and laws that protect the privacy and civil liberties of United States persons, including by working with the Privacy Officer appointed under section 142 of this title to ensure that the Center follows the policies and procedures specified in subsections (b) and (d)(5)(C) of section 105 of the Cybersecurity Act of 2015 [6 U.S.C. 1504].

57The Center shall maintain cyber hunt and incident response teams for the purpose of leading Federal asset response activities and providing timely technical assistance to Federal and non-Federal entities, including across all critical infrastructure sectors, regarding actual or potential security incidents, as appropriate and upon request, including—

58(A) assistance to asset owners and operators in restoring services following a cyber incident;

59(B) identification and analysis of cybersecurity risk and unauthorized cyber activity;

60(C) mitigation strategies to prevent, deter, and protect against cybersecurity risks;

61(D) recommendations to asset owners and operators for improving overall network and control systems security to lower cybersecurity risks, and other recommendations, as appropriate; and

62(E) such other capabilities as the Secretary determines appropriate.

63The Center shall—

64(A) define the goals and desired outcomes for each cyber hunt and incident response team; and

65(B) develop metrics—

66(i) to measure the effectiveness and efficiency of each cyber hunt and incident response team in achieving the goals and desired outcomes defined under subparagraph (A); and

67(ii) that—

68(I) are quantifiable and actionable; and

69(II) the Center shall use to improve the effectiveness and accountability of, and service delivery by, cyber hunt and incident response teams.

70After notice to, and with the approval of, the entity requesting action by or technical assistance from the Center, the Secretary may include cybersecurity specialists from the private sector on a cyber hunt and incident response team.

71The provision of assistance or information to, and inclusion in the Center, or any team or activity of the Center, of, governmental or private entities under this section shall be at the sole and unreviewable discretion of the Director.

72The provision of certain assistance or information to, or inclusion in the Center, or any team or activity of the Center, of, one governmental or private entity pursuant to this section shall not create a right or benefit, substantive or procedural, to similar assistance or information for any other governmental or private entity.

73The Director, in coordination with industry and other stakeholders, shall develop capabilities making use of existing information technology industry standards and best practices, as appropriate, that support and rapidly advance the development, adoption, and implementation of automated mechanisms for the sharing of cyber threat indicators and defensive measures in accordance with title I of the Cybersecurity Act of 2015 [6 U.S.C. 1501 et seq.].

74The Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives an annual report on the status and progress of the development of the capabilities described in paragraph (1). Such reports shall be required until such capabilities are fully implemented.

75The Center may enter into a voluntary information sharing relationship with any consenting non-Federal entity for the sharing of cyber threat indicators and defensive measures for cybersecurity purposes in accordance with this section. Nothing in this subsection may be construed to require any non-Federal entity to enter into any such information sharing relationship with the Center or any other entity. The Center may terminate a voluntary information sharing relationship under this subsection, at the sole and unreviewable discretion of the Secretary, acting through the Director, for any reason, including if the Center determines that the non-Federal entity with which the Center has entered into such a relationship has violated the terms of this subsection.

76The Secretary may decline to enter into a voluntary information sharing relationship under this subsection, at the sole and unreviewable discretion of the Secretary, acting through the Director, for any reason, including if the Secretary determines that such is appropriate for national security.

77A voluntary information sharing relationship under this subsection may be characterized as an agreement described in this paragraph.

78For the use of a non-Federal entity, the Center shall make available a standard agreement, consistent with this section, on the Department's website.

79At the request of a non-Federal entity, and if determined appropriate by the Center, at the sole and unreviewable discretion of the Secretary, acting through the Director, the Department shall negotiate a non-standard agreement, consistent with this section.

80An agreement between the Center and a non-Federal entity that is entered into before December 18, 2015, or such an agreement that is in effect before such date, shall be deemed in compliance with the requirements of this subsection, notwithstanding any other provision or requirement of this subsection. An agreement under this subsection shall include the relevant privacy protections as in effect under the Cooperative Research and Development Agreement for Cybersecurity Information Sharing and Collaboration, as of December 31, 2014. Nothing in this subsection may be construed to require a non-Federal entity to enter into either a standard or negotiated agreement to be in compliance with this subsection.

81The Secretary shall develop policies and procedures for direct reporting to the Secretary by the Director of the Center regarding significant cybersecurity risks and incidents.

82Not later than 180 days after December 18, 2015, and periodically thereafter, the Secretary of Homeland Security shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the range of efforts underway to bolster cybersecurity collaboration with relevant international partners in accordance with subsection (c)(8).

83Not later than 60 days after December 18, 2015, the Secretary, acting through the Director, shall—

84(1) disseminate to the public information about how to voluntarily share cyber threat indicators and defensive measures with the Center; and

85(2) enhance outreach to critical infrastructure owners and operators for purposes of such sharing.

86The Secretary may leverage small business development centers to provide assistance to small business concerns by disseminating information on cyber threat indicators, defense measures, cybersecurity risks, incidents, analyses, and warnings to help small business concerns in developing or enhancing cybersecurity infrastructure, awareness of cyber threat indicators, and cyber training programs for employees.

87For purposes of this subsection, the terms "small business concern" and "small business development center" have the meaning given such terms, respectively, under section 632 of title 15.

88The Secretary, in coordination with industry and other stakeholders, may develop and adhere to Department policies and procedures for coordinating vulnerability disclosures.

89The Director may, as appropriate, identify, develop, and disseminate actionable protocols to mitigate cybersecurity vulnerabilities to information systems and industrial control systems, including in circumstances in which such vulnerabilities exist because software or hardware is no longer supported by a vendor.

90In this subsection, the term "covered device or system"—

91(A) means a device or system commonly used to perform industrial, commercial, scientific, or governmental functions or processes that relate to critical infrastructure, including operational and industrial control systems, distributed control systems, and programmable logic controllers; and

92(B) does not include personal devices and systems, such as consumer mobile devices, home computers, residential wireless routers, or residential internet enabled consumer devices.

93If the Director identifies a system connected to the internet with a specific security vulnerability and has reason to believe such security vulnerability relates to critical infrastructure and affects a covered device or system, and the Director is unable to identify the entity at risk that owns or operates such covered device or system, the Director may issue a subpoena for the production of information necessary to identify and notify such entity at risk, in order to carry out a function authorized under subsection (c)(12).

94A subpoena issued pursuant to subparagraph (A) may seek information—

95(i) only in the categories set forth in subparagraphs (A), (B), (D), and (E) of section 2703(c)(2) of title 18; and

96(ii) for not more than 20 covered devices or systems.

97The provisions of section 2703(e) of title 18, shall apply to any subpoena issued pursuant to subparagraph (A).

98If the Director exercises the subpoena authority under this subsection, and in the interest of avoiding interference with ongoing law enforcement investigations, the Director shall coordinate the issuance of any such subpoena with the Department of Justice, including the Federal Bureau of Investigation, pursuant to interagency procedures which the Director, in coordination with the Attorney General, shall develop not later than 60 days after January 1, 2021.

99The inter-agency procedures developed under this paragraph shall provide that a subpoena issued by the Director under this subsection shall be—

100(i) issued to carry out a function described in subsection (c)(12); and

101(ii) subject to the limitations specified in this subsection.

102If any person, partnership, corporation, association, or entity fails to comply with any duly served subpoena issued pursuant to this subsection, the Director may request that the Attorney General seek enforcement of such subpoena in any judicial district in which such person, partnership, corporation, association, or entity resides, is found, or transacts business.

103Not later than seven days after the date on which the Director receives information obtained through a subpoena issued pursuant to this subsection, the Director shall notify any entity identified by information obtained pursuant to such subpoena regarding such subpoena and the identified vulnerability.

104Any subpoena issued pursuant to this subsection shall be authenticated with a cryptographic digital signature of an authorized representative of the Agency, or other comparable successor technology, that allows the Agency to demonstrate that such subpoena was issued by the Agency and has not been altered or modified since such issuance.

105Any subpoena issued pursuant to this subsection that is not authenticated in accordance with subparagraph (A) shall not be considered to be valid by the recipient of such subpoena.

106Not later than 90 days after January 1, 2021, the Director shall establish internal procedures and associated training, applicable to employees and operations of the Agency, regarding subpoenas issued pursuant to this subsection, which shall address the following:

107(A) The protection of and restriction on dissemination of nonpublic information obtained through such a subpoena, including a requirement that the Agency not disseminate nonpublic information obtained through such a subpoena that identifies the party that is subject to such subpoena or the entity at risk identified by information obtained, except that the Agency may share the nonpublic information with the Department of Justice for the purpose of enforcing such subpoena in accordance with paragraph (4), and may share with a Federal agency the nonpublic information of the entity at risk if—

108(i) the Agency identifies or is notified of a cybersecurity incident involving such entity, which relates to the vulnerability which led to the issuance of such subpoena;

109(ii) the Director determines that sharing the nonpublic information with another Federal department or agency is necessary to allow such department or agency to take a law enforcement or national security action, consistent with the interagency procedures under paragraph (3)(A), or actions related to mitigating or otherwise resolving such incident;

110(iii) the entity to which the information pertains is notified of the Director's determination, to the extent practicable consistent with national security or law enforcement interests, consistent with such interagency procedures; and

111(iv) the entity consents, except that the entity's consent shall not be required if another Federal department or agency identifies the entity to the Agency in connection with a suspected cybersecurity incident.

112(B) The restriction on the use of information obtained through such a subpoena for a cybersecurity purpose.

113(C) The retention and destruction of nonpublic information obtained through such a subpoena, including—

114(i) destruction of such information that the Director determines is unrelated to critical infrastructure immediately upon providing notice to the entity pursuant to paragraph (5); and

115(ii) destruction of any personally identifiable information not later than 6 months after the date on which the Director receives information obtained through such a subpoena, unless otherwise agreed to by the individual identified by the subpoena respondent.

116(D) The processes for providing notice to each party that is subject to such a subpoena and each entity identified by information obtained under such a subpoena.

117(E) The processes and criteria for conducting critical infrastructure security risk assessments to determine whether a subpoena is necessary prior to being issued pursuant to this subsection.

118(F) The information to be provided to an entity at risk at the time of the notice of the vulnerability, which shall include—

119(i) a discussion or statement that responding to, or subsequent engagement with, the Agency, is voluntary; and

120(ii) to the extent practicable, information regarding the process through which the Director identifies security vulnerabilities.

121The internal procedures established pursuant to paragraph (7) may not require an owner or operator of critical infrastructure to take any action as a result of a notice of vulnerability made pursuant to this chapter.

122Not later than 1 year after January 1, 2021, the Privacy Officer of the Agency shall—

123(A) review the internal procedures established pursuant to paragraph (7) to ensure that—

124(i) such procedures are consistent with fair information practices; and

125(ii) the operations of the Agency comply with such procedures; and

126(B) notify the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives of the results of the review under subparagraph (A).

127Not later than 120 days after establishing the internal procedures under paragraph (7), the Director shall publish information on the website of the Agency regarding the subpoena process under this subsection, including information regarding the following:

128(A) Such internal procedures.

129(B) The purpose for subpoenas issued pursuant to this subsection.

130(C) The subpoena process.

131(D) The criteria for the critical infrastructure security risk assessment conducted prior to issuing a subpoena.

132(E) Policies and procedures on retention and sharing of data obtained by subpoenas.

133(F) Guidelines on how entities contacted by the Director may respond to notice of a subpoena.

134The Director shall annually submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report (which may include a classified annex but with the presumption of declassification) on the use of subpoenas issued pursuant to this subsection, which shall include the following:

135(A) A discussion of the following:

136(i) The effectiveness of the use of such subpoenas to mitigate critical infrastructure security vulnerabilities.

137(ii) The critical infrastructure security risk assessment process conducted for subpoenas issued under this subsection.

138(iii) The number of subpoenas so issued during the preceding year.

139(iv) To the extent practicable, the number of vulnerable covered devices or systems mitigated under this subsection by the Agency during the preceding year.

140(v) The number of entities notified by the Director under this subsection, and their responses, during the preceding year.

141(B) For each subpoena issued pursuant to this subsection, the following:

142(i) Information relating to the source of the security vulnerability detected, identified, or received by the Director.

143(ii) Information relating to the steps taken to identify the entity at risk prior to issuing the subpoena.

144(iii) A description of the outcome of the subpoena, including discussion on the resolution or mitigation of the critical infrastructure security vulnerability.

145The Director shall publish a version of the annual report required under paragraph (11) on the website of the Agency, which shall, at a minimum, include the findings described in clauses (iii), (iv), and (v) of subparagraph (A) of such paragraph.

146Any information obtained pursuant to a subpoena issued under this subsection may not be provided to any other Federal department or agency for any purpose other than a cybersecurity purpose or for the purpose of enforcing a subpoena issued pursuant to this subsection.

147The Director shall maintain capabilities to identify and address threats and vulnerabilities to products and technologies intended for use in the automated control of critical infrastructure processes. In carrying out this subsection, the Director shall—

148(1) lead Federal Government efforts, in consultation with Sector Risk Management Agencies, as appropriate, to identify and mitigate cybersecurity threats to industrial control systems, including supervisory control and data acquisition systems;

149(2) maintain threat hunting and incident response capabilities to respond to industrial control system cybersecurity risks and incidents;

150(3) provide cybersecurity technical assistance to industry end-users, product manufacturers, Sector Risk Management Agencies, other Federal agencies, and other industrial control system stakeholders to identify, evaluate, assess, and mitigate vulnerabilities;

151(4) collect, coordinate, and provide vulnerability information to the industrial control systems community by, as appropriate, working closely with security researchers, industry end-users, product manufacturers, Sector Risk Management Agencies, other Federal agencies, and other industrial control systems stakeholders; and

152(5) conduct such other efforts and assistance as the Secretary determines appropriate.

153The Center shall, upon request and to the extent practicable, and in coordination as appropriate with Federal and non-Federal entities, such as the Multi-State Information Sharing and Analysis Center—

154(A) conduct exercises with SLTT entities;

155(B) provide operational and technical cybersecurity training to SLTT entities to address cybersecurity risks or incidents, with or without reimbursement, related to—

156(i) cyber threat indicators;

157(ii) defensive measures;

158(iii) cybersecurity risks;

159(iv) vulnerabilities; and

160(v) incident response and management;

161(C) in order to increase situational awareness and help prevent incidents, assist SLTT entities in sharing, in real time, with the Federal Government as well as among SLTT entities, actionable—

162(i) cyber threat indicators;

163(ii) defensive measures;

164(iii) information about cybersecurity risks; and

165(iv) information about incidents;

166(D) provide SLTT entities notifications containing specific incident and malware information that may affect them or their residents;

167(E) provide to, and periodically update, SLTT entities via an easily accessible platform and other means—

168(i) information about tools;

169(ii) information about products;

170(iii) resources;

171(iv) policies;

172(v) guidelines;

173(vi) controls; and

174(vii) other cybersecurity standards and best practices and procedures related to information security, including, as appropriate, information produced by other Federal agencies;

175(F) work with senior SLTT entity officials, including chief information officers and senior election officials and through national associations, to coordinate the effective implementation by SLTT entities of tools, products, resources, policies, guidelines, controls, and procedures related to information security to secure the information systems, including election systems, of SLTT entities;

176(G) provide operational and technical assistance to SLTT entities to implement tools, products, resources, policies, guidelines, controls, and procedures on information security;

177(H) assist SLTT entities in developing policies and procedures for coordinating vulnerability disclosures consistent with international and national standards in the information technology industry; and

178(I) promote cybersecurity education and awareness through engagements with Federal agencies and non-Federal entities.

179Not later than 1 year after June 21, 2022, and every 2 years thereafter, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the services and capabilities that the Agency directly and indirectly provides to SLTT entities.

660.

Cybersecurity plans

1In this section, the term "agency information system" means an information system used or operated by an agency or by another entity on behalf of an agency.

2The Secretary, in coordination with the Director of the Office of Management and Budget, shall—

3(A) develop and implement an intrusion assessment plan to proactively detect, identify, and remove intruders in agency information systems on a routine basis; and

4(B) update such plan as necessary.

5The intrusion assessment plan required under paragraph (1) shall not apply to the Department of Defense, a national security system, or an element of the intelligence community.

6The Director of the Cybersecurity and Infrastructure Security Agency shall, in coordination with appropriate Federal departments and agencies, State and local governments, sector coordinating councils, Information Sharing and Analysis Organizations, owners and operators of critical infrastructure, and other appropriate entities and individuals, develop, update not less often than biennially, maintain, and exercise adaptable cyber incident response plans to address cybersecurity risks to critical infrastructure. The Director, in consultation with relevant Sector Risk Management Agencies and the National Cyber Director, shall develop mechanisms to engage with stakeholders to educate such stakeholders regarding Federal Government cybersecurity roles and responsibilities for cyber incident response.

7The Secretary, in coordination with the heads of other appropriate Federal departments and agencies, and in accordance with the National Cybersecurity Incident Response Plan required under subsection (c), shall regularly update, maintain, and exercise the Cyber Incident Annex to the National Response Framework of the Department.

8Not later than one year after December 27, 2021, the Secretary, acting through the Director, shall, in coordination with the heads of appropriate Federal agencies, State, local, Tribal, and territorial governments, and other stakeholders, as appropriate, develop and make publicly available a Homeland Security Strategy to Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments.

9The strategy required under subparagraph (A) shall provide recommendations relating to the ways in which the Federal Government should support and promote the ability of State, local, Tribal, and territorial governments to identify, mitigate against, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents.

10The strategy required under paragraph (1) shall—

11(A) identify capability gaps in the ability of State, local, Tribal, and territorial governments to identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents;

12(B) identify Federal resources and capabilities that are available or could be made available to State, local, Tribal, and territorial governments to help those governments identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents;

13(C) identify and assess the limitations of Federal resources and capabilities available to State, local, Tribal, and territorial governments to help those governments identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents and make recommendations to address such limitations;

14(D) identify opportunities to improve the coordination of the Agency with Federal and non-Federal entities, such as the Multi-State Information Sharing and Analysis Center, to improve—

15(i) incident exercises, information sharing and incident notification procedures;

16(ii) the ability for State, local, Tribal, and territorial governments to voluntarily adapt and implement guidance in Federal binding operational directives; and

17(iii) opportunities to leverage Federal schedules for cybersecurity investments under section 502 of title 40;

18(E) recommend new initiatives the Federal Government should undertake to improve the ability of State, local, Tribal, and territorial governments to identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents;

19(F) set short-term and long-term goals that will improve the ability of State, local, Tribal, and territorial governments to identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents; and

20(G) set dates, including interim benchmarks, as appropriate for State, local, Tribal, and territorial governments to establish baseline capabilities to identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents.

21In developing the strategy required under paragraph (1), the Director, in coordination with the heads of appropriate Federal agencies, State, local, Tribal, and territorial governments, and other stakeholders, as appropriate, shall consider—

22(A) lessons learned from incidents that have affected State, local, Tribal, and territorial governments, and exercises with Federal and non-Federal entities;

23(B) the impact of incidents that have affected State, local, Tribal, and territorial governments, including the resulting costs to such governments;

24(C) the information related to the interest and ability of state and non-state threat actors to compromise information systems owned or operated by State, local, Tribal, and territorial governments; and

25(D) emerging cybersecurity risks and cybersecurity threats to State, local, Tribal, and territorial governments resulting from the deployment of new technologies.

26Chapter 35 of title 44 (commonly known as the "Paperwork Reduction Act") shall not apply to any action to implement this subsection.

661.

Cybersecurity strategy

1Not later than 90 days after December 23, 2016, the Secretary shall develop a departmental strategy to carry out cybersecurity responsibilities as set forth in law.

2The strategy required under subsection (a) shall include the following:

3(1) Strategic and operational goals and priorities to successfully execute the full range of the Secretary's cybersecurity responsibilities.

4(2) Information on the programs, policies, and activities that are required to successfully execute the full range of the Secretary's cybersecurity responsibilities, including programs, policies, and activities in furtherance of the following:

5(A) Cybersecurity functions set forth in section 659 of this title (relating to the national cybersecurity and communications integration center).

6(B) Cybersecurity investigations capabilities.

7(C) Cybersecurity research and development.

8(D) Engagement with international cybersecurity partners.

9In developing the strategy required under subsection (a), the Secretary shall—

10(1) consider—

11(A) the cybersecurity strategy for the Homeland Security Enterprise published by the Secretary in November 2011;

12(B) the Department of Homeland Security Fiscal Years 2014–2018 Strategic Plan; and

13(C) the most recent Quadrennial Homeland Security Review issued pursuant to section 347 of this title; and

14(2) include information on the roles and responsibilities of components and offices of the Department, to the extent practicable, to carry out such strategy.

15Not later than 90 days after the development of the strategy required under subsection (a), the Secretary shall issue an implementation plan for the strategy that includes the following:

16(1) Strategic objectives and corresponding tasks.

17(2) Projected timelines and costs for such tasks.

18(3) Metrics to evaluate performance of such tasks.

19The Secretary shall submit to Congress for assessment the following:

20(1) A copy of the strategy required under subsection (a) upon issuance.

21(2) A copy of the implementation plan required under subsection (d) upon issuance, together with detailed information on any associated legislative or budgetary proposals.

22The strategy required under subsection (a) shall be in an unclassified form but may contain a classified annex.

23Nothing in this section may be construed as permitting the Department to engage in monitoring, surveillance, exfiltration, or other collection activities for the purpose of tracking an individual's personally identifiable information.

662.

Clearances

1The Secretary shall make available the process of application for security clearances under Executive Order 13549 (75 Fed. Reg. 162; 1 relating to a classified national security information program) or any successor Executive Order to appropriate representatives of sector coordinating councils, sector Information Sharing and Analysis Organizations, owners and operators of critical infrastructure, and any other person that the Secretary determines appropriate.

663.

Federal intrusion detection and prevention system

1In this section—

2(1) the term "agency" has the meaning given the term in section 3502 of title 44;

3(2) the term "agency information" means information collected or maintained by or on behalf of an agency; 1

4(3) the term "agency information system" has the meaning given the term in section 660 of this title; and 2

5Not later than 1 year after December 18, 2015, the Secretary shall deploy, operate, and maintain, to make available for use by any agency, with or without reimbursement—

6(A) a capability to detect cybersecurity risks in network traffic transiting or traveling to or from an agency information system; and

7(B) a capability to prevent network traffic associated with such cybersecurity risks from transiting or traveling to or from an agency information system or modify such network traffic to remove the cybersecurity risk.

8The Secretary shall regularly deploy new technologies and modify existing technologies to the intrusion detection and prevention capabilities described in paragraph (1) as appropriate to improve the intrusion detection and prevention capabilities.

9In carrying out subsection (b), the Secretary—

10(1) may access, and the head of an agency may disclose to the Secretary or a private entity providing assistance to the Secretary under paragraph (2), information transiting or traveling to or from an agency information system, regardless of the location from which the Secretary or a private entity providing assistance to the Secretary under paragraph (2) accesses such information, notwithstanding any other provision of law that would otherwise restrict or prevent the head of an agency from disclosing such information to the Secretary or a private entity providing assistance to the Secretary under paragraph (2);

11(2) may enter into contracts or other agreements with, or otherwise request and obtain the assistance of, private entities to deploy, operate, and maintain technologies in accordance with subsection (b);

12(3) may retain, use, and disclose information obtained through the conduct of activities authorized under this section only to protect information and information systems from cybersecurity risks;

13(4) shall regularly assess through operational test and evaluation in real world or simulated environments available advanced protective technologies to improve detection and prevention capabilities, including commercial and noncommercial technologies and detection technologies beyond signature-based detection, and acquire, test, and deploy such technologies when appropriate;

14(5) shall establish a pilot through which the Secretary may acquire, test, and deploy, as rapidly as possible, technologies described in paragraph (4); and

15(6) shall periodically update the privacy impact assessment required under section 208(b) of the E-Government Act of 2002 (44 U.S.C. 3501 note).

16In carrying out subsection (b), the Secretary shall ensure that—

17(1) activities carried out under this section are reasonably necessary for the purpose of protecting agency information and agency information systems from a cybersecurity risk;

18(2) information accessed by the Secretary will be retained no longer than reasonably necessary for the purpose of protecting agency information and agency information systems from a cybersecurity risk;

19(3) notice has been provided to users of an agency information system concerning access to communications of users of the agency information system for the purpose of protecting agency information and the agency information system; and

20(4) the activities are implemented pursuant to policies and procedures governing the operation of the intrusion detection and prevention capabilities.

21A private entity described in subsection (c)(2) may not—

22(A) disclose any network traffic transiting or traveling to or from an agency information system to any entity other than the Department or the agency that disclosed the information under subsection (c)(1), including personal information of a specific individual or information that identifies a specific individual not directly related to a cybersecurity risk; or

23(B) use any network traffic transiting or traveling to or from an agency information system to which the private entity gains access in accordance with this section for any purpose other than to protect agency information and agency information systems against cybersecurity risks or to administer a contract or other agreement entered into pursuant to subsection (c)(2) or as part of another contract with the Secretary.

24No cause of action shall lie in any court against a private entity for assistance provided to the Secretary in accordance with this section and any contract or agreement entered into pursuant to subsection (c)(2).

25Nothing in paragraph (2) shall be construed to authorize an Internet service provider to break a user agreement with a customer without the consent of the customer.

26Not later than 1 year after December 18, 2015, the Privacy Officer appointed under section 142 of this title, in consultation with the Attorney General, shall review the policies and guidelines for the program carried out under this section to ensure that the policies and guidelines are consistent with applicable privacy laws, including those governing the acquisition, interception, retention, use, and disclosure of communications.

664.

National asset database

1The Secretary shall establish and maintain a national database of each system or asset that—

2(A) the Secretary, in consultation with appropriate homeland security officials of the States, determines to be vital and the loss, interruption, incapacity, or destruction of which would have a negative or debilitating effect on the economic security, public health, or safety of the United States, any State, or any local government; or

3(B) the Secretary determines is appropriate for inclusion in the database.

4In accordance with Homeland Security Presidential Directive–7, as in effect on January 1, 2007, the Secretary shall establish and maintain a single classified prioritized list of systems and assets included in the database under paragraph (1) that the Secretary determines would, if destroyed or disrupted, cause national or regional catastrophic effects.

5The Secretary shall use the database established under subsection (a)(1) in the development and implementation of Department plans and programs as appropriate.

6The Secretary shall maintain and annually update the database established under subsection (a)(1) and the list established under subsection (a)(2), including—

7(A) establishing data collection guidelines and providing such guidelines to the appropriate homeland security official of each State;

8(B) regularly reviewing the guidelines established under subparagraph (A), including by consulting with the appropriate homeland security officials of States, to solicit feedback about the guidelines, as appropriate;

9(C) after providing the homeland security official of a State with the guidelines under subparagraph (A), allowing the official a reasonable amount of time to submit to the Secretary any data submissions recommended by the official for inclusion in the database established under subsection (a)(1);

10(D) examining the contents and identifying any submissions made by such an official that are described incorrectly or that do not meet the guidelines established under subparagraph (A); and

11(E) providing to the appropriate homeland security official of each relevant State a list of submissions identified under subparagraph (D) for review and possible correction before the Secretary finalizes the decision of which submissions will be included in the database established under subsection (a)(1).

12The Secretary shall organize the contents of the database established under subsection (a)(1) and the list established under subsection (a)(2) as the Secretary determines is appropriate. Any organizational structure of such contents shall include the categorization of the contents—

13(A) according to the sectors listed in National Infrastructure Protection Plan developed pursuant to Homeland Security Presidential Directive–7; and

14(B) by the State and county of their location.

15The Secretary shall identify and evaluate methods, including the Department's Protected Critical Infrastructure Information Program, to acquire relevant private sector information for the purpose of using that information to generate any database or list, including the database established under subsection (a)(1) and the list established under subsection (a)(2).

16The classification of information required to be provided to Congress, the Department, or any other department or agency under this section by a Sector Risk Management Agency, including the assignment of a level of classification of such information, shall be binding on Congress, the Department, and that other Federal agency.

17Not later than 180 days after August 3, 2007, and annually thereafter, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the database established under subsection (a)(1) and the list established under subsection (a)(2).

18Each such report shall include the following:

19(A) The name, location, and sector classification of each of the systems and assets on the list established under subsection (a)(2).

20(B) The name, location, and sector classification of each of the systems and assets on such list that are determined by the Secretary to be most at risk to terrorism.

21(C) Any significant challenges in compiling the list of the systems and assets included on such list or in the database established under subsection (a)(1).

22(D) Any significant changes from the preceding report in the systems and assets included on such list or in such database.

23(E) If appropriate, the extent to which such database and such list have been used, individually or jointly, for allocating funds by the Federal Government to prevent, reduce, mitigate, or respond to acts of terrorism.

24(F) The amount of coordination between the Department and the private sector, through any entity of the Department that meets with representatives of private sector industries for purposes of such coordination, for the purpose of ensuring the accuracy of such database and such list.

25(G) Any other information the Secretary deems relevant.

26The report shall be submitted in unclassified form but may contain a classified annex.

27The Secretary may establish a consortium to be known as the "National Infrastructure Protection Consortium". The Consortium may advise the Secretary on the best way to identify, generate, organize, and maintain any database or list of systems and assets established by the Secretary, including the database established under subsection (a)(1) and the list established under subsection (a)(2). If the Secretary establishes the National Infrastructure Protection Consortium, the Consortium may—

28(1) be composed of national laboratories, Federal agencies, State and local homeland security organizations, academic institutions, or national Centers of Excellence that have demonstrated experience working with and identifying critical infrastructure and key resources; and

29(2) provide input to the Secretary on any request pertaining to the contents of such database or such list.

665.

Duties and authorities relating to .gov internet domain

1In this section, the term "agency" has the meaning given the term in section 3502 of title 44.

2The Director shall make .gov internet domain name registration services, as well as any supporting services described in subsection (e), generally available—

3(1) to any Federal, State, local, or territorial government entity, or other publicly controlled entity, including any Tribal government recognized by the Federal Government or a State government, that complies with the requirements for registration developed by the Director as described in subsection (c);

4(2) without conditioning registration on the sharing of any information with the Director or any other Federal entity, other than the information required to meet the requirements described in subsection (c); and

5(3) without conditioning registration on participation in any separate service offered by the Director or any other Federal entity.

6The Director, with the approval of the Director of the Office of Management and Budget for agency .gov internet domain requirements and in consultation with the Director of the Office of Management and Budget for .gov internet domain requirements for entities that are not agencies, shall establish and publish on a publicly available website requirements for the registration and operation of .gov internet domains sufficient to—

7(1) minimize the risk of .gov internet domains whose names could mislead or confuse users;

8(2) establish that .gov internet domains may not be used for commercial or political campaign purposes;

9(3) ensure that domains are registered and maintained only by authorized individuals; and

10(4) limit the sharing or use of any information obtained through the administration of the .gov internet domain with any other Department component or any other agency for any purpose other than the administration of the .gov internet domain, the services described in subsection (e), and the requirements for establishing a .gov inventory described in subsection (h).

11The Director of the Office of Management and Budget shall establish applicable processes and guidelines for the registration and acceptable use of .gov internet domains by agencies.

12The Director shall obtain the approval of the Director of the Office of Management and Budget before registering a .gov internet domain name for an agency.

13Each agency shall ensure that any website or digital service of the agency that uses a .gov internet domain is in compliance with the 21st Century IDEA Act (44 U.S.C. 3501 note) and implementation guidance issued pursuant to that Act.

14The Director may provide services to the entities described in subsection (b)(1) specifically intended to support the security, privacy, reliability, accessibility, and speed of registered .gov internet domains.

15Nothing in paragraph (1) shall be construed to—

16(A) limit other authorities of the Director to provide services or technical assistance to an entity described in subsection (b)(1); or

17(B) establish new authority for services other than those the purpose of which expressly supports the operation of .gov internet domains and the needs of .gov internet domain registrants.

18The Director may provide any service relating to the availability of the .gov internet domain program, including .gov internet domain name registration services described in subsection (b) and supporting services described in subsection (e), to entities described in subsection (b)(1) with or without reimbursement, including variable pricing.

19The total fees collected for new .gov internet domain registrants or annual renewals of .gov internet domains shall not exceed the direct operational expenses of improving, maintaining, and operating the .gov internet domain, .gov internet domain services, and .gov internet domain supporting services.

20The Director shall consult with the Director of the Office of Management and Budget, the Administrator of General Services, other civilian Federal agencies as appropriate, and entities representing State, local, Tribal, or territorial governments in developing the strategic direction of the .gov internet domain and in establishing requirements under subsection (c), in particular on matters of privacy, accessibility, transparency, and technology modernization.

21The Director shall, on a continuous basis—

22(A) inventory all hostnames and services in active use within the .gov internet domain; and

23(B) provide the data described in subparagraph (A) to domain registrants at no cost.

24In carrying out paragraph (1)—

25(A) data may be collected through analysis of public and non-public sources, including commercial data sets;

26(B) the Director shall share with Federal and non-Federal domain registrants all unique hostnames and services discovered within the zone of their registered domain;

27(C) the Director shall share any data or information collected or used in the management of the .gov internet domain name registration services relating to Federal executive branch registrants with the Director of the Office of Management and Budget for the purpose of fulfilling the duties of the Director of the Office of Management and Budget under section 3553 of title 44;

28(D) the Director shall publish on a publicly available website discovered hostnames that describe publicly accessible agency websites, to the extent consistent with the security of Federal information systems but with the presumption of disclosure;

29(E) the Director may publish on a publicly available website any analysis conducted and data collected relating to compliance with Federal mandates and industry best practices, to the extent consistent with the security of Federal information systems but with the presumption of disclosure; and

30(F) the Director shall—

31(i) collect information on the use of non-.gov internet domain suffixes by agencies for their official online services;

32(ii) collect information on the use of non-.gov internet domain suffixes by State, local, Tribal, and territorial governments; and

33(iii) publish the information collected under clause (i) on a publicly available website to the extent consistent with the security of the Federal information systems, but with the presumption of disclosure.

34In carrying out this subsection, the Director shall inventory, collect, and publish hostnames and services in a manner consistent with the protection of national security information.

35The Director may not inventory, collect, or publish hostnames or services under this subsection if the Director, in coordination with other heads of agencies, as appropriate, determines that the collection or publication would—

36(i) disrupt a law enforcement investigation;

37(ii) endanger national security or intelligence activities;

38(iii) impede national defense activities or military operations; or

39(iv) hamper security remediation actions.

40Not later than 180 days after December 27, 2020, the Director shall develop and submit to the Committee on Homeland Security and Governmental Affairs and the Committee on Rules and Administration of the Senate and the Committee on Homeland Security, the Committee on Oversight and Reform, and the Committee on House Administration of the House of Representatives a strategy to utilize the information collected under this subsection for countering malicious cyber activity.

665a.

Intelligence and cybersecurity diversity fellowship program

1In this section:

2The term "appropriate committees of Congress" means—

3(A) the Committee on Homeland Security and Governmental Affairs and the Select Committee on Intelligence of the Senate; and

4(B) the Committee on Homeland Security and the Permanent Select Committee on Intelligence of the House of Representatives.

5The term "excepted service" has the meaning given that term in section 2103 of title 5.

6The term "historically Black college or university" has the meaning given the term "part B institution" in section 1061 of title 20.

7The term "institution of higher education" has the meaning given that term in section 1001 of title 20.

8The term "minority-serving institution" means an institution of higher education described in section 1067q(a) of title 20.

9The Secretary shall carry out an intelligence and cybersecurity diversity fellowship program (in this section referred to as the "Program") under which an eligible individual may—

10(1) participate in a paid internship at the Department that relates to intelligence, cybersecurity, or some combination thereof;

11(2) receive tuition assistance from the Secretary; and

12(3) upon graduation from an institution of higher education and successful completion of the Program (as defined by the Secretary), receive an offer of employment to work in an intelligence or cybersecurity position of the Department that is in the excepted service.

13To be eligible to participate in the Program, an individual shall—

14(1) be a citizen of the United States; and

15(2) as of the date of submitting the application to participate in the Program—

16(A) have a cumulative grade point average of at least 3.2 on a 4.0 scale;

17(B) be a socially disadvantaged individual (as that term in 1 defined in section 124.103 of title 13, Code of Federal Regulations, or successor regulation); and

18(C) be a sophomore, junior, or senior at an institution of higher education.

19If an individual who receives an offer of employment under subsection (b)(3) accepts such offer, the Secretary shall appoint, without regard to provisions of subchapter I of chapter 33 of title 5 (except for section 3328 of such title) such individual to the position specified in such offer.

20Not later than 1 year after December 27, 2020, and on an annual basis thereafter, the Secretary shall submit to the appropriate committees of Congress a report on the Program.

21Each report under paragraph (1) shall include, with respect to the most recent year, the following:

22(A) A description of outreach efforts by the Secretary to raise awareness of the Program among institutions of higher education in which eligible individuals are enrolled.

23(B) Information on specific recruiting efforts conducted by the Secretary to increase participation in the Program.

24(C) The number of individuals participating in the Program, listed by the institution of higher education in which the individual is enrolled at the time of participation, and information on the nature of such participation, including on whether the duties of the individual under the Program relate primarily to intelligence or to cybersecurity.

25(D) The number of individuals who accepted an offer of employment under the Program and an identification of the element within the Department to which each individual was appointed.

665b.

Joint cyber planning office

1There is established in the Agency an office for joint cyber planning (in this section referred to as the "Office") to develop, for public and private sector entities, plans for cyber defense operations, including the development of a set of coordinated actions to protect, detect, respond to, and recover from cybersecurity risks or incidents or limit, mitigate, or defend against coordinated, malicious cyber operations that pose a potential risk to critical infrastructure or national interests. The Office shall be headed by a senior official of the Agency selected by the Director.

2In leading the development of plans for cyber defense operations pursuant to subsection (a), the head of the Office shall—

3(1) coordinate with relevant Federal departments and agencies to establish processes and procedures necessary to develop and maintain ongoing coordinated plans for cyber defense operations;

4(2) leverage cyber capabilities and authorities of participating Federal departments and agencies, as appropriate, in furtherance of plans for cyber defense operations;

5(3) ensure that plans for cyber defense operations are, to the greatest extent practicable, developed in collaboration with relevant private sector entities, particularly in areas in which such entities have comparative advantages in limiting, mitigating, or defending against a cybersecurity risk or incident or coordinated, malicious cyber operation;

6(4) ensure that plans for cyber defense operations, as appropriate, are responsive to potential adversary activity conducted in response to United States offensive cyber operations;

7(5) facilitate the exercise of plans for cyber defense operations, including by developing and modeling scenarios based on an understanding of adversary threats to, vulnerability of, and potential consequences of disruption or compromise of critical infrastructure;

8(6) coordinate with and, as necessary, support relevant Federal departments and agencies in the establishment of procedures, development of additional plans, including for offensive and intelligence activities in support of cyber defense operations, and creation of agreements necessary for the rapid execution of plans for cyber defense operations when a cybersecurity risk or incident or malicious cyber operation has been identified; and

9(7) support public and private sector entities, as appropriate, in the execution of plans developed pursuant to this section.

10The Office shall be composed of—

11(1) a central planning staff; and

12(2) appropriate representatives of Federal departments and agencies, including—

13(A) the Department;

14(B) United States Cyber Command;

15(C) the National Security Agency;

16(D) the Federal Bureau of Investigation;

17(E) the Department of Justice; and

18(F) the Office of the Director of National Intelligence.

19In carrying out its responsibilities described in subsection (b), the Office shall regularly consult with appropriate representatives of non-Federal entities, such as—

20(1) State, local, federally-recognized Tribal, and territorial governments;

21(2) Information Sharing and Analysis Organizations, including information sharing and analysis centers;

22(3) owners and operators of critical information systems;

23(4) private entities; and

24(5) other appropriate representatives or entities, as determined by the Secretary.

25The Secretary and the head of a Federal department or agency referred to in subsection (c) may enter into agreements for the purpose of detailing personnel on a reimbursable or non-reimbursable basis.

26In this section, the term "cyber defense operation" means the defensive activities performed for a cybersecurity purpose.

665c.

Cybersecurity State Coordinator

1The Director shall appoint an employee of the Agency in each State, with the appropriate cybersecurity qualifications and expertise, who shall serve as the Cybersecurity State Coordinator.

2The duties of a Cybersecurity State Coordinator appointed under subsection (a) shall include—

3(1) building strategic public and, on a voluntary basis, private sector relationships, including by advising on establishing governance structures to facilitate the development and maintenance of secure and resilient infrastructure;

4(2) serving as the Federal cybersecurity risk advisor and supporting preparation, response, and remediation efforts relating to cybersecurity risks and incidents;

5(3) facilitating the sharing of cyber threat information to improve understanding of cybersecurity risks and situational awareness of cybersecurity incidents;

6(4) raising awareness of the financial, technical, and operational resources available from the Federal Government to non-Federal entities to increase resilience against cyber threats;

7(5) supporting training, exercises, and planning for continuity of operations to expedite recovery from cybersecurity incidents, including ransomware;

8(6) serving as a principal point of contact for non-Federal entities to engage, on a voluntary basis, with the Federal Government on preparing, managing, and responding to cybersecurity incidents;

9(7) assisting non-Federal entities in developing and coordinating vulnerability disclosure programs consistent with Federal and information security industry standards;

10(8) assisting State, local, Tribal, and territorial governments, on a voluntary basis, in the development of State cybersecurity plans;

11(9) coordinating with appropriate officials within the Agency; and

12(10) performing such other duties as determined necessary by the Director to achieve the goal of managing cybersecurity risks in the United States and reducing the impact of cyber threats to non-Federal entities.

13The Director shall consult with relevant State, local, Tribal, and territorial officials regarding the appointment, and State, local, Tribal, and territorial officials and other non-Federal entities regarding the performance, of the Cybersecurity State Coordinator of a State.

665d.

Sector Risk Management Agencies

1Consistent with applicable law, Presidential directives, Federal regulations, and strategic guidance from the Secretary, each Sector Risk Management Agency, in coordination with the Director, shall—

2(1) provide specialized sector-specific expertise to critical infrastructure owners and operators within its designated critical infrastructure sector or subsector of such sector; and

3(2) support programs and associated activities of such sector or subsector of such sector.

4In carrying out this section, Sector Risk Management Agencies shall—

5(1) coordinate with the Department and, as appropriate, other relevant Federal departments and agencies;

6(2) collaborate with critical infrastructure owners and operators within the designated critical infrastructure sector or subsector of such sector; and

7(3) coordinate with independent regulatory agencies, and State, local, Tribal, and territorial entities, as appropriate.

8Consistent with applicable law, Presidential directives, Federal regulations, and strategic guidance from the Secretary, each Sector Risk Management Agency shall utilize its specialized expertise regarding its designated critical infrastructure sector or subsector of such sector and authorities under applicable law to—

9(1) support sector risk management, in coordination with the Director, including—

10(A) establishing and carrying out programs to assist critical infrastructure owners and operators within the designated sector or subsector of such sector in identifying, understanding, and mitigating threats, vulnerabilities, and risks to their systems or assets, or within a region, sector, or subsector of such sector; and

11(B) recommending security measures to mitigate the consequences of destruction, compromise, and disruption of systems and assets;

12(2) assess sector risk, in coordination with the Director, including—

13(A) identifying, assessing, and prioritizing risks within the designated sector or subsector of such sector, considering physical security and cybersecurity threats, vulnerabilities, and consequences; and

14(B) supporting national risk assessment efforts led by the Department;

15(3) sector coordination, including—

16(A) serving as a day-to-day Federal interface for the prioritization and coordination of sector-specific activities and responsibilities under this title;

17(B) serving as the Federal Government coordinating council chair for the designated sector or subsector of such sector; and

18(C) participating in cross-sector coordinating councils, as appropriate;

19(4) facilitating, in coordination with the Director, the sharing with the Department and other appropriate Federal department of information regarding physical security and cybersecurity threats within the designated sector or subsector of such sector, including—

20(A) facilitating, in coordination with the Director, access to, and exchange of, information and intelligence necessary to strengthen the security of critical infrastructure, including through Information Sharing and Analysis Organizations and the national cybersecurity and communications integration center established pursuant to section 659 of this title;

21(B) facilitating the identification of intelligence needs and priorities of critical infrastructure owners and operators in the designated sector or subsector of such sector, in coordination with the Director of National Intelligence and the heads of other Federal departments and agencies, as appropriate;

22(C) providing the Director, and facilitating awareness within the designated sector or subsector of such sector, of ongoing, and where possible, real-time awareness of identified threats, vulnerabilities, mitigations, and other actions related to the security of such sector or subsector of such sector; and

23(D) supporting the reporting requirements of the Department under applicable law by providing, on an annual basis, sector-specific critical infrastructure information;

24(5) supporting incident management, including—

25(A) supporting, in coordination with the Director, incident management and restoration efforts during or following a security incident; and

26(B) supporting the Director, upon request, in national cybersecurity asset response activities for critical infrastructure; and

27(6) contributing to emergency preparedness efforts, including—

28(A) coordinating with critical infrastructure owners and operators within the designated sector or subsector of such sector and the Director in the development of planning documents for coordinated action in the event of a natural disaster, act of terrorism, or other man-made disaster or emergency;

29(B) participating in and, in coordination with the Director, conducting or facilitating, exercises and simulations of potential natural disasters, acts of terrorism, or other man-made disasters or emergencies within the designated sector or subsector of such sector; and

30(C) supporting the Department and other Federal departments or agencies in developing planning documents or conducting exercises or simulations when relevant to the designated sector or subsector or such sector.

665e.

Cybersecurity Advisory Committee

1The Secretary shall establish within the Agency a Cybersecurity Advisory Committee (referred to in this section as the "Advisory Committee").

2The Advisory Committee shall advise, consult with, report to, and make recommendations to the Director, as appropriate, on the development, refinement, and implementation of policies, programs, planning, and training pertaining to the cybersecurity mission of the Agency.

3The Advisory Committee shall develop, at the request of the Director, recommendations for improvements to advance the cybersecurity mission of the Agency and strengthen the cybersecurity of the United States.

4Recommendations agreed upon by subcommittees established under subsection (d) for any year shall be approved by the Advisory Committee before the Advisory Committee submits to the Director the annual report under paragraph (4) for that year.

5The Advisory Committee shall periodically submit to the Director—

6(A) reports on matters identified by the Director; and

7(B) reports on other matters identified by a majority of the members of the Advisory Committee.

8The Advisory Committee shall submit to the Director an annual report providing information on the activities, findings, and recommendations of the Advisory Committee, including its subcommittees, for the preceding year.

9Not later than 180 days after the date on which the Director receives an annual report for a year under subparagraph (A), the Director shall publish a public version of the report describing the activities of the Advisory Committee and such related matters as would be informative to the public during that year, consistent with section 552(b) of title 5.

10Not later than 90 days after receiving any recommendation submitted by the Advisory Committee under paragraph (2), (3), or (4), the Director shall respond in writing to the Advisory Committee with feedback on the recommendation. Such a response shall include—

11(A) with respect to any recommendation with which the Director concurs, an action plan to implement the recommendation; and

12(B) with respect to any recommendation with which the Director does not concur, a justification for why the Director does not plan to implement the recommendation.

13Not less frequently than once per year after January 1, 2021, the Director shall provide to the Committee on Homeland Security and Governmental Affairs and the Committee on Appropriations of the Senate and the Committee on Homeland Security, the Committee on Energy and Commerce, and the Committee on Appropriations of the House of Representatives a briefing on feedback from the Advisory Committee.

14The Director shall establish rules for the structure and governance of the Advisory Committee and all subcommittees established under subsection (d).

15Not later than 180 days after the date of enactment of the Cybersecurity Advisory Committee Authorization Act of 2020,1 the Director shall appoint the members of the Advisory Committee.

16The membership of the Advisory Committee shall consist of not more than 35 individuals.

17The membership of the Advisory Committee shall satisfy the following criteria:

18(I) Consist of subject matter experts.

19(II) Be geographically balanced.

20(III) Include representatives of State, local, and Tribal governments and of a broad range of industries, which may include the following:

21(aa) Defense.

22(bb) Education.

23(cc) Financial services and insurance.

24(dd) Healthcare.

25(ee) Manufacturing.

26(ff) Media and entertainment.

27(gg) Chemicals.

28(hh) Retail.

29(ii) Transportation.

30(jj) Energy.

31(kk) Information Technology.

32(ll) Communications.

33(mm) Other relevant fields identified by the Director.

34Not fewer than one member nor more than three members may represent any one category under clause (i)(III).

35The Advisory Committee shall publish its membership list on a publicly available website not less than once per fiscal year and shall update the membership list as changes occur.

36The term of each member of the Advisory Committee shall be two years, except that a member may continue to serve until a successor is appointed.

37The Director may review the participation of a member of the Advisory Committee and remove such member any time at the discretion of the Director.

38A member of the Advisory Committee may be reappointed for an unlimited number of terms.

39The members of the Advisory Committee may not receive pay or benefits from the United States Government by reason of their service on the Advisory Committee.

40The Director shall require the Advisory Committee to meet not less frequently than semiannually, and may convene additional meetings as necessary.

41At least one of the meetings referred to in subparagraph (A) shall be open to the public.

42The Advisory Committee shall maintain a record of the persons present at each meeting.

43Not later than 60 days after the date on which a member is first appointed to the Advisory Committee and before the member is granted access to any classified information, the Director shall determine, for the purposes of the Advisory Committee, if the member should be restricted from reviewing, discussing, or possessing classified information.

44Access to classified materials shall be managed in accordance with Executive Order No. 13526 of December 29, 2009 (75 Fed. Reg. 707), or any subsequent corresponding Executive Order.

45A member of the Advisory Committee shall protect all classified information in accordance with the applicable requirements for the particular level of classification of such information.

46Nothing in this paragraph shall be construed to affect the security clearance of a member of the Advisory Committee or the authority of a Federal agency to provide a member of the Advisory Committee access to classified information.

47The Advisory Committee shall select, from among the members of the Advisory Committee—

48(A) a member to serve as chairperson of the Advisory Committee; and

49(B) a member to serve as chairperson of each subcommittee of the Advisory Committee established under subsection (d).

50The Director shall establish subcommittees within the Advisory Committee to address cybersecurity issues, which may include the following:

51(A) Information exchange.

52(B) Critical infrastructure.

53(C) Risk management.

54(D) Public and private partnerships.

55Each subcommittee shall meet not less frequently than semiannually, and submit to the Advisory Committee for inclusion in the annual report required under subsection (b)(4) information, including activities, findings, and recommendations, regarding subject matter considered by the subcommittee.

56The chair of the Advisory Committee shall appoint members to subcommittees and shall ensure that each member appointed to a subcommittee has subject matter expertise relevant to the subject matter of the subcommittee.

665f.

Cybersecurity education and training programs

1The Cybersecurity Education and Training Assistance Program (referred to in this section as "CETAP") is established within the Agency.

2The purpose of CETAP shall be to support the effort of the Agency in building and strengthening a national cybersecurity workforce pipeline capacity through enabling elementary and secondary cybersecurity education, including by—

3(A) providing foundational cybersecurity awareness and literacy;

4(B) encouraging cybersecurity career exploration; and

5(C) supporting the teaching of cybersecurity skills at the elementary and secondary education levels.

6In carrying out CETAP, the Director shall—

7(1) ensure that the program—

8(A) creates and disseminates cybersecurity-focused curricula and career awareness materials appropriate for use at the elementary and secondary education levels;

9(B) conducts professional development sessions for teachers;

10(C) develops resources for the teaching of cybersecurity-focused curricula described in subparagraph (A);

11(D) provides direct student engagement opportunities through camps and other programming;

12(E) engages with State educational agencies and local educational agencies to promote awareness of the program and ensure that offerings align with State and local curricula;

13(F) integrates with existing post-secondary education and workforce development programs at the Department;

14(G) promotes and supports national standards for elementary and secondary cyber education;

15(H) partners with cybersecurity and education stakeholder groups to expand outreach; and

16(I) any other activity the Director determines necessary to meet the purpose described in subsection (a)(2); and

17(2) enable the deployment of CETAP nationwide, with special consideration for underserved populations or communities.

18Not later than 1 year after the establishment of CETAP, and annually thereafter, the Secretary shall brief the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives on the program.

19Each briefing conducted under paragraph (1) shall include—

20(A) estimated figures on the number of students reached and teachers engaged;

21(B) information on outreach and engagement efforts, including the activities described in subsection (b)(1)(E);

22(C) information on any grants or cooperative agreements made pursuant to subsection (e), including how any such grants or cooperative agreements are being used to enhance cybersecurity education for underserved populations or communities;

23(D) information on new curricula offerings and teacher training platforms; and

24(E) information on coordination with post-secondary education and workforce development programs at the Department.

25The Director may use appropriated amounts to purchase promotional and recognition items and marketing and advertising services to publicize and promote the mission and services of the Agency, support the activities of the Agency, and to recruit and retain Agency personnel.

26The Director may award financial assistance in the form of grants or cooperative agreements to States, local governments, institutions of higher education (as such term is defined in section 1001 of title 20), nonprofit organizations, and other non-Federal entities as determined appropriate by the Director for the purpose of funding cybersecurity and infrastructure security education and training programs and initiatives to—

27(1) carry out the purposes of CETAP; and

28(2) enhance CETAP to address the national shortfall of cybersecurity professionals.

665g.

State and Local Cybersecurity Grant Program

1In this section:

2The term "Cybersecurity Plan" means a plan submitted by an eligible entity under subsection (e)(1).

3The term "eligible entity" means a—

4(A) State; or

5(B) Tribal government.

6The term "multi-entity group" means a group of 2 or more eligible entities desiring a grant under this section.

7The term "online service" means any internet-facing service, including a website, email, virtual private network, or custom application.

8The term "rural area" has the meaning given the term in section 5302 of title 49.

9The term "State and Local Cybersecurity Grant Program" means the program established under subsection (b).

10The term "Tribal government" means the recognized governing body of any Indian or Alaska Native Tribe, band, nation, pueblo, village, community, component band, or component reservation, that is individually identified (including parenthetically) in the most recent list published pursuant to section 5131 of title 25.

11There is established within the Department a program to award grants to eligible entities to address cybersecurity risks and cybersecurity threats to information systems owned or operated by, or on behalf of, State, local, or Tribal governments.

12An eligible entity desiring a grant under the State and Local Cybersecurity Grant Program shall submit to the Secretary an application at such time, in such manner, and containing such information as the Secretary may require.

13The State and Local Cybersecurity Grant Program shall be administered in the same office of the Department that administers grants made under sections 604 and 605 of this title.

14An eligible entity that receives a grant under this section and a local government that receives funds from a grant under this section, as appropriate, shall use the grant to—

15(1) implement the Cybersecurity Plan of the eligible entity;

16(2) develop or revise the Cybersecurity Plan of the eligible entity;

17(3) pay expenses directly relating to the administration of the grant, which shall not exceed 5 percent of the amount of the grant;

18(4) assist with activities that address imminent cybersecurity threats, as confirmed by the Secretary, acting through the Director, to the information systems owned or operated by, or on behalf of, the eligible entity or a local government within the jurisdiction of the eligible entity; or

19(5) fund any other appropriate activity determined by the Secretary, acting through the Director.

20An eligible entity applying for a grant under this section shall submit to the Secretary a Cybersecurity Plan for review in accordance with subsection (i).

21A Cybersecurity Plan of an eligible entity shall—

22(A) incorporate, to the extent practicable—

23(i) any existing plans of the eligible entity to protect against cybersecurity risks and cybersecurity threats to information systems owned or operated by, or on behalf of, State, local, or Tribal governments; and

24(ii) if the eligible entity is a State, consultation and feedback from local governments and associations of local governments within the jurisdiction of the eligible entity;

25(B) describe, to the extent practicable, how the eligible entity will—

26(i) manage, monitor, and track information systems, applications, and user accounts owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, and the information technology deployed on those information systems, including legacy information systems and information technology that are no longer supported by the manufacturer of the systems or technology;

27(ii) monitor, audit, and,1 track network traffic and activity transiting or traveling to or from information systems, applications, and user accounts owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity;

28(iii) enhance the preparation, response, and resiliency of information systems, applications, and user accounts owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, against cybersecurity risks and cybersecurity threats;

29(iv) implement a process of continuous cybersecurity vulnerability assessments and threat mitigation practices prioritized by degree of risk to address cybersecurity risks and cybersecurity threats on information systems, applications, and user accounts owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity;

30(v) ensure that the eligible entity and, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, adopt and use best practices and methodologies to enhance cybersecurity, such as—

31(I) the practices set forth in the cybersecurity framework developed by the National Institute of Standards and Technology;

32(II) cyber chain supply chain risk management best practices identified by the National Institute of Standards and Technology; and

33(III) knowledge bases of adversary tools and tactics;

34(vi) promote the delivery of safe, recognizable, and trustworthy online services by the eligible entity and, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, including through the use of the .gov internet domain;

35(vii) ensure continuity of operations of the eligible entity and, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, in the event of a cybersecurity incident, including by conducting exercises to practice responding to a cybersecurity incident;

36(viii) use the National Initiative for Cybersecurity Education Workforce Framework for Cybersecurity developed by the National Institute of Standards and Technology to identify and mitigate any gaps in the cybersecurity workforces of the eligible entity and, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, enhance recruitment and retention efforts for those workforces, and bolster the knowledge, skills, and abilities of personnel of the eligible entity and, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, to address cybersecurity risks and cybersecurity threats, such as through cybersecurity hygiene training;

37(ix) if the eligible entity is a State, ensure continuity of communications and data networks within the jurisdiction of the eligible entity between the eligible entity and local governments within the jurisdiction of the eligible entity in the event of an incident involving those communications or data networks;

38(x) assess and mitigate, to the greatest degree possible, cybersecurity risks and cybersecurity threats relating to critical infrastructure and key resources, the degradation of which may impact the performance of information systems within the jurisdiction of the eligible entity;

39(xi) enhance capabilities to share cyber threat indicators and related information between the eligible entity and—

40(I) if the eligible entity is a State, local governments within the jurisdiction of the eligible entity, including by expanding information sharing agreements with the Department; and

41(II) the Department;

42(xii) leverage cybersecurity services offered by the Department;

43(xiii) implement an information technology and operational technology modernization cybersecurity review process that ensures alignment between information technology and operational technology cybersecurity objectives;

44(xiv) develop and coordinate strategies to address cybersecurity risks and cybersecurity threats in consultation with—

45(I) if the eligible entity is a State, local governments and associations of local governments within the jurisdiction of the eligible entity; and

46(II) as applicable—

47(aa) eligible entities that neighbor the jurisdiction of the eligible entity or, as appropriate, members of an Information Sharing and Analysis Organization; and

48(bb) countries that neighbor the jurisdiction of the eligible entity;

49(xv) ensure adequate access to, and participation in, the services and programs described in this subparagraph by rural areas within the jurisdiction of the eligible entity; and

50(xvi) distribute funds, items, services, capabilities, or activities to local governments under subsection (n)(2)(A), including the fraction of that distribution the eligible entity plans to distribute to rural areas under subsection (n)(2)(B);

51(C) assess the capabilities of the eligible entity relating to the actions described in subparagraph (B);

52(D) describe, as appropriate and to the extent practicable, the individual responsibilities of the eligible entity and local governments within the jurisdiction of the eligible entity in implementing the plan;

53(E) outline, to the extent practicable, the necessary resources and a timeline for implementing the plan; and

54(F) describe the metrics the eligible entity will use to measure progress towards—

55(i) implementing the plan; and

56(ii) reducing cybersecurity risks to, and identifying, responding to, and recovering from cybersecurity threats to, information systems owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity.

57In drafting a Cybersecurity Plan, an eligible entity may—

58(A) consult with the Multi-State Information Sharing and Analysis Center;

59(B) include a description of cooperative programs developed by groups of local governments within the jurisdiction of the eligible entity to address cybersecurity risks and cybersecurity threats; and

60(C) include a description of programs provided by the eligible entity to support local governments and owners and operators of critical infrastructure to address cybersecurity risks and cybersecurity threats.

61The Secretary may award grants under this section to a multi-entity group to support multi-entity efforts to address cybersecurity risks and cybersecurity threats to information systems within the jurisdictions of the eligible entities that comprise the multi-entity group.

62In order to be eligible for a multi-entity grant under this subsection, each eligible entity that comprises a multi-entity group shall have—

63(A) a Cybersecurity Plan that has been reviewed by the Secretary in accordance with subsection (i); and

64(B) a cybersecurity planning committee established in accordance with subsection (g).

65A multi-entity group applying for a multi-entity grant under paragraph (1) shall submit to the Secretary an application at such time, in such manner, and containing such information as the Secretary may require.

66An application for a grant under this section of a multi-entity group under subparagraph (A) shall include a plan describing—

67(i) the division of responsibilities among the eligible entities that comprise the multi-entity group;

68(ii) the distribution of funding from the grant among the eligible entities that comprise the multi-entity group; and

69(iii) how the eligible entities that comprise the multi-entity group will work together to implement the Cybersecurity Plan of each of those eligible entities.

70An eligible entity that receives a grant under this section shall establish a cybersecurity planning committee to—

71(A) assist with the development, implementation, and revision of the Cybersecurity Plan of the eligible entity;

72(B) approve the Cybersecurity Plan of the eligible entity; and

73(C) assist with the determination of effective funding priorities for a grant under this section in accordance with subsections (d) and (j).

74A committee of an eligible entity established under paragraph (1) shall—

75(A) be comprised of representatives from—

76(i) the eligible entity;

77(ii) if the eligible entity is a State, counties, cities, and towns within the jurisdiction of the eligible entity; and

78(iii) institutions of public education and health within the jurisdiction of the eligible entity; and

79(B) include, as appropriate, representatives of rural, suburban, and high-population jurisdictions.

80Not less than one-half of the representatives of a committee established under paragraph (1) shall have professional experience relating to cybersecurity or information technology.

81Nothing in this subsection shall be construed to require an eligible entity to establish a cybersecurity planning committee if the eligible entity has established and uses a multijurisdictional planning committee or commission that—

82(A) meets the requirements of this subsection; or

83(B) may be expanded or leveraged to meet the requirements of this subsection, including through the formation of a cybersecurity planning subcommittee.

84Nothing in this subsection shall be construed to permit a cybersecurity planning committee of an eligible entity that meets the requirements of this subsection to make decisions relating to information systems owned or operated by, or on behalf of, the eligible entity.

85With respect to any requirement under subsection (e) or (g), the Secretary, in consultation with the Secretary of the Interior and Tribal governments, may prescribe an alternative substantively similar requirement for Tribal governments if the Secretary finds that the alternative requirement is necessary for the effective delivery and administration of grants to Tribal governments under this section.

86Subject to paragraph (3), before an eligible entity may receive a grant under this section, the Secretary, acting through the Director, shall—

87(i) review the Cybersecurity Plan of the eligible entity, including any revised Cybersecurity Plans of the eligible entity; and

88(ii) determine that the Cybersecurity Plan reviewed under clause (i) satisfies the requirements under paragraph (2).

89In the case of a determination under subparagraph (A)(ii) that a Cybersecurity Plan satisfies the requirements under paragraph (2), the determination shall be effective for the 2-year period beginning on the date of the determination.

90Not later than 2 years after the date on which the Secretary determines under subparagraph (A)(ii) that a Cybersecurity Plan satisfies the requirements under paragraph (2), and annually thereafter, the Secretary, acting through the Director, shall—

91(i) determine whether the Cybersecurity Plan and any revisions continue to meet the criteria described in paragraph (2); and

92(ii) renew the determination if the Secretary, acting through the Director, makes a positive determination under clause (i).

93In reviewing a Cybersecurity Plan of an eligible entity under this subsection, the Secretary, acting through the Director, shall ensure that the Cybersecurity Plan—

94(A) satisfies the requirements of subsection (e)(2); and

95(B) has been approved by—

96(i) the cybersecurity planning committee of the eligible entity established under subsection (g); and

97(ii) the Chief Information Officer, the Chief Information Security Officer, or an equivalent official of the eligible entity.

98Notwithstanding subsection (e) and paragraph (1) of this subsection, the Secretary may award a grant under this section to an eligible entity that does not submit a Cybersecurity Plan to the Secretary for review before September 30, 2023, if the eligible entity certifies to the Secretary that—

99(A) the activities that will be supported by the grant are—

100(i) integral to the development of the Cybersecurity Plan of the eligible entity; or

101(ii) necessary to assist with activities described in subsection (d)(4), as confirmed by the Director; and

102(B) the eligible entity will submit to the Secretary a Cybersecurity Plan for review under this subsection by September 30, 2023.

103Nothing in this subsection shall be construed to provide authority to the Secretary to—

104(A) regulate the manner by which an eligible entity or local government improves the cybersecurity of the information systems owned or operated by, or on behalf of, the eligible entity or local government; or

105(B) condition the receipt of grants under this section on—

106(i) participation in a particular Federal program; or

107(ii) the use of a specific product or technology.

108Any entity that receives funds from a grant under this section may not use the grant—

109(A) to supplant State or local funds;

110(B) for any recipient cost-sharing contribution;

111(C) to pay a ransom;

112(D) for recreational or social purposes; or

113(E) for any purpose that does not address cybersecurity risks or cybersecurity threats on information systems owned or operated by, or on behalf of, the eligible entity that receives the grant or a local government within the jurisdiction of the eligible entity.

114In addition to any other remedy available, the Secretary may take such actions as are necessary to ensure that a recipient of a grant under this section uses the grant for the purposes for which the grant is awarded.

115Nothing in paragraph (1)(A) shall be construed to prohibit the use of funds from a grant under this section awarded to a State, local, or Tribal government for otherwise permissible uses under this section on the basis that the State, local, or Tribal government has previously used State, local, or Tribal funds to support the same or similar uses.

116In considering applications for grants under this section, the Secretary shall provide applicants with a reasonable opportunity to correct any defects in those applications before making final awards, including by allowing applicants to revise a submitted Cybersecurity Plan.

117For fiscal year 2022 and each fiscal year thereafter, the Secretary shall apportion amounts appropriated to carry out this section among eligible entities as follows:

118The Secretary shall first apportion—

119(A) 0.25 percent of such amounts to each of American Samoa, the Commonwealth of the Northern Mariana Islands, Guam, and the United States Virgin Islands;

120(B) 1 percent of such amounts to each of the remaining States; and

121(C) 3 percent of such amounts to Tribal governments.

122The Secretary shall apportion the remainder of such amounts to States as follows:

123(A) 50 percent of such remainder in the ratio that the population of each State, bears to the population of all States; and

124(B) 50 percent of such remainder in the ratio that the population of each State that resides in rural areas, bears to the population of all States that resides in rural areas.

125In determining how to apportion amounts to Tribal governments under paragraph (1)(C), the Secretary shall consult with the Secretary of the Interior and Tribal governments.

126An amount received from a multi-entity grant awarded under subsection (f)(1) by a State or Tribal government that is a member of the multi-entity group shall qualify as an apportionment for the purpose of this subsection.

127The Federal share of the cost of an activity carried out using funds made available with a grant under this section may not exceed—

128(A) in the case of a grant to an eligible entity—

129(i) for fiscal year 2022, 90 percent;

130(ii) for fiscal year 2023, 80 percent;

131(iii) for fiscal year 2024, 70 percent; and

132(iv) for fiscal year 2025, 60 percent; and

133(B) in the case of a grant to a multi-entity group—

134(i) for fiscal year 2022, 100 percent;

135(ii) for fiscal year 2023, 90 percent;

136(iii) for fiscal year 2024, 80 percent; and

137(iv) for fiscal year 2025, 70 percent.

138The Secretary may waive or modify the requirements of paragraph (1) if an eligible entity or multi-entity group demonstrates economic hardship.

139The Secretary shall establish and publish guidelines for determining what constitutes economic hardship for the purposes of this subsection.

140In developing guidelines under subparagraph (B), the Secretary shall consider, with respect to the jurisdiction of an eligible entity—

141(i) changes in rates of unemployment in the jurisdiction from previous years;

142(ii) changes in the percentage of individuals who are eligible to receive benefits under the supplemental nutrition assistance program established under the Food and Nutrition Act of 2008 (7 U.S.C. 2011 et seq.) from previous years; and

143(iii) any other factors the Secretary considers appropriate.

144Notwithstanding paragraph (2), the Secretary, in consultation with the Secretary of the Interior and Tribal governments, may waive or modify the requirements of paragraph (1) for 1 or more Tribal governments if the Secretary determines that the waiver is in the public interest.

145Each eligible entity or multi-entity group that receives a grant under this section shall certify to the Secretary that the grant will be used—

146(A) for the purpose for which the grant is awarded; and

147(B) in compliance with subsections (d) and (j).

148Subject to subparagraph (C), not later than 45 days after the date on which an eligible entity or multi-entity group receives a grant under this section, the eligible entity or multi-entity group shall, without imposing unreasonable or unduly burdensome requirements as a condition of receipt, obligate or otherwise make available to local governments within the jurisdiction of the eligible entity or the eligible entities that comprise the multi-entity group, consistent with the Cybersecurity Plan of the eligible entity or the Cybersecurity Plans of the eligible entities that comprise the multi-entity group—

149(i) not less than 80 percent of funds available under the grant;

150(ii) with the consent of the local governments, items, services, capabilities, or activities having a value of not less than 80 percent of the amount of the grant; or

151(iii) with the consent of the local governments, grant funds combined with other items, services, capabilities, or activities having the total value of not less than 80 percent of the amount of the grant.

152In obligating funds, items, services, capabilities, or activities to local governments under subparagraph (A), the eligible entity or eligible entities that comprise the multi-entity group shall ensure that rural areas within the jurisdiction of the eligible entity or the eligible entities that comprise the multi-entity group receive not less than—

153(i) 25 percent of the amount of the grant awarded to the eligible entity;

154(ii) items, services, capabilities, or activities having a value of not less than 25 percent of the amount of the grant awarded to the eligible entity; or

155(iii) grant funds combined with other items, services, capabilities, or activities having the total value of not less than 25 percent of the grant awarded to the eligible entity.

156This paragraph shall not apply to—

157(i) any grant awarded under this section that solely supports activities that are integral to the development or revision of the Cybersecurity Plan of the eligible entity; or

158(ii) the District of Columbia, the Commonwealth of Puerto Rico, American Samoa, the Commonwealth of the Northern Mariana Islands, Guam, the United States Virgin Islands, or a Tribal government.

159An eligible entity or multi-entity group shall certify to the Secretary that the eligible entity or multi-entity group has made the distribution to local governments required under paragraph (2).

160An eligible entity or multi-entity group may request in writing that the Secretary extend the period of time specified in paragraph (2) for an additional period of time.

161The Secretary may approve a request for an extension under subparagraph (A) if the Secretary determines the extension is necessary to ensure that the obligation and expenditure of grant funds align with the purpose of the State and Local Cybersecurity Grant Program.

162If an eligible entity does not make a distribution to a local government required under paragraph (2) in a timely fashion, the local government may petition the Secretary to request the Secretary to provide funds directly to the local government.

163A grant awarded under this section may not be used to acquire land or to construct, remodel, or perform alterations of buildings or other physical facilities.

164An eligible entity applying for a grant under this section shall agree to consult the Chief Information Officer, the Chief Information Security Officer, or an equivalent official of the eligible entity in allocating funds from a grant awarded under this section.

165In addition to other remedies available to the Secretary, if an eligible entity violates a requirement of this subsection, the Secretary may—

166(A) terminate or reduce the amount of a grant awarded under this section to the eligible entity; or

167(B) distribute grant funds previously awarded to the eligible entity—

168(i) in the case of an eligible entity that is a State, directly to the appropriate local government as a replacement grant in an amount determined by the Secretary; or

169(ii) in the case of an eligible entity that is a Tribal government, to another Tribal government or Tribal governments as a replacement grant in an amount determined by the Secretary.

170In carrying out this section, the Secretary shall consult with State, local, and Tribal representatives with professional experience relating to cybersecurity, including representatives of associations representing State, local, and Tribal governments, to inform—

171(1) guidance for applicants for grants under this section, including guidance for Cybersecurity Plans;

172(2) the study of risk-based formulas required under subsection (q)(4);

173(3) the development of guidelines required under subsection (m)(2)(B); and

174(4) any modifications described in subsection (q)(2)(D).

175Not later than 3 business days before the date on which the Department announces the award of a grant to an eligible entity under this section, including an announcement to the eligible entity, the Secretary shall provide to the appropriate congressional committees notice of the announcement.

176Not later than 1 year after the date on which an eligible entity receives a grant under this section for the purpose of implementing the Cybersecurity Plan of the eligible entity, including an eligible entity that comprises a multi-entity group that receives a grant for that purpose, and annually thereafter until 1 year after the date on which funds from the grant are expended or returned, the eligible entity shall submit to the Secretary a report that, using the metrics described in the Cybersecurity Plan of the eligible entity, describes the progress of the eligible entity in—

177(i) implementing the Cybersecurity Plan of the eligible entity; and

178(ii) reducing cybersecurity risks to, and identifying, responding to, and recovering from cybersecurity threats to, information systems owned or operated by, or on behalf of, the eligible entity or, if the eligible entity is a State, local governments within the jurisdiction of the eligible entity.

179Not later than 1 year after the date on which an eligible entity that does not have a Cybersecurity Plan receives funds under this section, and annually thereafter until 1 year after the date on which funds from the grant are expended or returned, the eligible entity shall submit to the Secretary a report describing how the eligible entity obligated and expended grant funds to—

180(i) develop or revise a Cybersecurity Plan; or

181(ii) assist with the activities described in subsection (d)(4).

182Not less frequently than annually, the Secretary, acting through the Director, shall submit to Congress a report on—

183(A) the use of grants awarded under this section;

184(B) the proportion of grants used to support cybersecurity in rural areas;

185(C) the effectiveness of the State and Local Cybersecurity Grant Program;

186(D) any necessary modifications to the State and Local Cybersecurity Grant Program; and

187(E) any progress made toward—

188(i) developing, implementing, or revising Cybersecurity Plans; and

189(ii) reducing cybersecurity risks to, and identifying, responding to, and recovering from cybersecurity threats to, information systems owned or operated by, or on behalf of, State, local, or Tribal governments as a result of the award of grants under this section.

190The Secretary, acting through the Director, shall make each report submitted under paragraph (2) publicly available, including by making each report available on the website of the Agency.

191In making each report publicly available under subparagraph (A), the Director may make redactions that the Director, in consultation with each eligible entity, determines necessary to protect classified or other information exempt from disclosure under section 552 of title 5 (commonly referred to as the "Freedom of Information Act").

192Not later than September 30, 2024, the Secretary, acting through the Director, shall submit to the appropriate congressional committees a study and legislative recommendations on the potential use of a risk-based formula for apportioning funds under this section, including—

193(i) potential components that could be included in a risk-based formula, including the potential impact of those components on support for rural areas under this section;

194(ii) potential sources of data and information necessary for the implementation of a risk-based formula;

195(iii) any obstacles to implementing a risk-based formula, including obstacles that require a legislative solution;

196(iv) if a risk-based formula were to be implemented for fiscal year 2026, a recommended risk-based formula for the State and Local Cybersecurity Grant Program; and

197(v) any other information that the Secretary, acting through the Director, determines necessary to help Congress understand the progress towards, and obstacles to, implementing a risk-based formula.

198The requirements of chapter 35 of title 44 (commonly referred to as the "Paperwork Reduction Act"), shall not apply to any action taken to carry out this paragraph.

199Not later than 2 years after November 15, 2021, the Secretary, acting through the Director, shall submit to Congress a report that—

200(A) describes the cybersecurity needs of Tribal governments, which shall be determined in consultation with the Secretary of the Interior and Tribal governments; and

201(B) includes any recommendations for addressing the cybersecurity needs of Tribal governments, including any necessary modifications to the State and Local Cybersecurity Grant Program to better serve Tribal governments.

202Not later than 3 years after November 15, 2021, the Comptroller General of the United States shall conduct a review of the State and Local Cybersecurity Grant Program, including—

203(A) the grant selection process of the Secretary; and

204(B) a sample of grants awarded under this section.

205There are authorized to be appropriated for activities under this section—

206(A) for fiscal year 2022, $200,000,000;

207(B) for fiscal year 2023, $400,000,000;

208(C) for fiscal year 2024, $300,000,000; and

209(D) for fiscal year 2025, $100,000,000.

210During a fiscal year, the Secretary or the head of any component of the Department that administers the State and Local Cybersecurity Grant Program may transfer not more than 5 percent of the amounts appropriated pursuant to paragraph (1) or other amounts appropriated to carry out the State and Local Cybersecurity Grant Program for that fiscal year to an account of the Department for salaries, expenses, and other administrative costs incurred for the management, administration, or evaluation of this section.

211Any funds transferred under subparagraph (A) shall be in addition to any funds appropriated to the Department or the components described in subparagraph (A) for salaries, expenses, and other administrative costs.

212Subject to paragraph (2), the requirements of this section shall terminate on September 30, 2025.

213The reporting requirements under subsection (q) shall terminate on the date that is 1 year after the date on which the final funds from a grant under this section are expended or returned.

665h.

National Cyber Exercise Program

1There is established in the Agency the National Cyber Exercise Program (referred to in this section as the "Exercise Program") to evaluate the National Cyber Incident Response Plan, and other related plans and strategies.

2The Exercise Program shall be—

3(i) based on current risk assessments, including credible threats, vulnerabilities, and consequences;

4(ii) designed, to the extent practicable, to simulate the partial or complete incapacitation of a government or critical infrastructure network resulting from a cyber incident;

5(iii) designed to provide for the systematic evaluation of cyber readiness and enhance operational understanding of the cyber incident response system and relevant information sharing agreements; and

6(iv) designed to promptly develop after-action reports and plans that can quickly incorporate lessons learned into future operations.

7The Exercise Program shall—

8(i) include a selection of model exercises that government and private entities can readily adapt for use; and

9(ii) aid such governments and private entities with the design, implementation, and evaluation of exercises that—

10(I) conform to the requirements described in subparagraph (A);

11(II) are consistent with any applicable national, State, local, or Tribal strategy or plan; and

12(III) provide for systematic evaluation of readiness.

13In carrying out the Exercise Program, the Director may consult with appropriate representatives from Sector Risk Management Agencies, the Office of the National Cyber Director, cybersecurity research stakeholders, and Sector Coordinating Councils.

14In this section:

15The term "State" means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Northern Mariana Islands, the United States Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.

16The term "private entity" has the meaning given such term in section 1501 of this title.

17Nothing in this section shall be construed to affect the authorities or responsibilities of the Administrator of the Federal Emergency Management Agency pursuant to section 748 of this title.

665i.

CyberSentry program

1There is established in the Agency a program, to be known as "CyberSentry", to provide continuous monitoring and detection of cybersecurity risks to critical infrastructure entities that own or operate industrial control systems that support national critical functions, upon request and subject to the consent of such owner or operator.

2The Director, through CyberSentry, shall—

3(1) enter into strategic partnerships with critical infrastructure owners and operators that, in the determination of the Director and subject to the availability of resources, own or operate regionally or nationally significant industrial control systems that support national critical functions, in order to provide technical assistance in the form of continuous monitoring of industrial control systems and the information systems that support such systems and detection of cybersecurity risks to such industrial control systems and other cybersecurity services, as appropriate, based on and subject to the agreement and consent of such owner or operator;

4(2) leverage sensitive or classified intelligence about cybersecurity risks regarding particular sectors, particular adversaries, and trends in tactics, techniques, and procedures to advise critical infrastructure owners and operators regarding mitigation measures and share information as appropriate;

5(3) identify cybersecurity risks in the information technology and information systems that support industrial control systems which could be exploited by adversaries attempting to gain access to such industrial control systems, and work with owners and operators to remediate such vulnerabilities;

6(4) produce aggregated, anonymized analytic products, based on threat hunting and continuous monitoring and detection activities and partnerships, with findings and recommendations that can be disseminated to critical infrastructure owners and operators; and

7(5) support activities authorized in accordance with section 1501 of the National Defense Authorization Act for Fiscal Year 2022.

8Not later than 180 days after December 27, 2021, the Privacy Officer of the Agency under section 652(h) of this title shall—

9(1) review the policies, guidelines, and activities of CyberSentry for compliance with all applicable privacy laws, including such laws governing the acquisition, interception, retention, use, and disclosure of communities; and

10(2) submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report certifying compliance with all applicable privacy laws as referred to in paragraph (1), or identifying any instances of noncompliance with such privacy laws.

11Not later than one year after December 27, 2021, the Director shall provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a briefing and written report on implementation of this section.

12Nothing in this section may be construed to permit the Federal Government to gain access to information of a remote computing service provider to the public or an electronic service provider to the public, the disclosure of which is not permitted under section 2702 of title 18.

13In this section, the term "industrial control system" means an information system used to monitor and/or control industrial processes such as manufacturing, product handling, production, and distribution, including supervisory control and data acquisition (SCADA) systems used to monitor and/or control geographically dispersed assets, distributed control systems (DCSs), Human-Machine Interfaces (HMIs), and programmable logic controllers that control localized processes.

14The authority to carry out a program under this section shall terminate on the date that is seven years after December 27, 2021.

665j.

Ransomware threat mitigation activities

1Not later than 180 days after March 15, 2022, the Director, in consultation with the National Cyber Director, the Attorney General, and the Director of the Federal Bureau of Investigation, shall establish and chair the Joint Ransomware Task Force to coordinate an ongoing nationwide campaign against ransomware attacks, and identify and pursue opportunities for international cooperation.

2The Joint Ransomware Task Force shall consist of participants from Federal agencies, as determined appropriate by the National Cyber Director in consultation with the Secretary of Homeland Security.

3The Joint Ransomware Task Force, utilizing only existing authorities of each participating Federal agency, shall coordinate across the Federal Government the following activities:

4(A) Prioritization of intelligence-driven operations to disrupt specific ransomware actors.

5(B) Consult with relevant private sector, State, local, Tribal, and territorial governments and international stakeholders to identify needs and establish mechanisms for providing input into the Joint Ransomware Task Force.

6(C) Identifying, in consultation with relevant entities, a list of highest threat ransomware entities updated on an ongoing basis, in order to facilitate—

7(i) prioritization for Federal action by appropriate Federal agencies; and

8(ii) identify 1 metrics for success of said actions.

9(D) Disrupting ransomware criminal actors, associated infrastructure, and their finances.

10(E) Facilitating coordination and collaboration between Federal entities and relevant entities, including the private sector, to improve Federal actions against ransomware threats.

11(F) Collection, sharing, and analysis of ransomware trends to inform Federal actions.

12(G) Creation of after-action reports and other lessons learned from Federal actions that identify successes and failures to improve subsequent actions.

13(H) Any other activities determined appropriate by the Joint Ransomware Task Force to mitigate the threat of ransomware attacks.

14Nothing in this section shall be construed to provide any additional authority to any Federal agency.

665k.

Federal Clearinghouse on School Safety Evidence-based Practices

1The Secretary, in coordination with the Secretary of Education, the Attorney General, and the Secretary of Health and Human Services, shall establish a Federal Clearinghouse on School Safety Evidence-based Practices (in this section referred to as the "Clearinghouse") within the Department.

2The Clearinghouse shall serve as a Federal resource to identify and publish online through SchoolSafety.gov, or any successor website, evidence-based practices and recommendations to improve school safety for use by State and local educational agencies, institutions of higher education, State and local law enforcement agencies, health professionals, and the general public.

3The Clearinghouse shall be assigned such personnel and resources as the Secretary considers appropriate to carry out this section.

4The Secretary of Education, the Attorney General, and the Secretary of Health and Human Services may detail personnel to the Clearinghouse.

5Chapter 35 of title 44 (commonly known as the "Paperwork Reduction Act"), shall not apply to any rulemaking or information collection required under this section.

6The Federal Advisory Committee Act (5 U.S.C. App.) 1 shall not apply for the purposes of carrying out this section.

7In identifying the evidence-based practices and recommendations for the Clearinghouse, the Secretary shall—

8(A) consult with appropriate Federal, State, local, Tribal, private sector, and nongovernmental organizations, including civil rights and disability rights organizations; and

9(B) consult with the Secretary of Education to ensure that evidence-based practices published by the Clearinghouse are aligned with evidence-based practices to support a positive and safe learning environment for all students.

10The evidence-based practices and recommendations of the Clearinghouse shall—

11(A) include comprehensive evidence-based school safety measures;

12(B) include the evidence or research rationale supporting the determination of the Clearinghouse that the evidence-based practice or recommendation under subparagraph (A) has been shown to have a significant effect on improving the health, safety, and welfare of persons in school settings, including—

13(i) relevant research that is evidence-based, as defined in section 7801 of title 20, supporting the evidence-based practice or recommendation;

14(ii) findings and data from previous Federal or State commissions recommending improvements to the safety posture of a school; or

15(iii) other supportive evidence or findings relied upon by the Clearinghouse in determining evidence-based practices and recommendations, as determined in consultation with the officers described in subsection (a)(3)(B);

16(C) include information on Federal programs for which implementation of each evidence-based practice or recommendation is an eligible use for the program;

17(D) be consistent with Federal civil rights laws, including title II of the Americans with Disabilities Act of 1990 (42 U.S.C. 12131 et seq.), the Rehabilitation Act of 1973 (29 U.S.C. 701 et seq.), and title VI of the Civil Rights Act of 1964 (42 U.S.C. 2000d et seq.); and

18(E) include options for developmentally appropriate recommendations for use in educational settings with respect to children's ages and physical, social, sensory, and emotionally developmental statuses.

19The Clearinghouse shall present, as determined in consultation with the officers described in subsection (a)(3)(B), Federal, State, local, Tribal, private sector, and nongovernmental organization issued best practices and recommendations and identify any best practice or recommendation of the Clearinghouse that was previously issued by any such organization or commission.

20The Secretary may produce and publish materials on the Clearinghouse to assist and train educational agencies and law enforcement agencies on the implementation of the evidence-based practices and recommendations.

21The Secretary shall—

22(1) collect for the purpose of continuous improvement of the Clearinghouse—

23(A) Clearinghouse data analytics;

24(B) user feedback on the implementation of resources, evidence-based practices, and recommendations identified by the Clearinghouse; and

25(C) any evaluations conducted on implementation of the evidence-based practices and recommendations of the Clearinghouse; and

26(2) in coordination with the Secretary of Education, the Secretary of Health and Human Services, and the Attorney General—

27(A) regularly assess and identify Clearinghouse evidence-based practices and recommendations for which there are no resources available through Federal Government programs for implementation; and

28(B) establish an external advisory board, which shall be comprised of appropriate State, local, Tribal, private sector, and nongovernmental organizations, including organizations representing parents of elementary and secondary school students, representative 2 from civil rights organizations, representatives of disability rights organizations, representatives of educators, representatives of law enforcement, and nonprofit school safety and security organizations, to—

29(i) provide feedback on the implementation of evidence-based practices and recommendations of the Clearinghouse; and

30(ii) propose additional recommendations for evidence-based practices for inclusion in the Clearinghouse that meet the requirements described in subsection (b)(2)(B).

31The Clearinghouse shall produce materials in accessible formats to assist parents and legal guardians of students with identifying relevant Clearinghouse resources related to supporting the implementation of Clearinghouse evidence-based practices and recommendations.

665l.

School and daycare protection

1Not later than 180 days after December 23, 2022, and annually thereafter, the Secretary of Homeland Security shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report regarding the following:

2(1) The Department of Homeland Security's activities, policies, and plans to enhance the security of early childhood education programs, elementary schools, and secondary schools during the preceding year that includes information on the Department's activities through the Federal School Safety Clearinghouse.

3(2) Information on all structures or efforts within the Department intended to bolster coordination among departmental components and offices involved in carrying out paragraph (1) and, with respect to each structure or effort, specificity on which components and offices are involved and which component or office leads such structure or effort.

4(3) A detailed description of the measures used to ensure privacy rights, civil rights, and civil liberties protections in carrying out these activities.

5Not later than 30 days after the submission of each report required under subsection (a), the Secretary of Homeland Security shall provide to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a briefing regarding such report and the status of efforts to carry out plans included in such report for the preceding year.

6In this section, the terms "early childhood education program", "elementary school", and "secondary school" have the meanings given such terms in section 7801 of title 20.

665m.

President's Cup Cybersecurity Competition

1The Director of the Cybersecurity and Infrastructure Security Agency (in this section referred to as the "Director") of the Department of Homeland Security is authorized to hold an annual cybersecurity competition to be known as the "Department of Homeland Security Cybersecurity and Infrastructure Security Agency's President's Cup Cybersecurity Competition" (in this section referred to as the "competition") for the purpose of identifying, challenging, and competitively awarding prizes, including cash prizes, to the United States Government's best cybersecurity practitioners and teams across offensive and defensive cybersecurity disciplines.

2To be eligible to participate in the competition, an individual shall be a Federal civilian employee or member of the uniformed services (as such term is defined in section 2101(3) of title 5) and shall comply with any rules promulgated by the Director regarding the competition.

3The Director may enter into a grant, contract, cooperative agreement, or other agreement with a private sector for-profit or nonprofit entity or State or local government agency to administer the competition.

4Each competition shall incorporate the following elements:

5(1) Cybersecurity skills outlined in the National Initiative for Cybersecurity Education Framework, or any successor framework.

6(2) Individual and team events.

7(3) Categories demonstrating offensive and defensive cyber operations, such as software reverse engineering and exploitation, network operations, forensics, big data analysis, cyber analysis, cyber defense, cyber exploitation, secure programming, obfuscated coding, or cyber-physical systems.

8(4) Any other elements related to paragraphs (1), (2), or (3), as determined necessary by the Director.

9In order to further the goals and objectives of the competition, the Director may use amounts made available to the Director for the competition for reasonable expenses for the following:

10(A) Advertising, marketing, and promoting the competition.

11(B) Meals for participants and organizers of the competition if attendance at the meal during the competition is necessary to maintain the integrity of the competition.

12(C) Promotional items, including merchandise and apparel.

13(D) Consistent with section 4503 of title 5, necessary expenses for the honorary recognition of competition participants, including members of the uniformed services.

14(E) Monetary and nonmonetary awards for competition participants, including members of the uniformed services, subject to subsection (f).

15This subsection shall apply to amounts appropriated on or after December 23, 2022.

16The Director may make one or more awards per competition, except that the amount or value of each shall not exceed $10,000.

17The Secretary of Homeland Security may make one or more awards per competition, except the amount or the value of each shall not exceed $25,000.

18A monetary award under this section shall be in addition to the regular pay of the recipient.

19The total amount or value of awards made under this Act 1 during a fiscal year may not exceed $100,000.

20The Director shall annually provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report that includes the following with respect to each competition conducted in the preceding year:

21(1) A description of available amounts.

22(2) A description of authorized expenditures.

23(3) Information relating to participation.

24(4) Information relating to lessons learned, and how such lessons may be applied to improve cybersecurity operations and recruitment of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security.

665n.

Industrial Control Systems Cybersecurity Training Initiative

1The Industrial Control Systems Cybersecurity Training Initiative (in this section referred to as the "Initiative") is established within the Agency.

2The purpose of the Initiative is to develop and strengthen the skills of the cybersecurity workforce related to securing industrial control systems.

3In carrying out the Initiative, the Director shall—

4(1) ensure the Initiative includes—

5(A) virtual and in-person trainings and courses provided at no cost to participants;

6(B) trainings and courses available at different skill levels, including introductory level courses;

7(C) trainings and courses that cover cyber defense strategies for industrial control systems, including an understanding of the unique cyber threats facing industrial control systems and the mitigation of security vulnerabilities in industrial control systems technology; and

8(D) appropriate consideration regarding the availability of trainings and courses in different regions of the United States; and 1

9(2) engage in—

10(A) collaboration with the National Laboratories of the Department of Energy in accordance with section 189 of this title;

11(B) consultation with Sector Risk Management Agencies;2

12(C) as appropriate, consultation with private sector entities with relevant expertise, such as vendors of industrial control systems technologies; and

13(3) consult, to the maximum extent practicable, with commercial training providers and academia to minimize the potential for duplication of other training opportunities.

14Not later than one year after December 23, 2022, and annually thereafter, the Director shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the Initiative.

15Each report submitted under paragraph (1) shall include the following:

16(A) A description of the courses provided under the Initiative.

17(B) A description of outreach efforts to raise awareness of the availability of such courses.

18(C) The number of participants in each course.

19(D) Voluntarily provided information on the demographics of participants in such courses, including by sex, race, and place of residence.

20(E) Information on the participation in such courses of workers from each critical infrastructure sector.

21(F) Plans for expanding access to industrial control systems education and training, including expanding access to women and underrepresented populations, and expanding access to different regions of the United States.

22(G) Recommendations regarding how to strengthen the state of industrial control systems cybersecurity education and training.

671.

Definitions

1In this part:

2The term "agency" has the meaning given it in section 551 of title 5.

3The term "covered Federal agency" means the Department of Homeland Security.

4The term "critical infrastructure information" has the meaning given the term in section 650 of this title.

5The term "critical infrastructure protection program" means any component or bureau of a covered Federal agency that has been designated by the President or any agency head to receive critical infrastructure information.

6The term "protected system"—

7(A) means any service, physical or computer-based system, process, or procedure that directly or indirectly affects the viability of a facility of critical infrastructure; and

8(B) includes any physical or computer-based system, including a computer, computer system, computer or communications network, or any component hardware or element thereof, software program, processing instructions, or information or data in transmission or storage therein, irrespective of the medium of transmission or storage.

9The term "voluntary", in the case of any submittal of critical infrastructure information to a covered Federal agency, means the submittal thereof in the absence of such agency's exercise of legal authority to compel access to or submission of such information and may be accomplished by a single entity or an Information Sharing and Analysis Organization on behalf of itself or its members.

10The term "voluntary"—

11(i) in the case of any action brought under the securities laws as is defined in section 78c(a)(47) of title 15—

12(I) does not include information or statements contained in any documents or materials filed with the Securities and Exchange Commission, or with Federal banking regulators, pursuant to section 78l(i) of title 15; and

13(II) with respect to the submittal of critical infrastructure information, does not include any disclosure or writing that when made accompanied the solicitation of an offer or a sale of securities; and

14(ii) does not include information or statements submitted or relied upon as a basis for making licensing or permitting determinations, or during regulatory proceedings.

672.

Designation of critical infrastructure protection program

1A critical infrastructure protection program may be designated as such by one of the following:

2(1) The President.

3(2) The Secretary of Homeland Security.

673.

Protection of voluntarily shared critical infrastructure information

1Notwithstanding any other provision of law, critical infrastructure information (including the identity of the submitting person or entity) that is voluntarily submitted to a covered Federal agency for use by that agency regarding the security of critical infrastructure and protected systems, analysis, warning, interdependency study, recovery, reconstitution, or other informational purpose, when accompanied by an express statement specified in paragraph (2)—

2(A) shall be exempt from disclosure under section 552 of title 5 (commonly referred to as the Freedom of Information Act);

3(B) shall not be subject to any agency rules or judicial doctrine regarding ex parte communications with a decision making official;

4(C) shall not, without the written consent of the person or entity submitting such information, be used directly by such agency, any other Federal, State, or local authority, or any third party, in any civil action arising under Federal or State law if such information is submitted in good faith;

5(D) shall not, without the written consent of the person or entity submitting such information, be used or disclosed by any officer or employee of the United States for purposes other than the purposes of this part, except—

6(i) in furtherance of an investigation or the prosecution of a criminal act; or

7(ii) when disclosure of the information would be—

8(I) to either House of Congress, or to the extent of matter within its jurisdiction, any committee or subcommittee thereof, any joint committee thereof or subcommittee of any such joint committee; or

9(II) to the Comptroller General, or any authorized representative of the Comptroller General, in the course of the performance of the duties of the Government Accountability Office.1

10(E) shall not, if provided to a State or local government or government agency—

11(i) be made available pursuant to any State or local law requiring disclosure of information or records;

12(ii) otherwise be disclosed or distributed to any party by said State or local government or government agency without the written consent of the person or entity submitting such information; or

13(iii) be used other than for the purpose of protecting critical infrastructure or protected systems, or in furtherance of an investigation or the prosecution of a criminal act; and

14(F) does not constitute a waiver of any applicable privilege or protection provided under law, such as trade secret protection.

15For purposes of paragraph (1), the term "express statement", with respect to information or records, means—

16(A) in the case of written information or records, a written marking on the information or records substantially similar to the following: "This information is voluntarily submitted to the Federal Government in expectation of protection from disclosure as provided by the provisions of the Critical Infrastructure Information Act of 2002."; or

17(B) in the case of oral information, a similar written statement submitted within a reasonable period following the oral communication.

18No communication of critical infrastructure information to a covered Federal agency made pursuant to this part shall be considered to be an action subject to the requirements of chapter 10 of title 5.

19Nothing in this section shall be construed to limit or otherwise affect the ability of a State, local, or Federal Government entity, agency, or authority, or any third party, under applicable law, to obtain critical infrastructure information in a manner not covered by subsection (a), including any information lawfully and properly disclosed generally or broadly to the public and to use such information in any manner permitted by law. For purposes of this section a permissible use of independently obtained information includes the disclosure of such information under section 2302(b)(8) of title 5.

20The voluntary submittal to the Government of information or records that are protected from disclosure by this part shall not be construed to constitute compliance with any requirement to submit such information to a Federal agency under any other provision of law.

21The Secretary of the Department of Homeland Security shall, in consultation with appropriate representatives of the National Security Council and the Office of Science and Technology Policy, establish uniform procedures for the receipt, care, and storage by Federal agencies of critical infrastructure information that is voluntarily submitted to the Government. The procedures shall be established not later than 90 days after November 25, 2002.

22The procedures established under paragraph (1) shall include mechanisms regarding—

23(A) the acknowledgement of receipt by Federal agencies of critical infrastructure information that is voluntarily submitted to the Government;

24(B) the maintenance of the identification of such information as voluntarily submitted to the Government for purposes of and subject to the provisions of this part;

25(C) the care and storage of such information; and

26(D) the protection and maintenance of the confidentiality of such information so as to permit the sharing of such information within the Federal Government and with State and local governments, and the issuance of notices and warnings related to the protection of critical infrastructure and protected systems, in such manner as to protect from public disclosure the identity of the submitting person or entity, or information that is proprietary, business sensitive, relates specifically to the submitting person or entity, and is otherwise not appropriately in the public domain.

27Whoever, being an officer or employee of the United States or of any department or agency thereof, knowingly publishes, divulges, discloses, or makes known in any manner or to any extent not authorized by law, any critical infrastructure information protected from disclosure by this part coming to him in the course of this employment or official duties or by reason of any examination or investigation made by, or return, report, or record made to or filed with, such department or agency or officer or employee thereof, shall be fined under title 18, imprisoned not more than 1 year, or both, and shall be removed from office or employment.

28The Federal Government may provide advisories, alerts, and warnings to relevant companies, targeted sectors, other governmental entities, or the general public regarding potential threats to critical infrastructure as appropriate. In issuing a warning, the Federal Government shall take appropriate actions to protect from disclosure—

29(1) the source of any voluntarily submitted critical infrastructure information that forms the basis for the warning; or

30(2) information that is proprietary, business sensitive, relates specifically to the submitting person or entity, or is otherwise not appropriately in the public domain.

31The President may delegate authority to a critical infrastructure protection program, designated under section 672 of this title, to enter into a voluntary agreement to promote critical infrastructure security, including with any Information Sharing and Analysis Organization, or a plan of action as otherwise defined in section 4558 of title 50.

674.

No private right of action

1Nothing in this part may be construed to create a private right of action for enforcement of any provision of this chapter.

677.

Sense of Congress

1It is the sense of Congress that—

2(1) the purpose of this part is to authorize the Secretary to declare that a significant incident has occurred and to establish the authorities that are provided under the declaration to respond to and recover from the significant incident; and

3(2) the authorities established under this part are intended to enable the Secretary to provide voluntary assistance to non-Federal entities impacted by a significant incident.

677a.

Definitions

1For the purposes of this part:

2The term "asset response activity" means an activity to support an entity impacted by an incident with the response to, remediation of, or recovery from, the incident, including—

3(A) furnishing technical and advisory assistance to the entity to protect the assets of the entity, mitigate vulnerabilities, and reduce the related impacts;

4(B) assessing potential risks to the critical infrastructure sector or geographic region impacted by the incident, including potential cascading effects of the incident on other critical infrastructure sectors or geographic regions;

5(C) developing courses of action to mitigate the risks assessed under subparagraph (B);

6(D) facilitating information sharing and operational coordination with entities performing threat response activities; and

7(E) providing guidance on how best to use Federal resources and capabilities in a timely, effective manner to speed recovery from the incident.

8The term "declaration" means a declaration of the Secretary under section 677b(a)(1) of this title.

9The term "Director" means the Director of the Cybersecurity and Infrastructure Security Agency.

10The term "Federal agency" has the meaning given the term "agency" in section 3502 of title 44.

11The term "Fund" means the Cyber Response and Recovery Fund established under section 677c(a) of this title.

12The term "incident" has the meaning given the term in section 3552 of title 44.

13The term "renewal" means a renewal of a declaration under section 677b(d) of this title.

14The term "significant incident"—

15(A) means an incident or a group of related incidents that results, or is likely to result, in demonstrable harm to—

16(i) the national security interests, foreign relations, or economy of the United States; or

17(ii) the public confidence, civil liberties, or public health and safety of the people of the United States; and

18(B) does not include an incident or a portion of a group of related incidents that occurs on—

19(i) a national security system (as defined in section 3552 of title 44); or

20(ii) an information system described in paragraph (2) or (3) of section 3553(e) of title 44.

677b.

Declaration

1The Secretary, in consultation with the National Cyber Director, may make a declaration of a significant incident in accordance with this section for the purpose of enabling the activities described in this part if the Secretary determines that—

2(A) a specific significant incident—

3(i) has occurred; or

4(ii) is likely to occur imminently; and

5(B) otherwise available resources, other than the Fund, are likely insufficient to respond effectively to, or to mitigate effectively, the specific significant incident described in subparagraph (A).

6The Secretary may not delegate the authority provided to the Secretary under paragraph (1).

7Upon a declaration, the Director shall coordinate—

8(1) the asset response activities of each Federal agency in response to the specific significant incident associated with the declaration; and

9(2) with appropriate entities, which may include—

10(A) public and private entities and State and local governments with respect to the asset response activities of those entities and governments; and

11(B) Federal, State, local, and Tribal law enforcement agencies with respect to investigations and threat response activities of those law enforcement agencies; and

12(3) Federal, State, local, and Tribal emergency management and response agencies.

13Subject to subsection (d), a declaration shall terminate upon the earlier of—

14(1) a determination by the Secretary that the declaration is no longer necessary; or

15(2) the expiration of the 120-day period beginning on the date on which the Secretary makes the declaration.

16The Secretary, without delegation, may renew a declaration as necessary.

17Not later than 72 hours after a declaration or a renewal, the Secretary shall publish the declaration or renewal in the Federal Register.

18A declaration or renewal published under paragraph (1) may not include the name of any affected individual or private company.

19The Secretary—

20(A) shall assess the resources available to respond to a potential declaration; and

21(B) may take actions before and while a declaration is in effect to arrange or procure additional resources for asset response activities or technical assistance the Secretary determines necessary, which may include entering into standby contracts with private entities for cybersecurity services or incident responders in the event of a declaration.

22Any expenditure from the Fund for the purpose of paragraph (1)(B) shall be made from amounts available in the Fund, and amounts available in the Fund shall be in addition to any other appropriations available to the Cybersecurity and Infrastructure Security Agency for such purpose.

677c.

Cyber Response and Recovery Fund

1There is established a Cyber Response and Recovery Fund, which shall be available for—

2(1) the coordination of activities described in section 677b(b) of this title;

3(2) response and recovery support for the specific significant incident associated with a declaration to Federal, State, local, and Tribal, entities and public and private entities on a reimbursable or non-reimbursable basis, including through asset response activities and technical assistance, such as—

4(A) vulnerability assessments and mitigation;

5(B) technical incident mitigation;

6(C) malware analysis;

7(D) analytic support;

8(E) threat detection and hunting; and

9(F) network protections;

10(3) as the Director determines appropriate, grants for, or cooperative agreements with, Federal, State, local, and Tribal public and private entities to respond to, and recover from, the specific significant incident associated with a declaration, such as—

11(A) hardware or software to replace, update, improve, harden, or enhance the functionality of existing hardware, software, or systems; and

12(B) technical contract personnel support; and

13(4) advance actions taken by the Secretary under section 677b(f)(1)(B) of this title.

14Amounts shall be deposited into the Fund from—

15(A) appropriations to the Fund for activities of the Fund; and

16(B) reimbursement from Federal agencies for the activities described in paragraphs (1), (2), and (4) of subsection (a), which shall only be from amounts made available in advance in appropriations Acts for such reimbursement.

17Any expenditure from the Fund for the purposes of this part shall be made from amounts available in the Fund from a deposit described in paragraph (1), and amounts available in the Fund shall be in addition to any other appropriations available to the Cybersecurity and Infrastructure Security Agency for such purposes.

18Amounts in the Fund shall be used to supplement, not supplant, other Federal, State, local, or Tribal funding for activities in response to a declaration.

19The Secretary shall require an entity that receives amounts from the Fund to submit a report to the Secretary that details the specific use of the amounts.

677d.

Notification and reporting

1Upon a declaration or renewal, the Secretary shall immediately notify the National Cyber Director and appropriate congressional committees and include in the notification—

2(1) an estimation of the planned duration of the declaration;

3(2) with respect to a notification of a declaration, the reason for the declaration, including information relating to the specific significant incident or imminent specific significant incident, including—

4(A) the operational or mission impact or anticipated impact of the specific significant incident on Federal and non-Federal entities;

5(B) if known, the perpetrator of the specific significant incident; and

6(C) the scope of the Federal and non-Federal entities impacted or anticipated to be impacted by the specific significant incident;

7(3) with respect to a notification of a renewal, the reason for the renewal;

8(4) justification as to why available resources, other than the Fund, are insufficient to respond to or mitigate the specific significant incident; and

9(5) a description of the coordination activities described in section 677b(b) of this title that the Secretary anticipates the Director to perform.

10Not later than 180 days after the date of a declaration or renewal, the Secretary shall submit to the appropriate congressional committees a report that includes—

11(1) the reason for the declaration or renewal, including information and intelligence relating to the specific significant incident that led to the declaration or renewal;

12(2) the use of any funds from the Fund for the purpose of responding to the incident or threat described in paragraph (1);

13(3) a description of the actions, initiatives, and projects undertaken by the Department and State and local governments and public and private entities in responding to and recovering from the specific significant incident described in paragraph (1);

14(4) an accounting of the specific obligations and outlays of the Fund; and

15(5) an analysis of—

16(A) the impact of the specific significant incident described in paragraph (1) on Federal and non-Federal entities;

17(B) the impact of the declaration or renewal on the response to, and recovery from, the specific significant incident described in paragraph (1); and

18(C) the impact of the funds made available from the Fund as a result of the declaration or renewal on the recovery from, and response to, the specific significant incident described in paragraph (1).

19Each notification made under subsection (a) and each report submitted under subsection (b)—

20(1) shall be in an unclassified form with appropriate markings to indicate information that is exempt from disclosure under section 552 of title 5 (commonly known as the "Freedom of Information Act"); and

21(2) may include a classified annex.

22The Secretary shall not be required to submit multiple reports under subsection (b) for multiple declarations or renewals if the Secretary determines that the declarations or renewals substantively relate to the same specific significant incident.

23The requirements of subchapter I of chapter 35 of title 44 (commonly known as the "Paperwork Reduction Act") shall not apply to the voluntary collection of information by the Department during an investigation of, a response to, or an immediate post-response review of, the specific significant incident leading to a declaration or renewal.

677e.

Rule of construction

1Nothing in this part shall be construed to impair or limit the ability of the Director to carry out the authorized activities of the Cybersecurity and Infrastructure Security Agency.

677f.

Authorization of appropriations

1There are authorized to be appropriated to the Fund $20,000,000 for fiscal year 2022 and each fiscal year thereafter until September 30, 2028, which shall remain available until September 30, 2028.

677g.

Sunset

1The authorities granted to the Secretary or the Director under this part shall expire on the date that is 7 years after November 15, 2021.

681.

Definitions

1In this part:

2The term "Center" means the center established under section 659 of this title.

3The term "Council" means the Cyber Incident Reporting Council described in section 681f of this title.

4The term "covered cyber incident" means a substantial cyber incident experienced by a covered entity that satisfies the definition and criteria established by the Director in the final rule issued pursuant to section 681b(b) of this title.

5The term "covered entity" means an entity in a critical infrastructure sector, as defined in Presidential Policy Directive 21, that satisfies the definition established by the Director in the final rule issued pursuant to section 681b(b) of this title.

6The term "cyber incident"—

7(A) has the meaning given the term "incident" in section 659 1 of this title; and

8(B) does not include an occurrence that imminently, but not actually, jeopardizes—

9(i) information on information systems; or

10(ii) information systems.

11The term "cyber threat" has the meaning given the term "cybersecurity threat" in section 650 of this title.

12The term "Federal entity" has the meaning given the term in section 1501 of this title.

13The term "ransom payment" means the transmission of any money or other property or asset, including virtual currency, or any portion thereof, which has at any time been delivered as ransom in connection with a ransomware attack.

14The term "significant cyber incident" means a cyber incident, or a group of related cyber incidents, that the Secretary determines is likely to result in demonstrable harm to the national security interests, foreign relations, or economy of the United States or to the public confidence, civil liberties, or public health and safety of the people of the United States.

15The term "virtual currency" means the digital representation of value that functions as a medium of exchange, a unit of account, or a store of value.

16The term "virtual currency address" means a unique public cryptographic key identifying the location to which a virtual currency payment can be made.

681a.

Cyber incident review

1The Center shall—

2(1) receive, aggregate, analyze, and secure, using processes consistent with the processes developed pursuant to the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501 et seq.) reports from covered entities related to a covered cyber incident to assess the effectiveness of security controls, identify tactics, techniques, and procedures adversaries use to overcome those controls and other cybersecurity purposes, including to assess potential impact of cyber incidents on public health and safety and to enhance situational awareness of cyber threats across critical infrastructure sectors;

3(2) coordinate and share information with appropriate Federal departments and agencies to identify and track ransom payments, including those utilizing virtual currencies;

4(3) leverage information gathered about cyber incidents to—

5(A) enhance the quality and effectiveness of information sharing and coordination efforts with appropriate entities, including agencies, sector coordinating councils, Information Sharing and Analysis Organizations, State, local, Tribal, and territorial governments, technology providers, critical infrastructure owners and operators, cybersecurity and cyber incident response firms, and security researchers; and

6(B) provide appropriate entities, including sector coordinating councils, Information Sharing and Analysis Organizations, State, local, Tribal, and territorial governments, technology providers, cybersecurity and cyber incident response firms, and security researchers, with timely, actionable, and anonymized reports of cyber incident campaigns and trends, including, to the maximum extent practicable, related contextual information, cyber threat indicators, and defensive measures, pursuant to section 681e of this title;

7(4) establish mechanisms to receive feedback from stakeholders on how the Agency can most effectively receive covered cyber incident reports, ransom payment reports, and other voluntarily provided information, and how the Agency can most effectively support private sector cybersecurity;

8(5) facilitate the timely sharing, on a voluntary basis, between relevant critical infrastructure owners and operators of information relating to covered cyber incidents and ransom payments, particularly with respect to ongoing cyber threats or security vulnerabilities and identify and disseminate ways to prevent or mitigate similar cyber incidents in the future;

9(6) for a covered cyber incident, including a ransomware attack, that also satisfies the definition of a significant cyber incident, or is part of a group of related cyber incidents that together satisfy such definition, conduct a review of the details surrounding the covered cyber incident or group of those incidents and identify and disseminate ways to prevent or mitigate similar incidents in the future;

10(7) with respect to covered cyber incident reports under section 1 681b(a) and 681c of this title involving an ongoing cyber threat or security vulnerability, immediately review those reports for cyber threat indicators that can be anonymized and disseminated, with defensive measures, to appropriate stakeholders, in coordination with other divisions within the Agency, as appropriate;

11(8) publish quarterly unclassified, public reports that describe aggregated, anonymized observations, findings, and recommendations based on covered cyber incident reports, which may be based on the unclassified information contained in the briefings required under subsection (c);

12(9) proactively identify opportunities, consistent with the protections in section 681e of this title, to leverage and utilize data on cyber incidents in a manner that enables and strengthens cybersecurity research carried out by academic institutions and other private sector organizations, to the greatest extent practicable; and

13(10) in accordance with section 681e of this title and subsection (b) of this section, as soon as possible but not later than 24 hours after receiving a covered cyber incident report, ransom payment report, voluntarily submitted information pursuant to section 681c of this title, or information received pursuant to a request for information or subpoena under section 681d of this title, make available the information to appropriate Sector Risk Management Agencies and other appropriate Federal agencies.

14The President or a designee of the President—

15(1) may establish a specific time requirement for sharing information under subsection (a)(10); and

16(2) shall determine the appropriate Federal agencies under subsection (a)(10).

17Not later than 60 days after the effective date of the final rule required under section 681b(b) of this title, and on the first day of each month thereafter, the Director, in consultation with the National Cyber Director, the Attorney General, and the Director of National Intelligence, shall provide to the majority leader of the Senate, the minority leader of the Senate, the Speaker of the House of Representatives, the minority leader of the House of Representatives, the Committee on Homeland Security and Governmental Affairs of the Senate, and the Committee on Homeland Security of the House of Representatives a briefing that characterizes the national cyber threat landscape, including the threat facing Federal agencies and covered entities, and applicable intelligence and law enforcement information, covered cyber incidents, and ransomware attacks, as of the date of the briefing, which shall—

18(1) include the total number of reports submitted under sections 681b and 681c of this title during the preceding month, including a breakdown of required and voluntary reports;

19(2) include any identified trends in covered cyber incidents and ransomware attacks over the course of the preceding month and as compared to previous reports, including any trends related to the information collected in the reports submitted under sections 681b and 681c of this title, including—

20(A) the infrastructure, tactics, and techniques malicious cyber actors commonly use; and

21(B) intelligence gaps that have impeded, or currently are impeding, the ability to counter covered cyber incidents and ransomware threats;

22(3) include a summary of the known uses of the information in reports submitted under sections 681b and 681c of this title; and

23(4) include an unclassified portion, but may include a classified component.

681b.

Required reporting of certain cyber incidents

1A covered entity that experiences a covered cyber incident shall report the covered cyber incident to the Agency not later than 72 hours after the covered entity reasonably believes that the covered cyber incident has occurred.

2The Director may not require reporting under subparagraph (A) any earlier than 72 hours after the covered entity reasonably believes that a covered cyber incident has occurred.

3A covered entity that makes a ransom payment as the result of a ransomware attack against the covered entity shall report the payment to the Agency not later than 24 hours after the ransom payment has been made.

4The requirements under subparagraph (A) shall apply even if the ransomware attack is not a covered cyber incident subject to the reporting requirements under paragraph (1).

5A covered entity shall promptly submit to the Agency an update or supplement to a previously submitted covered cyber incident report if substantial new or different information becomes available or if the covered entity makes a ransom payment after submitting a covered cyber incident report required under paragraph (1), until such date that such covered entity notifies the Agency that the covered cyber incident at issue has concluded and has been fully mitigated and resolved.

6Any covered entity subject to requirements of paragraph (1), (2), or (3) shall preserve data relevant to the covered cyber incident or ransom payment in accordance with procedures established in the final rule issued pursuant to subsection (b).

7If a covered entity is the victim of a covered cyber incident and makes a ransom payment prior to the 72 hour requirement under paragraph (1), such that the reporting requirements under paragraphs (1) and (2) both apply, the covered entity may submit a single report to satisfy the requirements of both paragraphs in accordance with procedures established in the final rule issued pursuant to subsection (b).

8Subject to the limitation described in clause (ii), where the Agency has an agreement in place that satisfies the requirements of section 681g(a) of this title, the requirements under paragraphs (1), (2), and (3) shall not apply to a covered entity required by law, regulation, or contract to report substantially similar information to another Federal agency within a substantially similar timeframe.

9The exemption in clause (i) shall take effect with respect to a covered entity once an agency agreement and sharing mechanism is in place between the Agency and the respective Federal agency, pursuant to section 681g(a) of this title.

10Nothing in this paragraph shall be construed to—

11(I) exempt a covered entity from the reporting requirements under paragraph (3) unless the supplemental report also meets the requirements of clauses (i) and (ii) of this paragraph; 1

12(II) prevent the Agency from contacting an entity submitting information to another Federal agency that is provided to the Agency pursuant to section 681g of this title; or

13(III) prevent an entity from communicating with the Agency.

14The requirements under paragraphs (1), (2) and (3) shall not apply to a covered entity or the functions of a covered entity that the Director determines constitute critical infrastructure owned, operated, or governed by multi-stakeholder organizations that develop, implement, and enforce policies concerning the Domain Name System, such as the Internet Corporation for Assigned Names and Numbers or the Internet Assigned Numbers Authority.

15Reports made under paragraphs (1), (2), and (3) shall be made in the manner and form, and within the time period in the case of reports made under paragraph (3), prescribed in the final rule issued pursuant to subsection (b).

16Paragraphs (1) through (4) shall take effect on the dates prescribed in the final rule issued pursuant to subsection (b).

17Not later than 24 months after March 15, 2022, the Director, in consultation with Sector Risk Management Agencies, the Department of Justice, and other Federal agencies, shall publish in the Federal Register a notice of proposed rulemaking to implement subsection (a).

18Not later than 18 months after publication of the notice of proposed rulemaking under paragraph (1), the Director shall issue a final rule to implement subsection (a).

19The Director is authorized to issue regulations to amend or revise the final rule issued pursuant to paragraph (2).

20Any subsequent rules issued under subparagraph (A) shall comply with the requirements under chapter 5 of title 5, including the issuance of a notice of proposed rulemaking under section 553 of such title.

21The final rule issued pursuant to subsection (b) shall be composed of the following elements:

22(1) A clear description of the types of entities that constitute covered entities, based on—

23(A) the consequences that disruption to or compromise of such an entity could cause to national security, economic security, or public health and safety;

24(B) the likelihood that such an entity may be targeted by a malicious cyber actor, including a foreign country; and

25(C) the extent to which damage, disruption, or unauthorized access to such an entity, including the accessing of sensitive cybersecurity vulnerability information or penetration testing tools or techniques, will likely enable the disruption of the reliable operation of critical infrastructure.

26(2) A clear description of the types of substantial cyber incidents that constitute covered cyber incidents, which shall—

27(A) at a minimum, require the occurrence of—

28(i) a cyber incident that leads to substantial loss of confidentiality, integrity, or availability of such information system or network, or a serious impact on the safety and resiliency of operational systems and processes;

29(ii) a disruption of business or industrial operations, including due to a denial of service attack, ransomware attack, or exploitation of a zero day vulnerability, against 2

30(I) an information system or network; or

31(II) an operational technology system or process; or

32(iii) unauthorized access or disruption of business or industrial operations due to loss of service facilitated through, or caused by, a compromise of a cloud service provider, managed service provider, or other third-party data hosting provider or by a supply chain compromise;

33(B) consider—

34(i) the sophistication or novelty of the tactics used to perpetrate such a cyber incident, as well as the type, volume, and sensitivity of the data at issue;

35(ii) the number of individuals directly or indirectly affected or potentially affected by such a cyber incident; and

36(iii) potential impacts on industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers; and

37(C) exclude—

38(i) any event where the cyber incident is perpetrated in good faith by an entity in response to a specific request by the owner or operator of the information system; and

39(ii) the threat of disruption as extortion, as described in section 681(14)(A) 3 of this title.

40(3) A requirement that, if a covered cyber incident or a ransom payment occurs following an exempted threat described in paragraph (2)(C)(ii), the covered entity shall comply with the requirements in this part in reporting the covered cyber incident or ransom payment.

41(4) A clear description of the specific required contents of a report pursuant to subsection (a)(1), which shall include the following information, to the extent applicable and available, with respect to a covered cyber incident:

42(A) A description of the covered cyber incident, including—

43(i) identification and a description of the function of the affected information systems, networks, or devices that were, or are reasonably believed to have been, affected by such cyber incident;

44(ii) a description of the unauthorized access with substantial loss of confidentiality, integrity, or availability of the affected information system or network or disruption of business or industrial operations;

45(iii) the estimated date range of such incident; and

46(iv) the impact to the operations of the covered entity.

47(B) Where applicable, a description of the vulnerabilities exploited and the security defenses that were in place, as well as the tactics, techniques, and procedures used to perpetrate the covered cyber incident.

48(C) Where applicable, any identifying or contact information related to each actor reasonably believed to be responsible for such cyber incident.

49(D) Where applicable, identification of the category or categories of information that were, or are reasonably believed to have been, accessed or acquired by an unauthorized person.

50(E) The name and other information that clearly identifies the covered entity impacted by the covered cyber incident, including, as applicable, the State of incorporation or formation of the covered entity, trade names, legal names, or other identifiers.

51(F) Contact information, such as telephone number or electronic mail address, that the Agency may use to contact the covered entity or an authorized agent of such covered entity, or, where applicable, the service provider of such covered entity acting with the express permission of, and at the direction of, the covered entity to assist with compliance with the requirements of this part.

52(5) A clear description of the specific required contents of a report pursuant to subsection (a)(2), which shall be the following information, to the extent applicable and available, with respect to a ransom payment:

53(A) A description of the ransomware attack, including the estimated date range of the attack.

54(B) Where applicable, a description of the vulnerabilities, tactics, techniques, and procedures used to perpetrate the ransomware attack.

55(C) Where applicable, any identifying or contact information related to the actor or actors reasonably believed to be responsible for the ransomware attack.

56(D) The name and other information that clearly identifies the covered entity that made the ransom payment or on whose behalf the payment was made.

57(E) Contact information, such as telephone number or electronic mail address, that the Agency may use to contact the covered entity that made the ransom payment or an authorized agent of such covered entity, or, where applicable, the service provider of such covered entity acting with the express permission of, and at the direction of, that covered entity to assist with compliance with the requirements of this part.

58(F) The date of the ransom payment.

59(G) The ransom payment demand, including the type of virtual currency or other commodity requested, if applicable.

60(H) The ransom payment instructions, including information regarding where to send the payment, such as the virtual currency address or physical address the funds were requested to be sent to, if applicable.

61(I) The amount of the ransom payment.

62(6) A clear description of the types of data required to be preserved pursuant to subsection (a)(4), the period of time for which the data is required to be preserved, and allowable uses, processes, and procedures.

63(7) Deadlines and criteria for submitting supplemental reports to the Agency required under subsection (a)(3), which shall—

64(A) be established by the Director in consultation with the Council;

65(B) consider any existing regulatory reporting requirements similar in scope, purpose, and timing to the reporting requirements to which such a covered entity may also be subject, and make efforts to harmonize the timing and contents of any such reports to the maximum extent practicable;

66(C) balance the need for situational awareness with the ability of the covered entity to conduct cyber incident response and investigations; and

67(D) provide a clear description of what constitutes substantial new or different information.

68(8) Procedures for—

69(A) entities, including third parties pursuant to subsection (d)(1), to submit reports required by paragraphs (1), (2), and (3) of subsection (a), including the manner and form thereof, which shall include, at a minimum, a concise, user-friendly web-based form;

70(B) the Agency to carry out—

71(i) the enforcement provisions of section 681d of this title, including with respect to the issuance, service, withdrawal, referral process, and enforcement of subpoenas, appeals and due process procedures;

72(ii) other available enforcement mechanisms including acquisition, suspension and debarment procedures; and

73(iii) other aspects of noncompliance;

74(C) implementing the exceptions provided in subsection (a)(5); and

75(D) protecting privacy and civil liberties consistent with processes adopted pursuant to section 1504(b) of this title and anonymizing and safeguarding, or no longer retaining, information received and disclosed through covered cyber incident reports and ransom payment reports that is known to be personal information of a specific individual or information that identifies a specific individual that is not directly related to a cybersecurity threat.

76(9) Other procedural measures directly necessary to implement subsection (a).

77A covered entity that is required to submit a covered cyber incident report or a ransom payment report may use a third party, such as an incident response company, insurance provider, service provider, Information Sharing and Analysis Organization, or law firm, to submit the required report under subsection (a).

78If a covered entity impacted by a ransomware attack uses a third party to make a ransom payment, the third party shall not be required to submit a ransom payment report for itself under subsection (a)(2).

79Third-party reporting under this subparagraph 4 does not relieve a covered entity from the duty to comply with the requirements for covered cyber incident report or ransom payment report submission.

80Any third party used by a covered entity that knowingly makes a ransom payment on behalf of a covered entity impacted by a ransomware attack shall advise the impacted covered entity of the responsibilities of the impacted covered entity regarding reporting ransom payments under this section.

81The Agency shall conduct an outreach and education campaign to inform likely covered entities, entities that offer or advertise as a service to customers to make or facilitate ransom payments on behalf of covered entities impacted by ransomware attacks and other appropriate entities of the requirements of paragraphs (1), (2), and (3) of subsection (a).

82The outreach and education campaign under paragraph (1) shall include the following:

83(A) An overview of the final rule issued pursuant to subsection (b).

84(B) An overview of mechanisms to submit to the Agency covered cyber incident reports, ransom payment reports, and information relating to the disclosure, retention, and use of covered cyber incident reports and ransom payment reports under this section.

85(C) An overview of the protections afforded to covered entities for complying with the requirements under paragraphs (1), (2), and (3) of subsection (a).

86(D) An overview of the steps taken under section 681d of this title when a covered entity is not in compliance with the reporting requirements under subsection (a).

87(E) Specific outreach to cybersecurity vendors, cyber incident response providers, cybersecurity insurance entities, and other entities that may support covered entities.

88(F) An overview of the privacy and civil liberties requirements in this part.

89In conducting the outreach and education campaign required under paragraph (1), the Agency may coordinate with—

90(A) the Critical Infrastructure Partnership Advisory Council established under section 451 of this title;

91(B) Information Sharing and Analysis Organizations;

92(C) trade associations;

93(D) information sharing and analysis centers;

94(E) sector coordinating councils; and

95(F) any other entity as determined appropriate by the Director.

96Sections 3506(c), 3507, 3508, and 3509 of title 44 shall not apply to any action to carry out this section.

97Nothing in this section shall affect the authorities of the Federal Government to implement the requirements of Executive Order 14028 (86 Fed. Reg. 26633; relating to improving the nation's cybersecurity), including changes to the Federal Acquisition Regulations and remedies to include suspension and debarment.

98Nothing in this section shall be construed to supersede or to abrogate, modify, or otherwise limit the authority that is vested in any officer or any agency of the United States Government to regulate or take action with respect to the cybersecurity of an entity.

681c.

Voluntary reporting of other cyber incidents

1Entities may voluntarily report cyber incidents or ransom payments to the Agency that are not required under paragraph (1), (2), or (3) of section 681b(a) of this title, but may enhance the situational awareness of cyber threats.

2Covered entities may voluntarily include in reports required under paragraph (1), (2), or (3) of section 681b(a) of this title information that is not required to be included, but may enhance the situational awareness of cyber threats.

3Section 681e of this title shall apply in the same manner and to the same extent to reports and information submitted under subsections (a) and (b) as it applies to reports and information submitted under section 681b of this title.

681d.

Noncompliance with required reporting

1In the event that a covered entity that is required to submit a report under section 681b(a) of this title fails to comply with the requirement to report, the Director may obtain information about the cyber incident or ransom payment by engaging the covered entity directly to request information about the cyber incident or ransom payment, and if the Director is unable to obtain information through such engagement, by issuing a subpoena to the covered entity, pursuant to subsection (c), to gather information sufficient to determine whether a covered cyber incident or ransom payment has occurred.

2If the Director has reason to believe, whether through public reporting or other information in the possession of the Federal Government, including through analysis performed pursuant to paragraph (1) or (2) of section 681a(a) of this title, that a covered entity has experienced a covered cyber incident or made a ransom payment but failed to report such cyber incident or payment to the Agency in accordance with section 681b(a) of this title, the Director may request additional information from the covered entity to confirm whether or not a covered cyber incident or ransom payment has occurred.

3Information provided to the Agency in response to a request under paragraph (1) shall be treated as if it was submitted through the reporting procedures established in section 681b of this title 1 including that section 681e of this title shall apply to such information in the same manner and to the same extent to information submitted in response to requests under paragraph (1) as it applies to information submitted under section 681b of this title.

4If, after the date that is 72 hours from the date on which the Director made the request for information in subsection (b), the Director has received no response from the covered entity from which such information was requested, or received an inadequate response, the Director may issue to such covered entity a subpoena to compel disclosure of information the Director deems necessary to determine whether a covered cyber incident or ransom payment has occurred and obtain the information required to be reported pursuant to section 681b of this title and any implementing regulations, and assess potential impacts to national security, economic security, or public health and safety.

5If a covered entity fails to comply with a subpoena, the Director may refer the matter to the Attorney General to bring a civil action in a district court of the United States to enforce such subpoena.

6An action under this paragraph may be brought in the judicial district in which the covered entity against which the action is brought resides, is found, or does business.

7A court may punish a failure to comply with a subpoena issued under this subsection as contempt of court.

8The authority of the Director to issue a subpoena under this subsection may not be delegated.

9Any subpoena issued electronically pursuant to this subsection shall be authenticated with a cryptographic digital signature of an authorized representative of the Agency, or other comparable successor technology, that allows the Agency to demonstrate that such subpoena was issued by the Agency and has not been altered or modified since such issuance.

10Any subpoena issued electronically pursuant to this subsection that is not authenticated in accordance with subparagraph (A) shall not be considered to be valid by the recipient of such subpoena.

11Notwithstanding section 681e(a)(5) of this title and paragraph (b)(2) of this section, if the Director determines, based on the information provided in response to a subpoena issued pursuant to subsection (c), that the facts relating to the cyber incident or ransom payment at issue may constitute grounds for a regulatory enforcement action or criminal prosecution, the Director may provide such information to the Attorney General or the head of the appropriate Federal regulatory agency, who may use such information for a regulatory enforcement action or criminal prosecution.

12The Director may consult with the Attorney General or the head of the appropriate Federal regulatory agency when making the determination under paragraph (1).

13When determining whether to exercise the authorities provided under this section, the Director shall take into consideration—

14(1) the complexity in determining if a covered cyber incident has occurred; and

15(2) prior interaction with the Agency or awareness of the covered entity of the policies and procedures of the Agency for reporting covered cyber incidents and ransom payments.

16This section shall not apply to a State, local, Tribal, or territorial government entity.

17The Director shall submit to Congress an annual report on the number of times the Director—

18(1) issued an initial request for information pursuant to subsection (b);

19(2) issued a subpoena pursuant to subsection (c); or

20(3) referred a matter to the Attorney General for a civil action pursuant to subsection (c)(2).

21The Director shall publish a version of the annual report required under subsection (g) on the website of the Agency, which shall include, at a minimum, the number of times the Director—

22(1) issued an initial request for information pursuant to subsection (b); or

23(2) issued a subpoena pursuant to subsection (c).

24The Director shall ensure any victim information contained in a report required to be published under subsection (h) be anonymized before the report is published.

681e.

Information shared with or provided to the Federal Government

1Information provided to the Agency pursuant to section 681b or 681c of this title may be disclosed to, retained by, and used by, consistent with otherwise applicable provisions of Federal law, any Federal agency or department, component, officer, employee, or agent of the Federal Government solely for—

2(A) a cybersecurity purpose;

3(B) the purpose of identifying—

4(i) a cyber threat, including the source of the cyber threat; or

5(ii) a security vulnerability;

6(C) the purpose of responding to, or otherwise preventing or mitigating, a specific threat of death, a specific threat of serious bodily harm, or a specific threat of serious economic harm, including a terrorist act or use of a weapon of mass destruction;

7(D) the purpose of responding to, investigating, prosecuting, or otherwise preventing or mitigating, a serious threat to a minor, including sexual exploitation and threats to physical safety; or

8(E) the purpose of preventing, investigating, disrupting, or prosecuting an offense arising out of a cyber incident reported pursuant to section 681b or 681c of this title or any of the offenses listed in section 1504(d)(5)(A)(v) of this title.

9Upon receiving a covered cyber incident or ransom payment report submitted pursuant to this section, the Agency shall immediately review the report to determine whether the cyber incident that is the subject of the report is connected to an ongoing cyber threat or security vulnerability and where applicable, use such report to identify, develop, and rapidly disseminate to appropriate stakeholders actionable, anonymized cyber threat indicators and defensive measures.

10With respect to information in a covered cyber incident or ransom payment report regarding a security vulnerability referred to in paragraph (1)(B)(ii), the Director shall develop principles that govern the timing and manner in which information relating to security vulnerabilities may be shared, consistent with common industry best practices and United States and international standards.

11Information contained in covered cyber incident and ransom payment reports submitted to the Agency pursuant to section 681b of this title shall be retained, used, and disseminated, where permissible and appropriate, by the Federal Government in accordance with processes to be developed for the protection of personal information consistent with processes adopted pursuant to section 1504 of this title and in a manner that protects personal information from unauthorized use or unauthorized disclosure.

12The Agency shall ensure that reports submitted to the Agency pursuant to section 681b of this title, and any information contained in those reports, are collected, stored, and protected at a minimum in accordance with the requirements for moderate impact Federal information systems, as described in Federal Information Processing Standards Publication 199, or any successor document.

13A Federal, State, local, or Tribal government shall not use information about a covered cyber incident or ransom payment obtained solely through reporting directly to the Agency in accordance with this part to regulate, including through an enforcement action, the activities of the covered entity or entity that made a ransom payment, unless the government entity expressly allows entities to submit reports to the Agency to meet regulatory reporting obligations of the entity.

14A report submitted to the Agency pursuant to section 681b or 681c of this title may, consistent with Federal or State regulatory authority specifically relating to the prevention and mitigation of cybersecurity threats to information systems, inform the development or implementation of regulations relating to such systems.

15Reports describing covered cyber incidents or ransom payments submitted to the Agency by entities in accordance with section 681b of this title, as well as voluntarily-submitted cyber incident reports submitted to the Agency pursuant to section 681c of this title, shall—

16(1) be considered the commercial, financial, and proprietary information of the covered entity when so designated by the covered entity;

17(2) be exempt from disclosure under section 552(b)(3) of title 5 (commonly known as the "Freedom of Information Act"), as well as any provision of State, Tribal, or local freedom of information law, open government law, open meetings law, open records law, sunshine law, or similar law requiring disclosure of information or records;

18(3) be considered not to constitute a waiver of any applicable privilege or protection provided by law, including trade secret protection; and

19(4) not be subject to a rule of any Federal agency or department or any judicial doctrine regarding ex parte communications with a decision-making official.

20No cause of action shall lie or be maintained in any court by any person or entity and any such action shall be promptly dismissed for the submission of a report pursuant to section 681b(a) of this title that is submitted in conformance with this part and the rule promulgated under section 681b(b) of this title, except that this subsection shall not apply with regard to an action by the Federal Government pursuant to section 681d(c)(2) of this title.

21The liability protections provided in this subsection shall only apply to or affect litigation that is solely based on the submission of a covered cyber incident report or ransom payment report to the Agency.

22Notwithstanding paragraph (2), no report submitted to the Agency pursuant to this part or any communication, document, material, or other record, created for the sole purpose of preparing, drafting, or submitting such report, may be received in evidence, subject to discovery, or otherwise used in any trial, hearing, or other proceeding in or before any court, regulatory body, or other authority of the United States, a State, or a political subdivision thereof, provided that nothing in this part shall create a defense to discovery or otherwise affect the discovery of any communication, document, material, or other record not created for the sole purpose of preparing, drafting, or submitting such report.

23The Agency shall anonymize the victim who reported the information when making information provided in reports received under section 681b of this title available to critical infrastructure owners and operators and the general public.

24Nothing in this part shall be construed to permit or require disclosure by a provider of a remote computing service or a provider of an electronic communication service to the public of information not otherwise permitted or required to be disclosed under chapter 121 of title 18 (commonly known as the "Stored Communications Act").

681f.

Cyber Incident Reporting Council

1The Secretary shall lead an intergovernmental Cyber Incident Reporting Council, in consultation with the Director of the Office of Management and Budget, the Attorney General, the National Cyber Director, Sector Risk Management Agencies, and other appropriate Federal agencies, to coordinate, deconflict, and harmonize Federal incident reporting requirements, including those issued through regulations.

2Nothing in subsection (a) shall be construed to provide any additional regulatory authority to any Federal entity.

681g.

Federal sharing of incident reports

1Notwithstanding any other provision of law or regulation, any Federal agency, including any independent establishment (as defined in section 104 of title 5), that receives a report from an entity of a cyber incident, including a ransomware attack, shall provide the report to the Agency as soon as possible, but not later than 24 hours after receiving the report, unless a shorter period is required by an agreement made between the Department of Homeland Security (including the Cybersecurity and Infrastructure Security Agency) and the recipient Federal agency. The Director shall share and coordinate each report pursuant to section 681a(b) of this title, as added by section 103 of this division.

2The requirements described in paragraph (1) and section 681e(d) of this title, as added by section 103 of this division, may not be construed to be a violation of any provision of law or policy that would otherwise prohibit disclosure or provision of information within the executive branch.

3The Director shall comply with any obligations of the recipient Federal agency described in paragraph (1) to protect information, including with respect to privacy, confidentiality, or information security, if those obligations would impose greater protection requirements than this division or the amendments made by this division.

4This subsection shall take effect on the effective date of the final rule issued pursuant to section 681b(b) of this title, as added by section 103 of this division.

5The Agency and any Federal agency, including any independent establishment (as defined in section 104 of title 5), that receives incident reports from entities, including due to ransomware attacks, shall, as appropriate, enter into a documented agreement to establish policies, processes, procedures, and mechanisms to ensure reports are shared with the Agency pursuant to paragraph (1).

6To the maximum extent practicable, each documented agreement required under subparagraph (A) shall be made publicly available.

7The documented agreements required by subparagraph (A) shall require reports be shared from Federal agencies with the Agency in such time as to meet the overall timeline for covered entity reporting of covered cyber incidents and ransom payments established in section 681b of this title, as added by section 103 of this division.

8The Secretary of Homeland Security, acting through the Director, shall, in consultation with the Cyber Incident Reporting Council described in section 681f of this title, as added by section 103 of this division, to the maximum extent practicable—

9(1) periodically review existing regulatory requirements, including the information required in such reports, to report incidents and ensure that any such reporting requirements and procedures avoid conflicting, duplicative, or burdensome requirements; and

10(2) coordinate with appropriate Federal partners and regulatory authorities that receive reports relating to incidents to identify opportunities to streamline reporting processes, and where feasible, facilitate interagency agreements between such authorities to permit the sharing of such reports, consistent with applicable law and policy, without impacting the ability of the Agency to gain timely situational awareness of a covered cyber incident or ransom payment.

CHAPTER 2—NATIONAL EMERGENCY MANAGEMENT

701.

Definitions

1In this title— 1

2(1) the term "Administrator" means the Administrator of the Agency;

3(2) the term "Agency" means the Federal Emergency Management Agency;

4(3) the term "appropriate committees of Congress" means—

5(A) the Committee on Homeland Security and Governmental Affairs of the Senate; and

6(B) those committees of the House of Representatives that the Speaker of the House of Representatives determines appropriate;

7(4) the term "catastrophic incident" means any natural disaster, act of terrorism, or other man-made disaster that results in extraordinary levels of casualties or damage or disruption severely affecting the population (including mass evacuations), infrastructure, environment, economy, national morale, or government functions in an area;

8(5) the term "Department" means the Department of Homeland Security;

9(6) the terms "emergency" and "major disaster" have the meanings given the terms in section 5122 of title 42;

10(7) the term "emergency management" means the governmental function that coordinates and integrates all activities necessary to build, sustain, and improve the capability to prepare for, protect against, respond to, recover from, or mitigate against threatened or actual natural disasters, acts of terrorism, or other man-made disasters;

11(8) the term "emergency response provider" has the meaning given the term in section 101 of this title;

12(9) the term "Federal coordinating officer" means a Federal coordinating officer as described in section 5143 of title 42;

13(10) the term "individual with a disability" has the meaning given the term in section 12102 of title 42;

14(11) the terms "local government" and "State" have the meaning given the terms in section 101 of this title;

15(12) the term "National Incident Management System" means a system to enable effective, efficient, and collaborative incident management;

16(13) the term "National Response Plan" means the National Response Plan or any successor plan prepared under section 314(a)(6) of this title;

17(14) the term "Secretary" means the Secretary of Homeland Security;

18(15) the term "surge capacity" means the ability to rapidly and substantially increase the provision of search and rescue capabilities, food, water, medicine, shelter and housing, medical care, evacuation capacity, staffing (including disaster assistance employees), and other resources necessary to save lives and protect property during a catastrophic incident; and

19(16) the term "tribal government" means the government of an Indian tribe or authorized tribal organization, or in Alaska a Native village or Alaska Regional Native Corporation.

711.

Surge Capacity Force

1Not later than 6 months after October 4, 2006, the Administrator shall prepare and submit to the appropriate committees of Congress a plan to establish and implement a Surge Capacity Force for deployment of individuals to respond to natural disasters, acts of terrorism, and other man-made disasters, including catastrophic incidents.

2Except as provided in subparagraph (B), the plan shall provide for individuals in the Surge Capacity Force to be trained and deployed under the authorities set forth in the Robert T. Stafford Disaster Relief and Emergency Assistance Act [42 U.S.C. 5121 et seq.].

3If the Administrator determines that the existing authorities are inadequate for the training and deployment of individuals in the Surge Capacity Force, the Administrator shall report to Congress as to the additional statutory authorities that the Administrator determines necessary.

4The plan shall include procedures under which the Secretary shall designate employees of the Department who are not employees of the Agency and shall, in conjunction with the heads of other Executive agencies, designate employees of those other Executive agencies, as appropriate, to serve on the Surge Capacity Force.

5The plan shall ensure that the Surge Capacity Force—

6(1) includes a sufficient number of individuals credentialed in accordance with section 320 of this title that are capable of deploying rapidly and efficiently after activation to prepare for, respond to, and recover from natural disasters, acts of terrorism, and other man-made disasters, including catastrophic incidents; and

7(2) includes a sufficient number of full-time, highly trained individuals credentialed in accordance with section 320 of this title to lead and manage the Surge Capacity Force.

8The plan shall ensure that the Administrator provides appropriate and continuous training to members of the Surge Capacity Force to ensure such personnel are adequately trained on the Agency's programs and policies for natural disasters, acts of terrorism, and other man-made disasters.

9Surge Capacity Force members shall not be counted against any personnel ceiling applicable to the Federal Emergency Management Agency.

10The Administrator may provide members of the Surge Capacity Force with travel expenses, including per diem in lieu of subsistence, at rates authorized for employees of agencies under subchapter I of chapter 57 of title 5 for the purpose of participating in any training that relates to service as a member of the Surge Capacity Force.

11As soon as practicable after October 4, 2006, the Administrator shall develop and implement—

12(1) the procedures under subsection (b); and

13(2) other elements of the plan needed to establish the portion of the Surge Capacity Force consisting of individuals designated under those procedures.

721.

Evacuation preparedness technical assistance

1The Administrator, in coordination with the heads of other appropriate Federal agencies, shall provide evacuation preparedness technical assistance to State, local, and tribal governments, including the preparation of hurricane evacuation studies and technical assistance in developing evacuation plans, assessing storm surge estimates, evacuation zones, evacuation clearance times, transportation capacity, and shelter capacity.

722.

Urban Search and Rescue Response System

1There is in the Agency a system known as the Urban Search and Rescue Response System.

2There is authorized to be appropriated to carry out the system for fiscal year 2008, an amount equal to the amount appropriated for the system for fiscal year 2007 and an additional $20,000,000.

723.

Metropolitan Medical Response Grant Program

1There is a Metropolitan Medical Response Program.

2The program shall include each purpose of the program as it existed on June 1, 2006.

3There is authorized to be appropriated to carry out the program for fiscal year 2008, an amount equal to the amount appropriated for the program for fiscal year 2007 and an additional $30,000,000.

724.

Logistics

1The Administrator shall develop an efficient, transparent, and flexible logistics system for procurement and delivery of goods and services necessary for an effective and timely response to natural disasters, acts of terrorism, and other man-made disasters and for real-time visibility of items at each point throughout the logistics system.

725.

Prepositioned equipment program

1The Administrator shall establish a prepositioned equipment program to preposition standardized emergency equipment in at least 11 locations to sustain and replenish critical assets used by State, local, and tribal governments in response to (or rendered inoperable by the effects of) natural disasters, acts of terrorism, and other man-made disasters.

2The Administrator shall notify State, local, and tribal officials in an area in which a location for the prepositioned equipment program will be closed not later than 60 days before the date of such closure.

726.

Basic life supporting first aid and education

1The Administrator shall enter into agreements with organizations to provide funds to emergency response providers to provide education and training in life supporting first aid to children.

727.

Improvements to information technology systems

1The Administrator, in coordination with the Chief Information Officer of the Department, shall take appropriate measures to update and improve the information technology systems of the Agency, including measures to—

2(1) ensure that the multiple information technology systems of the Agency (including the National Emergency Management Information System, the Logistics Information Management System III, and the Automated Deployment Database) are, to the extent practicable, fully compatible and can share and access information, as appropriate, from each other;

3(2) ensure technology enhancements reach the headquarters and regional offices of the Agency in a timely fashion, to allow seamless integration;

4(3) develop and maintain a testing environment that ensures that all system components are properly and thoroughly tested before their release;

5(4) ensure that the information technology systems of the Agency have the capacity to track disaster response personnel, mission assignments task orders, commodities, and supplies used in response to a natural disaster, act of terrorism, or other man-made disaster;

6(5) make appropriate improvements to the National Emergency Management Information System to address shortcomings in such system on October 4, 2006; and

7(6) provide training, manuals, and guidance on information technology systems to personnel, including disaster response personnel, to help ensure employees can properly use information technology systems.

8Not later than 270 days after October 4, 2006, the Administrator shall submit to the appropriate committees of Congress a report describing the implementation of this section, including a description of any actions taken, improvements made, and remaining problems and a description of any additional funding needed to make necessary and appropriate improvements to the information technology systems of the Agency.

728.

Disclosure of certain information to law enforcement agencies

1In the event of circumstances requiring an evacuation, sheltering, or mass relocation, the Administrator may disclose information in any individual assistance database of the Agency in accordance with section 552a(b) of title 5 (commonly referred to as the "Privacy Act") to any law enforcement agency of the Federal Government or a State, local, or tribal government in order to identify illegal conduct or address public safety or security issues, including compliance with sex offender notification laws.

741.

Definitions

1In this part:

2The term "capability" means the ability to provide the means to accomplish one or more tasks under specific conditions and to specific performance standards. A capability may be achieved with any combination of properly planned, organized, equipped, trained, and exercised personnel that achieves the intended outcome.

3The terms "credentialed" and "credentialing" have the meanings given those terms in section 311 of this title.

4The term "hazard" has the meaning given that term under section 5195a(a)(1) of title 42.

5The term "mission assignment" means a work order issued to a Federal agency by the Agency, directing completion by that agency of a specified task and setting forth funding, other managerial controls, and guidance.

6The term "national preparedness goal" means the national preparedness goal established under section 743 of this title.

7The term "national preparedness system" means the national preparedness system established under section 744 of this title.

8The term "national training program" means the national training program established under section 748(a) of this title.

9The term "operational readiness" means the capability of an organization, an asset, a system, or equipment to perform the missions or functions for which it is organized or designed.

10The term "performance measure" means a quantitative or qualitative characteristic used to gauge the results of an outcome compared to its intended purpose.

11The term "performance metric" means a particular value or characteristic used to measure the outcome that is generally expressed in terms of a baseline and a target.

12The term "prevention" means any activity undertaken to avoid, prevent, or stop a threatened or actual act of terrorism.

13The term "resources" has the meaning given that term in section 311 of this title.

14The term "type" means a classification of resources that refers to the capability of a resource.

15The terms "typed" and "typing" have the meanings given those terms in section 311 of this title.

742.

National preparedness

1In order to prepare the Nation for all hazards, including natural disasters, acts of terrorism, and other man-made disasters, the President, consistent with the declaration of policy under section 5195 of title 42 and title V of the Homeland Security Act of 2002 (6 U.S.C. 311 et seq.), as amended by this Act, shall develop a national preparedness goal and a national preparedness system.

743.

National preparedness goal

1The President, acting through the Administrator, shall complete, revise, and update, as necessary, a national preparedness goal that defines the target level of preparedness to ensure the Nation's ability to prevent, respond to, recover from, and mitigate against natural disasters, acts of terrorism, and other man-made disasters.

2The national preparedness goal, to the greatest extent practicable, shall be consistent with the National Incident Management System and the National Response Plan.

744.

Establishment of national preparedness system

1The President, acting through the Administrator, shall develop a national preparedness system to enable the Nation to meet the national preparedness goal.

2The national preparedness system shall include the following components:

3(1) Target capabilities and preparedness priorities.

4(2) Equipment and training standards.

5(3) Training and exercises.

6(4) Comprehensive assessment system.

7(5) Remedial action management program.

8(6) Federal response capability inventory.

9(7) Reporting requirements.

10(8) Federal preparedness.

11The national preparedness system may include national planning scenarios.

745.

National planning scenarios

1The Administrator, in coordination with the heads of appropriate Federal agencies and the National Advisory Council, may develop planning scenarios to reflect the relative risk requirements presented by all hazards, including natural disasters, acts of terrorism, and other man-made disasters, in order to provide the foundation for the flexible and adaptive development of target capabilities and the identification of target capability levels to meet the national preparedness goal.

2In developing, revising, and replacing national planning scenarios, the Administrator shall ensure that the scenarios—

3(1) reflect the relative risk of all hazards and illustrate the potential scope, magnitude, and complexity of a broad range of representative hazards; and

4(2) provide the minimum number of representative scenarios necessary to identify and define the tasks and target capabilities required to respond to all hazards.

746.

Target capabilities and preparedness priorities

1Not later than 180 days after October 4, 2006, the Administrator, in coordination with the heads of appropriate Federal agencies, the National Council on Disability, and the National Advisory Council, shall complete, revise, and update, as necessary, guidelines to define risk-based target capabilities for Federal, State, local, and tribal government preparedness that will enable the Nation to prevent, respond to, recover from, and mitigate against all hazards, including natural disasters, acts of terrorism, and other man-made disasters.

2The Administrator shall ensure that the guidelines are provided promptly to the appropriate committees of Congress and the States.

3The Administrator shall ensure that the guidelines are specific, flexible, and measurable.

4With respect to analyzing and assessing the risk of acts of terrorism, the Administrator shall consider—

5(1) the variables of threat, vulnerability, and consequences related to population (including transient commuting and tourist populations), areas of high population density, critical infrastructure, coastline, and international borders; and

6(2) the most current risk assessment available from the Chief Intelligence Officer of the Department of the threats of terrorism against the United States.

7In establishing the guidelines under subsection (a), the Administrator shall establish preparedness priorities that appropriately balance the risk of all hazards, including natural disasters, acts of terrorism, and other man-made disasters, with the resources required to prevent, respond to, recover from, and mitigate against the hazards.

8The Administrator may provide support for the development of mutual aid agreements within States.

747.

Equipment and training standards

1The Administrator, in coordination with the heads of appropriate Federal agencies and the National Advisory Council, shall support the development, promulgation, and updating, as necessary, of national voluntary consensus standards for the performance, use, and validation of equipment used by Federal, State, local, and tribal governments and nongovernmental emergency response providers.

2The national voluntary consensus standards shall—

3(A) be designed to achieve equipment and other capabilities consistent with the national preparedness goal, including the safety and health of emergency response providers;

4(B) to the maximum extent practicable, be consistent with existing national voluntary consensus standards;

5(C) take into account, as appropriate, threats that may not have been contemplated when the existing standards were developed; and

6(D) focus on maximizing operability, interoperability, interchangeability, durability, flexibility, efficiency, efficacy, portability, sustainability, and safety.

7The Administrator shall—

8(1) support the development, promulgation, and regular updating, as necessary, of national voluntary consensus standards for training; and

9(2) ensure that the training provided under the national training program is consistent with the standards.

10In carrying out this section, the Administrator shall consult with representatives of relevant public and private sector national voluntary consensus standards development organizations.

748.

Training and exercises

1Beginning not later than 180 days after October 4, 2006, the Administrator, in coordination with the heads of appropriate Federal agencies, the National Council on Disability, and the National Advisory Council, shall carry out a national training program to implement the national preparedness goal, National Incident Management System, National Response Plan, and other related plans and strategies.

2In developing and implementing the national training program, the Administrator shall—

3(A) work with government training facilities, academic institutions, private organizations, and other entities that provide specialized, state-of-the-art training for emergency managers or emergency response providers; and

4(B) utilize, as appropriate, training courses provided by community colleges, State and local public safety academies, State and private universities, and other facilities.

5Beginning not later than 180 days after October 4, 2006, the Administrator, in coordination with the heads of appropriate Federal agencies, the National Council on Disability, and the National Advisory Council, shall carry out a national exercise program to test and evaluate the national preparedness goal, National Incident Management System, National Response Plan, and other related plans and strategies.

6The national exercise program—

7(A) shall be—

8(i) as realistic as practicable, based on current risk assessments, including credible and emerging threats, vulnerabilities, and consequences, and designed to stress the national preparedness system;

9(ii) designed, as practicable, to simulate the partial or complete incapacitation of a State, local, or tribal government;

10(iii) carried out, as appropriate, with a minimum degree of notice to involved parties regarding the timing and details of such exercises, consistent with safety considerations;

11(iv) designed to provide for the systematic evaluation of readiness and enhance operational understanding of the incident command system and relevant mutual aid agreements;

12(v) designed to address the unique requirements of populations with special needs, including the elderly; and

13(vi) designed to promptly develop after-action reports and plans for quickly incorporating lessons learned into future operations; and

14(B) shall include a selection of model exercises that State, local, and tribal governments can readily adapt for use and provide assistance to State, local, and tribal governments with the design, implementation, and evaluation of exercises (whether a model exercise program or an exercise designed locally) that—

15(i) conform to the requirements under subparagraph (A);

16(ii) are consistent with any applicable State, local, or tribal strategy or plan; and

17(iii) provide for systematic evaluation of readiness.

18The Administrator shall periodically, but not less than biennially, perform national exercises for the following purposes:

19(A) To test and evaluate the capability of Federal, State, local, and tribal governments to detect, disrupt, and prevent threatened or actual catastrophic acts of terrorism, especially those involving weapons of mass destruction.

20(B) To test and evaluate the readiness of Federal, State, local, and tribal governments to respond and recover in a coordinated and unified manner to catastrophic incidents.

748a.

Prioritization of facilities

1Not later than 180 days after October 5, 2018, the Administrator shall provide guidance and training on an annual basis to State, local, and Indian tribal governments, first responders, and utility companies on—

2(1) the need to prioritize assistance to hospitals, nursing homes, and other long-term care facilities to ensure that such health care facilities remain functioning or return to functioning as soon as practicable during power outages caused by natural hazards, including severe weather events;

3(2) how hospitals, nursing homes and other long-term care facilities should adequately prepare for power outages during a major disaster or emergency, as those terms are defined in section 5122 of title 42; and

4(3) how State, local, and Indian tribal governments, first responders, utility companies, hospitals, nursing homes, and other long-term care facilities should develop a strategy to coordinate emergency response plans, including the activation of emergency response plans, in anticipation of a major disaster, including severe weather events.

749.

Comprehensive assessment system

1The Administrator, in coordination with the National Council on Disability and the National Advisory Council, shall establish a comprehensive system to assess, on an ongoing basis, the Nation's prevention capabilities and overall preparedness, including operational readiness.

2The Administrator shall ensure that each component of the national preparedness system, National Incident Management System, National Response Plan, and other related plans and strategies, and the reports required under section 752 of this title is developed, revised, and updated with clear and quantifiable performance metrics, measures, and outcomes.

3The assessment system established under subsection (a) shall assess—

4(1) compliance with the national preparedness system, National Incident Management System, National Response Plan, and other related plans and strategies;

5(2) capability levels at the time of assessment against target capability levels defined pursuant to the guidelines established under section 746(a) of this title;

6(3) resource needs to meet the desired target capability levels defined pursuant to the guidelines established under section 746(a) of this title; and

7(4) performance of training, exercises, and operations.

750.

Remedial action management program

1The Administrator, in coordination with the National Council on Disability and the National Advisory Council, shall establish a remedial action management program to—

2(1) analyze training, exercises, and real-world events to identify and disseminate lessons learned and best practices;

3(2) generate and disseminate, as appropriate, after action reports to participants in exercises and real-world events; and

4(3) conduct remedial action tracking and long-term trend analysis.

751.

Federal response capability inventory

1In accordance with section 5196(h)(1)(C) of title 42, the Administrator shall accelerate the completion of the inventory of Federal response capabilities.

2For each Federal agency with responsibilities under the National Response Plan, the inventory shall include—

3(1) for each capability—

4(A) the performance parameters of the capability;

5(B) the timeframe within which the capability can be brought to bear on an incident; and

6(C) the readiness of the capability to respond to all hazards, including natural disasters, acts of terrorism, and other man-made disasters;

7(2) a list of personnel credentialed in accordance with section 320 of this title;

8(3) a list of resources typed in accordance with section 320 of this title; and

9(4) emergency communications assets maintained by the Federal Government and, if appropriate, State, local, and tribal governments and the private sector.

10The Administrator, in coordination with the Secretary of Defense, shall develop a list of organizations and functions within the Department of Defense that may be used, pursuant to the authority provided under the National Response Plan and sections 5170a, 5170b, and 5192 of title 42, to provide support to civil authorities during natural disasters, acts of terrorism, and other man-made disasters.

11The Administrator shall establish an inventory database to allow—

12(1) real-time exchange of information regarding—

13(A) capabilities;

14(B) readiness;

15(C) the compatibility of equipment;

16(D) credentialed personnel; and

17(E) typed resources;

18(2) easy identification and rapid deployment of capabilities, credentialed personnel, and typed resources during an incident; and

19(3) the sharing of the inventory described in subsection (a) with other Federal agencies, as appropriate.

752.

Reporting requirements

1Not later than 12 months after October 4, 2006, and annually thereafter, the Administrator, in coordination with the heads of appropriate Federal agencies, shall submit to the appropriate committees of Congress a report on the Nation's level of preparedness for all hazards, including natural disasters, acts of terrorism, and other man-made disasters.

2Each report shall include—

3(A) an assessment of how Federal assistance supports the national preparedness system;

4(B) the results of the comprehensive assessment carried out under section 749 of this title;

5(C) a review of the inventory described in section 751 of this title, including the number and type of credentialed personnel in each category of personnel trained and ready to respond to a natural disaster, act of terrorism, or other man-made disaster;

6(D) an assessment of resource needs to meet preparedness priorities established under section 746(e) of this title, including—

7(i) an estimate of the amount of Federal, State, local, and tribal expenditures required to attain the preparedness priorities; and

8(ii) the extent to which the use of Federal assistance during the preceding fiscal year achieved the preparedness priorities;

9(E) an evaluation of the extent to which grants administered by the Department, including grants under title XX of the Homeland Security Act of 2002 [6 U.S.C. 601 et seq.]—

10(i) have contributed to the progress of State, local, and tribal governments in achieving target capabilities; and

11(ii) have led to the reduction of risk from natural disasters, acts of terrorism, or other man-made disasters nationally and in State, local, and tribal jurisdictions; and

12(F) a discussion of whether the list of credentialed personnel of the Agency described in section 751(b)(2) of this title—

13(i) complies with the strategic human capital plan developed under section 10102 of title 5; and

14(ii) is sufficient to respond to a natural disaster, act of terrorism, or other man-made disaster, including a catastrophic incident.

15The Administrator shall develop and submit to the appropriate committees of Congress annually an estimate of the resources of the Agency and other Federal agencies needed for and devoted specifically to developing the capabilities of Federal, State, local, and tribal governments necessary to respond to a catastrophic incident.

16Each estimate under paragraph (1) shall include the resources both necessary for and devoted to—

17(A) planning;

18(B) training and exercises;

19(C) Regional Office enhancements;

20(D) staffing, including for surge capacity during a catastrophic incident;

21(E) additional logistics capabilities;

22(F) other responsibilities under the catastrophic incident annex and the catastrophic incident supplement of the National Response Plan;

23(G) State, local, and tribal government catastrophic incident preparedness; and

24(H) covering increases in the fixed costs or expenses of the Agency, including rent or property acquisition costs or expenses, taxes, contributions to the working capital fund of the Department, and security costs for the year after the year in which such estimate is submitted.

25Not later than 15 months after October 4, 2006, and annually thereafter, a State receiving Federal preparedness assistance administered by the Department shall submit a report to the Administrator on the State's level of preparedness.

26Each report shall include—

27(A) an assessment of State compliance with the national preparedness system, National Incident Management System, National Response Plan, and other related plans and strategies;

28(B) an assessment of current capability levels and a description of target capability levels; and

29(C) a discussion of the extent to which target capabilities identified in the applicable State homeland security plan and other applicable plans remain unmet and an assessment of resources needed to meet the preparedness priorities established under section 746(e) of this title, including—

30(i) an estimate of the amount of expenditures required to attain the preparedness priorities; and

31(ii) the extent to which the use of Federal assistance during the preceding fiscal year achieved the preparedness priorities.

753.

Federal preparedness

1In support of the national preparedness system, the President shall ensure that each Federal agency with responsibilities under the National Response Plan—

2(1) has the operational capability to meet the national preparedness goal, including—

3(A) the personnel to make and communicate decisions;

4(B) organizational structures that are assigned, trained, and exercised for the missions of the agency;

5(C) sufficient physical resources; and

6(D) the command, control, and communication channels to make, monitor, and communicate decisions;

7(2) complies with the National Incident Management System, including credentialing of personnel and typing of resources likely needed to respond to a natural disaster, act of terrorism, or other man-made disaster in accordance with section 320 of this title;

8(3) develops, trains, and exercises rosters of response personnel to be deployed when the agency is called upon to support a Federal response;

9(4) develops deliberate operational plans and the corresponding capabilities, including crisis planning, to respond effectively to natural disasters, acts of terrorism, and other man-made disasters in support of the National Response Plan to ensure a coordinated Federal response; and

10(5) regularly updates, verifies the accuracy of, and provides to the Administrator the information in the inventory required under section 751 of this title.

11An operations plan developed under subsection (a)(4) shall meet the following requirements:

12(1) The operations plan shall be coordinated under a unified system with a common terminology, approach, and framework.

13(2) The operations plan shall be developed, in coordination with State, local, and tribal government officials, to address both regional and national risks.

14(3) The operations plan shall contain, as appropriate, the following elements:

15(A) Concepts of operations.

16(B) Critical tasks and responsibilities.

17(C) Detailed resource and personnel requirements, together with sourcing requirements.

18(D) Specific provisions for the rapid integration of the resources and personnel of the agency into the overall response.

19(4) The operations plan shall address, as appropriate, the following matters:

20(A) Support of State, local, and tribal governments in conducting mass evacuations, including—

21(i) transportation and relocation;

22(ii) short- and long-term sheltering and accommodation;

23(iii) provisions for populations with special needs, keeping families together, and expeditious location of missing children; and

24(iv) policies and provisions for pets.

25(B) The preparedness and deployment of public health and medical resources, including resources to address the needs of evacuees and populations with special needs.

26(C) The coordination of interagency search and rescue operations, including land, water, and airborne search and rescue operations.

27(D) The roles and responsibilities of the Senior Federal Law Enforcement Official with respect to other law enforcement entities.

28(E) The protection of critical infrastructure.

29(F) The coordination of maritime salvage efforts among relevant agencies.

30(G) The coordination of Department of Defense and National Guard support of civilian authorities.

31(H) To the extent practicable, the utilization of Department of Defense, National Air and Space Administration, National Oceanic and Atmospheric Administration, and commercial aircraft and satellite remotely sensed imagery.

32(I) The coordination and integration of support from the private sector and nongovernmental organizations.

33(J) The safe disposal of debris, including hazardous materials, and, when practicable, the recycling of debris.

34(K) The identification of the required surge capacity.

35(L) Specific provisions for the recovery of affected geographic areas.

36To expedite the provision of assistance under the National Response Plan, the President shall ensure that the Administrator, in coordination with Federal agencies with responsibilities under the National Response Plan, develops prescripted mission assignments, including logistics, communications, mass care, health services, and public safety.

37The President shall certify to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Transportation and Infrastructure of the House of Representatives on an annual basis that each Federal agency with responsibilities under the National Response Plan complies with subsections (a) and (b).

38Nothing in this section shall be construed to limit the authority of the Secretary of Defense with regard to—

39(1) the command, control, training, planning, equipment, exercises, or employment of Department of Defense forces; or

40(2) the allocation of Department of Defense resources.

754.

Use of existing resources

1In establishing the national preparedness goal and national preparedness system, the Administrator shall use existing preparedness documents, planning tools, and guidelines to the extent practicable and consistent with this Act.

761.

Emergency Management Assistance Compact grants

1The Administrator may make grants to administer the Emergency Management Assistance Compact consented to by the Joint Resolution entitled "Joint Resolution granting the consent of Congress to the Emergency Management Assistance Compact" (Public Law 104–321; 110 Stat. 3877).

2A grant under this section shall be used—

3(1) to carry out recommendations identified in the Emergency Management Assistance Compact after-action reports for the 2004 and 2005 hurricane season;

4(2) to administer compact operations on behalf of all member States and territories;

5(3) to continue coordination with the Agency and appropriate Federal agencies;

6(4) to continue coordination with State, local, and tribal government entities and their respective national organizations; and

7(5) to assist State and local governments, emergency response providers, and organizations representing such providers with credentialing emergency response providers and the typing of emergency response resources.

8The Administrator shall consult with the Administrator of the Emergency Management Assistance Compact to ensure effective coordination of efforts in responding to requests for assistance.

9There is authorized to be appropriated to carry out this section $4,000,000 for each of fiscal years 2018 through 2022. Such sums shall remain available until expended.

762.

Emergency management performance grants program

1In this section—

2(1) the term "program" means the emergency management performance grants program described in subsection (b); and

3(2) the term "State" has the meaning given that term in section 102 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5122).

4The Administrator of the Federal Emergency Management Agency shall continue implementation of an emergency management performance grants program, to make grants to States to assist State, local, and tribal governments in preparing for all hazards, as authorized by the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.).

5Except as otherwise specifically provided by title VI of the Robert T. Stafford Disaster Relief and Emergency Assistance Act [42 U.S.C. 5195 et seq.], the Federal share of the cost of an activity carried out using funds made available under the program shall not exceed 50 percent.

6For fiscal year 2008, and each fiscal year thereafter, the Administrator shall apportion the amounts appropriated to carry out the program among the States as follows:

7The Administrator shall first apportion 0.25 percent of such amounts to each of American Samoa, the Commonwealth of the Northern Mariana Islands, Guam, and the Virgin Islands and 0.75 percent of such amounts to each of the remaining States.

8The Administrator shall apportion the remainder of such amounts in the ratio that—

9(A) the population of each State; bears to

10(B) the population of all States.

11Notwithstanding subsection (d), in any fiscal year before fiscal year 2013 in which the appropriation for grants under this section is equal to or greater than the appropriation for emergency management performance grants in fiscal year 2007, no State shall receive an amount under this section for that fiscal year less than the amount that State received in fiscal year 2007.

12There is authorized to be appropriated to carry out the program, for each of fiscal years 2018 through 2022, $950,000,000.

763.

Transfer of Noble Training Center

1The Noble Training Center is transferred to the Center for Domestic Preparedness. The Center for Domestic Preparedness shall integrate the Noble Training Center into the program structure of the Center for Domestic Preparedness.

763a.

Training for Federal Government, foreign governments, or private entities

1In fiscal year 2013 and thereafter: (a) the Center for Domestic Preparedness may provide training to emergency response providers from the Federal Government, foreign governments, or private entities, if the Center for Domestic Preparedness is reimbursed for the cost of such training, and any reimbursement under this subsection shall be credited to the account from which the expenditure being reimbursed was made and shall be available, without fiscal year limitation, for the purposes for which amounts in the account may be expended; (b) the head of the Center for Domestic Preparedness shall ensure that any training provided under (a) does not interfere with the primary mission of the Center to train State and local emergency response providers; and (c) subject to (b), nothing in (a) prohibits the Center for Domestic Preparedness from providing training to employees of the Federal Emergency Management Agency in existing chemical, biological, radiological, nuclear, explosives, mass casualty, and medical surge courses pursuant to 5 U.S.C. 4103 without reimbursement for the cost of such training.

764.

National exercise simulation center

1The President shall establish a national exercise simulation center that—

2(1) uses a mix of live, virtual, and constructive simulations to—

3(A) prepare elected officials, emergency managers, emergency response providers, and emergency support providers at all levels of government to operate cohesively;

4(B) provide a learning environment for the homeland security personnel of all Federal agencies;

5(C) assist in the development of operational procedures and exercises, particularly those based on catastrophic incidents; and

6(D) allow incident commanders to exercise decisionmaking in a simulated environment; and

7(2) uses modeling and simulation for training, exercises, and command and control functions at the operational level.

765.

Real property transactions

1The Director of the Office of Civil and Defense Mobilization, or his designee, may not enter into any of the following listed transactions by or for the use of that agency until after the expiration of thirty days from the date upon which a report of the facts concerning the proposed transaction is submitted to the Committees on Armed Services of the Senate and House of Representatives:

2(1) An acquisition of fee title to any real property, if the estimated price is more than $50,000.

3(2) A lease of any real property to the United States, if the estimated annual rental is more than $50,000.

4(3) A lease of real property owned by the United States, if the estimated annual rental is more than $50,000.

5(4) A transfer of real property owned by the United States to another Federal agency or to a State, if the estimated value is more than $50,000.

6(5) A report of excess real property owned by the United States to a disposal agency, if the estimated value is more than $50,000.

7If a transaction covered by clause (1) or (2) is part of a project, the report must include a summarization of the general plan for that project, including an estimate of the total cost of the lands to be acquired or leases to be made.

8The Director of the Office of Civil and Defense Mobilization shall report annually to the Committees on Armed Services of the Senate and the House of Representatives on transactions described in subsection (a) that involve an estimated value of more than $5,000 but not more than $50,000.

9This section applies only to real property in the States of the Union, the District of Columbia, and Puerto Rico. It does not apply to real property for river and harbor projects or flood-control projects, or to leases of Government-owned real property for agricultural or grazing purposes.

10A statement in an instrument of conveyance, including a lease, that the requirements of this section have been met, or that the conveyance is not subject to this section, is conclusive.

771.

National Disaster Recovery Strategy

1The Administrator, in coordination with the Secretary of Housing and Urban Development, the Administrator of the Environmental Protection Agency, the Secretary of Agriculture, the Secretary of Commerce, the Secretary of the Treasury, the Secretary of Transportation, the Administrator of the Small Business Administration, the Assistant Secretary for Indian Affairs of the Department of the Interior, and the heads of other appropriate Federal agencies, State, local, and tribal government officials (including through the National Advisory Council), and representatives of appropriate nongovernmental organizations shall develop, coordinate, and maintain a National Disaster Recovery Strategy to serve as a guide to recovery efforts after major disasters and emergencies.

2The National Disaster Recovery Strategy shall—

3(1) outline the most efficient and cost-effective Federal programs that will meet the recovery needs of States, local and tribal governments, and individuals and households affected by a major disaster;

4(2) clearly define the role, programs, authorities, and responsibilities of each Federal agency that may be of assistance in providing assistance in the recovery from a major disaster;

5(3) promote the use of the most appropriate and cost-effective building materials (based on the hazards present in an area) in any area affected by a major disaster, with the goal of encouraging the construction of disaster-resistant buildings; and

6(4) describe in detail the programs that may be offered by the agencies described in paragraph (2), including—

7(A) discussing funding issues;

8(B) detailing how responsibilities under the National Disaster Recovery Strategy will be shared; and

9(C) addressing other matters concerning the cooperative effort to provide recovery assistance.

10Not later than 270 days after October 4, 2006, the Administrator shall submit to the appropriate committees of Congress a report describing in detail the National Disaster Recovery Strategy and any additional authorities necessary to implement any portion of the National Disaster Recovery Strategy.

11The Administrator shall submit to the appropriate committees of Congress a report updating the report submitted under paragraph (1)—

12(A) on the same date that any change is made to the National Disaster Recovery Strategy; and

13(B) on a periodic basis after the submission of the report under paragraph (1), but not less than once every 5 years after the date of the submission of the report under paragraph (1).

772.

National Disaster Housing Strategy

1The Administrator, in coordination with representatives of the Federal agencies, governments, and organizations listed in subsection (b)(2) of this section, the National Advisory Council, the National Council on Disability, and other entities at the Administrator's discretion, shall develop, coordinate, and maintain a National Disaster Housing Strategy.

2The National Disaster Housing Strategy shall—

3(1) outline the most efficient and cost effective Federal programs that will best meet the short-term and long-term housing needs of individuals and households affected by a major disaster;

4(2) clearly define the role, programs, authorities, and responsibilities of each entity in providing housing assistance in the event of a major disaster, including—

5(A) the Agency;

6(B) the Department of Housing and Urban Development;

7(C) the Department of Agriculture;

8(D) the Department of Veterans Affairs;

9(E) the Department of Health and Human Services;

10(F) the Bureau of Indian Affairs;

11(G) any other Federal agency that may provide housing assistance in the event of a major disaster;

12(H) the American Red Cross; and

13(I) State, local, and tribal governments;

14(3) describe in detail the programs that may be offered by the entities described in paragraph (2), including—

15(A) outlining any funding issues;

16(B) detailing how responsibilities under the National Disaster Housing Strategy will be shared; and

17(C) addressing other matters concerning the cooperative effort to provide housing assistance during a major disaster;

18(4) consider methods through which housing assistance can be provided to individuals and households where employment and other resources for living are available;

19(5) describe programs directed to meet the needs of special needs and low-income populations and ensure that a sufficient number of housing units are provided for individuals with disabilities;

20(6) describe plans for the operation of clusters of housing provided to individuals and households, including access to public services, site management, security, and site density;

21(7) describe plans for promoting the repair or rehabilitation of existing rental housing, including through lease agreements or other means, in order to improve the provision of housing to individuals and households under section 408 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5174); and

22(8) describe any additional authorities necessary to carry out any portion of the strategy.

23The Administrator should develop and make publicly available guidance on—

24(1) types of housing assistance available under the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.) to individuals and households affected by an emergency or major disaster;

25(2) eligibility for such assistance (including, where appropriate, the continuation of such assistance); and

26(3) application procedures for such assistance.

27Not later than 270 days after October 4, 2006, the Administrator shall submit to the appropriate committees of Congress a report describing in detail the National Disaster Housing Strategy, including programs directed to meeting the needs of special needs populations.

28The Administrator shall submit to the appropriate committees of Congress a report updating the report submitted under paragraph (1)—

29(A) on the same date that any change is made to the National Disaster Housing Strategy; and

30(B) on a periodic basis after the submission of the report under paragraph (1), but not less than once every 5 years after the date of the submission of the report under paragraph (1).

773.

Individuals with disabilities guidelines

1Not later than 90 days after October 4, 2006, and in coordination with the National Advisory Council, the National Council on Disability, the Interagency Coordinating Council on Preparedness and Individuals With Disabilities established under Executive Order No. 13347, and the Disability Coordinator (established under section 321b of this title), the Administrator shall develop guidelines to accommodate individuals with disabilities, which shall include guidelines for—

2(1) the accessibility of, and communications and programs in, shelters, recovery centers, and other facilities; and

3(2) devices used in connection with disaster operations, including first aid stations, mass feeding areas, portable payphone stations, portable toilets, and temporary housing.

774.

Reunification

1In this section:

2The term "Child Locator Center" means the National Emergency Child Locator Center established under subsection (b).

3The term "declared event" means a major disaster or emergency.

4The term "displaced adult" means an individual 21 years of age or older who is displaced from the habitual residence of that individual as a result of a declared event.

5The term "displaced child" means an individual under 21 years of age who is displaced from the habitual residence of that individual as a result of a declared event.

6Not later than 180 days after October 4, 2006, the Administrator, in coordination with the Attorney General of the United States, shall establish within the National Center for Missing and Exploited Children the National Emergency Child Locator Center. In establishing the National Emergency Child Locator Center, the Administrator shall establish procedures to make all relevant information available to the National Emergency Child Locator Center in a timely manner to facilitate the expeditious identification and reunification of children with their families.

7The purposes of the Child Locator Center are to—

8(A) enable individuals to provide to the Child Locator Center the name of and other identifying information about a displaced child or a displaced adult who may have information about the location of a displaced child;

9(B) enable individuals to receive information about other sources of information about displaced children and displaced adults; and

10(C) assist law enforcement in locating displaced children.

11The responsibilities and duties of the Child Locator Center are to—

12(A) establish a toll-free telephone number to receive reports of displaced children and information about displaced adults that may assist in locating displaced children;

13(B) create a website to provide information about displaced children;

14(C) deploy its staff to the location of a declared event to gather information about displaced children;

15(D) assist in the reunification of displaced children with their families;

16(E) provide information to the public about additional resources for disaster assistance;

17(F) work in partnership with Federal, State, and local law enforcement agencies;

18(G) provide technical assistance in locating displaced children;

19(H) share information on displaced children and displaced adults with governmental agencies and nongovernmental organizations providing disaster assistance;

20(I) use its resources to gather information about displaced children;

21(J) refer reports of displaced adults to—

22(i) an entity designated by the Attorney General to provide technical assistance in locating displaced adults; and

23(ii) the National Emergency Family Registry and Locator System as defined under section 775(a) of this title;

24(K) enter into cooperative agreements with Federal and State agencies and other organizations such as the American Red Cross as necessary to implement the mission of the Child Locator Center; and

25(L) develop an emergency response plan to prepare for the activation of the Child Locator Center.

26Not later than 270 days after October 4, 2006, the Administrator shall submit to the Committee on Homeland Security and Governmental Affairs and the Committee on the Judiciary of the Senate and the Committee on Transportation and Infrastructure and the Committee on the Judiciary of the House of Representatives a report describing in detail the status of the Child Locator Center, including funding issues and any difficulties or issues in establishing the Center or completing the cooperative agreements described in subsection (b)(3)(K).

775.

National Emergency Family Registry and Locator System

1In this section—

2(1) the term "displaced individual" means an individual displaced by an emergency or major disaster; and

3(2) the term "National Emergency Family Registry and Locator System" means the National Emergency Family Registry and Locator System established under subsection (b).

4Not later than 180 days after October 4, 2006, the Administrator shall establish a National Emergency Family Registry and Locator System to help reunify families separated after an emergency or major disaster.

5The National Emergency Family Registry and Locator System shall—

6(1) allow a displaced adult (including medical patients) to voluntarily register (and allow an adult that is the parent or guardian of a displaced child to register such child), by submitting personal information to be entered into a database (such as the name, current location of residence, and any other relevant information that could be used by others seeking to locate that individual);

7(2) ensure that information submitted under paragraph (1) is accessible to those individuals named by a displaced individual and to those law enforcement officials;

8(3) be accessible through the Internet and through a toll-free number, to receive reports of displaced individuals; and

9(4) include a means of referring displaced children to the National Emergency Child Locator Center established under section 774 of this title.

10Not later than 210 days after October 4, 2006, the Administrator shall establish a mechanism to inform the public about the National Emergency Family Registry and Locator System and its potential usefulness for assisting to reunite displaced individuals with their families.

11Not later than 90 days after October 4, 2006, the Administrator shall enter a memorandum of understanding with the Department of Justice, the National Center for Missing and Exploited Children, the Department of Health and Human Services, and the American Red Cross and other relevant private organizations that will enhance the sharing of information to facilitate reuniting displaced individuals (including medical patients) with their families.

12Not later than 270 days after October 4, 2006, the Administrator shall submit to the appropriate committees of Congress a report describing in detail the status of the National Emergency Family Registry and Locator System, including any difficulties or issues in establishing the System, including funding issues.

776.

Individuals and households pilot program

1The President, acting through the Administrator, in coordination with State, local, and tribal governments, shall establish and conduct a pilot program. The pilot program shall be designed to make better use of existing rental housing, located in areas covered by a major disaster declaration, in order to provide timely and cost-effective temporary housing assistance to individuals and households eligible for assistance under section 5174 of title 42 where alternative housing options are less available or less cost-effective.

2For the purposes of the pilot program under this section, the Administrator may—

3(i) enter into lease agreements with owners of multi-family rental property located in areas covered by a major disaster declaration to house individuals and households eligible for assistance under section 5174 of title 42;

4(ii) make improvements to properties under such lease agreements;

5(iii) use the pilot program where the program is cost effective in that the cost to the Government for the lease agreements is in proportion to the savings to the Government by not providing alternative housing; and

6(iv) limit repairs to those required to ensure that the housing units shall meet Federal housing quality standards.

7Under the terms of any lease agreement for a property described under subparagraph (A)(ii), the value of the contribution of the Agency to such improvements—

8(i) shall be deducted from the value of the lease agreement; and

9(ii) may not exceed the value of the lease agreement.

10In administering the pilot program under this section, the Administrator may consult with State, local, and tribal governments.

11Not later than March 31, 2009, the Administrator shall submit to the appropriate committees of Congress a report regarding the effectiveness of the pilot program.

12The Administrator shall include in the report—

13(i) an assessment of the effectiveness of the pilot program under this section, including an assessment of cost-savings to the Federal Government and any benefits to individuals and households eligible for assistance under section 5174 of title 42 under the pilot program;

14(ii) findings and conclusions of the Administrator with respect to the pilot program;

15(iii) an assessment of additional authorities needed to aid the Agency in its mission of providing disaster housing assistance to individuals and households eligible for assistance under section 5174 of title 42, either under the pilot program under this section or other potential housing programs; and

16(iv) any recommendations of the Administrator for additional authority to continue or make permanent the pilot program.

17The Administrator shall not approve a project under the pilot program after December 31, 2008.

777.

Public assistance pilot program

1The President, acting through the Administrator, and in coordination with State and local governments, shall establish and conduct a pilot program to—

2(A) reduce the costs to the Federal Government of providing assistance to States and local governments under sections 5170b(a)(3)(A), 5172, and 5173 of title 42;

3(B) increase flexibility in the administration of sections 5170b(a)(3)(A), 5172, and 5173 of title 42; and

4(C) expedite the provision of assistance to States and local governments provided under sections 5170b(a)(3)(A), 5172, and 5173 of title 42.

5Only States and local governments that elect to participate in the pilot program may participate in the pilot program for a particular project.

6For purposes of the pilot program, the Administrator shall establish new procedures to administer assistance provided under the sections referred to in paragraph (1).

7The new procedures established under subparagraph (A) may include 1 or more of the following:

8(i) Notwithstanding section 5172(c)(1)(A) of title 42, providing an option for a State or local government to elect to receive an in-lieu contribution in an amount equal to 90 percent of the Federal share of the Federal estimate of the cost of repair, restoration, reconstruction, or replacement of a public facility owned or controlled by the State or local government and of management expenses.

9(ii) Making grants on the basis of estimates agreed to by the local government (or where no local government is involved, by the State government) and the Administrator to provide financial incentives and disincentives for the local government (or where no local government is involved, for the State government) for the timely or cost effective completion of projects under sections 5170b(a)(3)(A), 5172, and 5173 of title 42.

10(iii) Increasing the Federal share for removal of debris and wreckage for States and local governments that have a debris management plan approved by the Administrator and have pre-qualified 1 or more debris and wreckage removal contractors before the date of declaration of the major disaster.

11(iv) Using a sliding scale for the Federal share for removal of debris and wreckage based on the time it takes to complete debris and wreckage removal.

12(v) Using a financial incentive to recycle debris.

13(vi) Reimbursing base wages for employees and extra hires of a State or local government involved in or administering debris and wreckage removal.

14The Administrator may waive such regulations or rules applicable to the provisions of assistance under the sections referred to in paragraph (1) as the Administrator determines are necessary to carry out the pilot program under this section.

15Not later than March 31, 2009, the Administrator shall submit to the appropriate committees of Congress a report regarding the effectiveness of the pilot program under this section.

16The report submitted under paragraph (1) shall include—

17(A) an assessment by the Administrator of any administrative or financial benefits of the pilot program;

18(B) an assessment by the Administrator of the effect, including any savings in time and cost, of the pilot program;

19(C) any identified legal or other obstacles to increasing the amount of debris recycled after a major disaster;

20(D) any other findings and conclusions of the Administrator with respect to the pilot program; and

21(E) any recommendations of the Administrator for additional authority to continue or make permanent the pilot program.

22The Administrator shall initiate implementation of the pilot program under this section not later than 90 days after October 4, 2006.

23The Administrator may not approve a project under the pilot program under this section after December 31, 2008.

791.

Advance contracting

1Not later than 180 days after October 4, 2006, the Administrator shall submit a report under paragraph (2) identifying—

2(A) recurring disaster response requirements, including specific goods and services, for which the Agency is capable of contracting for in advance of a natural disaster or act of terrorism or other man-made disaster in a cost effective manner;

3(B) recurring disaster response requirements, including specific goods and services, for which the Agency can not contract in advance of a natural disaster or act of terrorism or other man-made disaster in a cost effective manner; and

4(C) a contracting strategy that maximizes the use of advance contracts to the extent practical and cost-effective.

5The report under paragraph (1) shall be submitted to the appropriate committees of Congress.

6Not later than 1 year after October 4, 2006, the Administrator shall enter into 1 or more contracts for each type of goods or services identified under subsection (a)(1)(A), and in accordance with the contracting strategy identified in subsection (a)(1)(C). Any contract for goods or services identified in subsection (a)(1)(A) previously awarded may be maintained in fulfilling this requirement.

7Before entering into any contract under this subsection, the Administrator shall consider section 5150 of title 42.

8The Administrator, in coordination with State and local governments and other Federal agencies, shall establish a process to ensure that Federal prenegotiated contracts for goods and services are coordinated with State and local governments, as appropriate.

9The Administrator shall encourage State and local governments to establish prenegotiated contracts with vendors for goods and services in advance of natural disasters and acts of terrorism or other man-made disasters.

10After the date described under subsection (b), the Administrator shall have the responsibility to maintain contracts for appropriate levels of goods and services in accordance with subsection (a)(1)(C).

11At the end of each fiscal quarter, beginning with the first fiscal quarter occurring at least 90 days after October 4, 2006, the Administrator shall submit a report on each disaster assistance contract entered into by the Agency by other than competitive procedures to the appropriate committees of Congress.

12Not later than 180 days after December 31, 2020, the Administrator shall submit to the appropriate committees of Congress an updated report that contains—

13(1) the information required in the initial report under subparagraphs (A) and (B) of subsection (a)(1); and

14(2) an updated strategy described in subsection (a)(1)(C) that clearly defines—

15(A) the objectives of advance contracts;

16(B) how advance contracts contribute to disaster response operations of the Agency;

17(C) how to maximize the award of advance contracts to small business concerns, as defined in section 632 of title 15; and

18(D) whether and how advance contracts should be prioritized in relation to new post-disaster contract awards.

19The Administrator shall ensure that the head of contracting activity of the Agency—

20(A) not later than 270 days after December 31, 2020, updates the Disaster Contracting Desk Guide of the Agency to provide specific guidance—

21(i) on whether and under what circumstances contracting officers should consider using existing advance contracts entered into in accordance with this section prior to making new post-disaster contract awards, and include this guidance in existing semi-annual training given to contracting officers; and

22(ii) for contracting officers to perform outreach to State and local governments on the potential benefits of establishing their own pre-negotiated advance contracts;

23(B) adheres to hard copy contract file management requirements in effect to ensure that the files relating to advance contracts entered into in accordance with this section are complete and up to date, whether the files will be transferred into the Electronic Contract Filing System of the Agency or remain in hard copy format;

24(C) notifies contracting officers of the 3-day time frame requirement for entering completed award documentation into the contract writing system of the Agency when executing notice to proceed documentation;

25(D) not later than 180 days after December 31, 2020, revises the reporting methodology of the Agency to ensure that all disaster contracts are included in each quarterly report submitted to the appropriate congressional committees under this section on disaster contract actions;

26(E) identifies a single centralized resource listing advance contracts entered into under this section and ensures that source is current and up to date and includes all available advance contracts; and

27(F) communicates complete and up-to-date information on available advance contracts to State and local governments to inform their advance contracting efforts.

28Not later than 180 days after December 31, 2020, the Administrator shall update and implement guidance for program office and acquisition personnel of the Agency to—

29(A) identify acquisition planning time frames and considerations across the entire acquisition planning process of the Agency; and

30(B) clearly communicate the purpose and use of a master acquisition planning schedule.

792.

Repealed. Pub. L. 117–253, §1, Dec. 20, 2022, 136 Stat. 2360

793.

Oversight and accountability of Federal disaster expenditures

1The Administrator may designate up to 1 percent of the total amount provided to a Federal agency for a mission assignment as oversight funds to be used by the recipient agency for performing oversight of activities carried out under the Agency reimbursable mission assignment process. Such funds shall remain available until expended.

2Oversight funds may be used for the following types of oversight activities related to Agency mission assignments:

3(A) Monitoring, tracking, and auditing expenditures of funds.

4(B) Ensuring that sufficient management and internal control mechanisms are available so that Agency funds are spent appropriately and in accordance with all applicable laws and regulations.

5(C) Reviewing selected contracts and other activities.

6(D) Investigating allegations of fraud involving Agency funds.

7(E) Conducting and participating in fraud prevention activities with other Federal, State, and local government personnel and contractors.

8Oversight funds may be used to issue the plans required under subsection (e) and the reports required under subsection (f).

9Oversight funds may not be used to finance existing agency oversight responsibilities related to direct agency appropriations used for disaster response, relief, and recovery activities.

10Oversight activities may be carried out by an agency under this section either directly or by contract. Such activities may include evaluations and financial and performance audits.

11To the extent practicable, evaluations and audits under this section shall be performed by the inspector general of the agency.

12If an agency receives oversight funds for a fiscal year, the head of the agency shall prepare a plan describing the oversight activities for disaster response, relief, and recovery anticipated to be undertaken during the subsequent fiscal year.

13In preparing the plan, the head of the agency shall select oversight activities based upon a risk assessment of those areas that present the greatest risk of fraud, waste, and abuse.

14The plan shall include a schedule for conducting oversight activities, including anticipated dates of completion.

15A Federal agency receiving oversight funds under this section shall submit annually to the Administrator and the appropriate committees of Congress a consolidated report regarding the use of such funds, including information summarizing oversight activities and the results achieved.

16In this section, the term "oversight funds" means funds referred to in subsection (a) that are designated for use in performing oversight activities.

794.

Limitation on length of certain noncompetitive contracts

1The Secretary shall promulgate regulations applicable to contracts described in subsection (c) to restrict the contract period of any such contract entered into using procedures other than competitive procedures pursuant to the exception provided in paragraph (2) of section 3304(a) of title 41 to the minimum contract period necessary—

2(1) to meet the urgent and compelling requirements of the work to be performed under the contract; and

3(2) to enter into another contract for the required goods or services through the use of competitive procedures.

4The regulations promulgated under subsection (a) shall require the contract period to not to exceed 1 150 days, unless the Secretary determines that exceptional circumstances apply.

5This section applies to any contract in an amount greater than the simplified acquisition threshold (as defined by section 134 of title 41) entered into by the Department to facilitate response to or recovery from a natural disaster, act of terrorism, or other man-made disaster.

795.

Fraud, waste, and abuse controls

1The Administrator shall ensure that—

2(1) all programs within the Agency administering Federal disaster relief assistance develop and maintain proper internal management controls to prevent and detect fraud, waste, and abuse;

3(2) application databases used by the Agency to collect information on eligible recipients must record disbursements;

4(3) such tracking is designed to highlight and identify ineligible applications; and

5(4) the databases used to collect information from applications for such assistance must be integrated with disbursements and payment records.

6The Administrator shall ensure that any database or similar application processing system for Federal disaster relief assistance programs administered by the Agency undergoes a review by the Inspector General of the Agency to determine the existence and implementation of such internal controls required under this section and the amendments made by this section.

796.

Registry of disaster response contractors

1In this section—

2(1) the term "registry" means the registry created under subsection (b); and

3(2) the terms "small business concern", "small business concern owned and controlled by socially and economically disadvantaged individuals", "small business concern owned and controlled by women", and "small business concern owned and controlled by service-disabled veterans" have the meanings given those terms under the Small Business Act (15 U.S.C. 631 et seq.).

4The Administrator shall establish and maintain a registry of contractors who are willing to perform debris removal, distribution of supplies, reconstruction, and other disaster or emergency relief activities.

5The registry shall include, for each business concern—

6(A) the name of the business concern;

7(B) the location of the business concern;

8(C) the area served by the business concern;

9(D) the type of good or service provided by the business concern;

10(E) the bonding level of the business concern; and

11(F) whether the business concern is—

12(i) a small business concern;

13(ii) a small business concern owned and controlled by socially and economically disadvantaged individuals;

14(iii) a small business concern owned and controlled by women; or

15(iv) a small business concern owned and controlled by service-disabled veterans.

16Information maintained in the registry shall be submitted on a voluntary basis and be kept current by the submitting business concerns.

17Each business concern submitting information to the registry shall submit—

18(i) an attestation that the information is true; and

19(ii) documentation supporting such attestation.

20The Administrator shall verify that the documentation submitted by each business concern supports the information submitted by that business concern.

21The registry shall be made generally available on the Internet site of the Agency.

22As part of the acquisition planning for contracting for debris removal, distribution of supplies in a disaster, reconstruction, and other disaster or emergency relief activities, a Federal agency shall consult the registry.

797.

Fraud prevention training program

1The Administrator shall develop and implement a program to provide training on the prevention of waste, fraud, and abuse of Federal disaster relief assistance relating to the response to or recovery from natural disasters and acts of terrorism or other man-made disasters and ways to identify such potential waste, fraud, and abuse.

811.

Authorization of appropriations

1There are authorized to be appropriated to carry out this title 1 and the amendments made by this title for the administration and operations of the Agency—

2(1) for fiscal year 2008, an amount equal to the amount appropriated for fiscal year 2007 for administration and operations of the Agency, multiplied by 1.1;

3(2) for fiscal year 2009, an amount equal to the amount described in paragraph (1), multiplied by 1.1; and

4(3) for fiscal year 2010, an amount equal to the amount described in paragraph (2), multiplied by 1.1.

821.

Definitions

1In this part:

2The term "Administrator" means the Administrator of the Federal Emergency Management Agency.

3The term "basic need"—

4(A) means any good, service, or activity necessary to protect the health, safety, and general welfare of the civilian population of the United States; and

5(B) includes—

6(i) food;

7(ii) water;

8(iii) shelter;

9(iv) basic communication services;

10(v) basic sanitation and health services; and

11(vi) public safety.

12The term "catastrophic incident"—

13(A) means any natural or man-made disaster that results in extraordinary levels of casualties or damage, mass evacuations, or disruption severely affecting the population, infrastructure, environment, economy, national morale, or government functions in an area; and

14(B) may include an incident—

15(i) with a sustained national impact over a prolonged period of time;

16(ii) that may rapidly exceed resources available to State and local government and private sector authorities in the impacted area; or

17(iii) that may significantly interrupt governmental operations and emergency services to such an extent that national security could be threatened.

18The term "critical infrastructure" has the meaning given such term in section 5195c(e) of title 42.

19The term "existential risk" means the potential for an outcome that would result in human extinction.

20The term "global catastrophic risk" means the risk of events or incidents consequential enough to significantly harm or set back human civilization at the global scale.

21The term "global catastrophic and existential threats" means threats that with varying likelihood may produce consequences severe enough to result in systemic failure or destruction of critical infrastructure or significant harm to human civilization. Examples of global catastrophic and existential threats include severe global pandemics, nuclear war, asteroid and comet impacts, supervolcanoes, sudden and severe changes to the climate, and intentional or accidental threats arising from the use and development of emerging technologies.

22The term "Indian Tribal government" has the meaning given the term "Indian tribal government" in section 5122 of title 42.

23The terms "local government" and "State" have the meanings given such terms in section 5122 of title 42.

24The term "national exercise program" means activities carried out to test and evaluate the national preparedness goal and related plans and strategies as described in section 748(b) of this title.

25The term "Secretary" means the Secretary of Homeland Security.

822.

Assessment of global catastrophic risk

1The Secretary and the Administrator shall coordinate an assessment of global catastrophic risk.

2When coordinating the assessment under subsection (a), the Secretary and the Administrator shall coordinate with senior designees of—

3(1) the Assistant to the President for National Security Affairs;

4(2) the Director of the Office of Science and Technology Policy;

5(3) the Secretary of State and the Under Secretary of State for Arms Control and International Security;

6(4) the Attorney General and the Director of the Federal Bureau of Investigation;

7(5) the Secretary of Energy, the Under Secretary of Energy for Nuclear Security, and the Director of Science;

8(6) the Secretary of Health and Human Services, the Assistant Secretary for Preparedness and Response, and the Assistant Secretary of Global Affairs;

9(7) the Secretary of Commerce, the Under Secretary of Commerce for Oceans and Atmosphere, and the Under Secretary of Commerce for Standards and Technology;

10(8) the Secretary of the Interior and the Director of the United States Geological Survey;

11(9) the Administrator of the Environmental Protection Agency and the Assistant Administrator for Water;

12(10) the Administrator of the National Aeronautics and Space Administration;

13(11) the Director of the National Science Foundation;

14(12) the Secretary of the Treasury;

15(13) the Secretary of Defense, the Assistant Secretary of the Army for Civil Works, and the Chief of Engineers and Commanding General of the Army Corps of Engineers;

16(14) the Chairman of the Joint Chiefs of Staff;

17(15) the Administrator of the United States Agency for International Development;

18(16) the Secretary of Transportation; and

19(17) other stakeholders the Secretary and the Administrator determine appropriate.

823.

Report required

1Not later than 1 year after December 23, 2022, and every 10 years thereafter, the Secretary, in coordination with the Administrator, shall submit to the Committee on Homeland Security and Governmental Affairs and the Committee on Armed Services of the Senate and the Committee on Transportation and Infrastructure and the Committee on Armed Services of the House of Representatives a report containing a detailed assessment, based on the input and coordination required under section 822 of this title, of global catastrophic and existential risk.

2Each report required under subsection (a) shall include—

3(1) expert estimates of cumulative global catastrophic and existential risk in the next 30 years, including separate estimates for the likelihood of occurrence and potential consequences;

4(2) expert-informed analyses of the risk of the most concerning specific global catastrophic and existential threats, including separate estimates, where reasonably feasible and credible, of each threat for its likelihood of occurrence and its potential consequences, as well as associated uncertainties;

5(3) a comprehensive list of potential catastrophic or existential threats, including even those that may have very low likelihood;

6(4) technical assessments and lay explanations of the analyzed global catastrophic and existential risks, including their qualitative character and key factors affecting their likelihood of occurrence and potential consequences;

7(5) an explanation of any factors that limit the ability of the Secretary to assess the risk both cumulatively and for particular threats, and how those limitations may be overcome through future research or with additional resources, programs, or authorities;

8(6) a forecast of if and why global catastrophic and existential risk is likely to increase or decrease significantly in the next 10 years, both qualitatively and quantitatively, as well as a description of associated uncertainties;

9(7) proposals for how the Federal Government may more adequately assess global catastrophic and existential risk on an ongoing basis in future years;

10(8) recommendations for legislative actions, as appropriate, to support the evaluation and assessment of global catastrophic and existential risk; and

11(9) other matters deemed appropriate by the Secretary, in coordination with the Administrator, and based on the input and coordination required under section 822 of this title.

12In producing the report required under subsection (a), the Secretary shall—

13(1) regularly consult with experts on severe global pandemics, nuclear war, asteroid and comet impacts, supervolcanoes, sudden and severe changes to the climate, and intentional or accidental threats arising from the use and development of emerging technologies; and

14(2) share information gained through the consultation required under paragraph (1) with relevant Federal partners listed in section 822(b) of this title.

824.

Enhanced catastrophic incident annex

1The Secretary, in coordination with the Administrator and the Federal partners listed in section 822(b) of this title, shall supplement each Federal Interagency Operational Plan to include an annex containing a strategy to ensure the health, safety, and general welfare of the civilian population affected by catastrophic incidents by—

2(1) providing for the basic needs of the civilian population of the United States that is impacted by catastrophic incidents in the United States;

3(2) coordinating response efforts with State, local, and Indian Tribal governments, the private sector, and nonprofit relief organizations;

4(3) promoting personal and local readiness and non-reliance on government relief during periods of heightened tension or after catastrophic incidents; and

5(4) developing international partnerships with allied nations for the provision of relief services and goods.

6The strategy required under subsection (a) shall include a description of—

7(1) actions the Federal Government should take to ensure the basic needs of the civilian population of the United States in a catastrophic incident are met;

8(2) how the Federal Government should coordinate with non-Federal entities to multiply resources and enhance relief capabilities, including—

9(A) State and local governments;

10(B) Indian Tribal governments;

11(C) State disaster relief agencies;

12(D) State and local disaster relief managers;

13(E) State National Guards;

14(F) law enforcement and first response entities; and

15(G) nonprofit relief services;

16(3) actions the Federal Government should take to enhance individual resiliency to the effects of a catastrophic incident, which actions shall include—

17(A) readiness alerts to the public during periods of elevated threat;

18(B) efforts to enhance domestic supply and availability of critical goods and basic necessities; and

19(C) information campaigns to ensure the public is aware of response plans and services that will be activated when necessary;

20(4) efforts the Federal Government should undertake and agreements the Federal Government should seek with international allies to enhance the readiness of the United States to provide for the general welfare;

21(5) how the strategy will be implemented should multiple levels of critical infrastructure be destroyed or taken offline entirely for an extended period of time; and

22(6) the authorities the Federal Government should implicate in responding to a catastrophic incident.

23In designing the strategy under subsection (a), the Secretary, in coordination with the Administrator and the Federal partners listed in section 822(b) of this title, shall account for certain factors to make the strategy operationally viable, including the assumption that—

24(1) multiple levels of critical infrastructure have been taken offline or destroyed by catastrophic incidents or the effects of catastrophic incidents;

25(2) impacted sectors may include—

26(A) the transportation sector;

27(B) the communication sector;

28(C) the energy sector;

29(D) the healthcare and public health sector; and

30(E) the water and wastewater sector;

31(3) State, local, Indian Tribal, and territorial governments have been equally affected or made largely inoperable by catastrophic incidents or the effects of catastrophic incidents;

32(4) the emergency has exceeded the response capabilities of State, local, and Indian Tribal governments under the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.) and other relevant disaster response laws; and

33(5) the United States military is sufficiently engaged in armed or cyber conflict with State or non-State adversaries, or is otherwise unable to augment domestic response capabilities in a significant manner due to a catastrophic incident.

825.

Rules of construction

1Nothing in this part shall be construed to supersede the civilian emergency management authority of the Administrator under the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.) or the Post Katrina Emergency Management Reform Act 1 (6 U.S.C. 701 et seq.).

2Nothing in this part shall be construed as providing new authority to the Secretary, except to coordinate and facilitate the development of the assessments and reports required pursuant to this part.

CHAPTER 3—SECURITY AND ACCOUNTABILITY FOR EVERY PORT

901.

Definitions

1In this Act:

2Except as otherwise provided, the term "appropriate congressional committees" means—

3(A) the Committee on Appropriations of the Senate;

4(B) the Committee on Commerce, Science, and Transportation of the Senate;

5(C) the Committee on Finance of the Senate;

6(D) the Committee on Homeland Security and Governmental Affairs of the Senate;

7(E) the Committee on Appropriations of the House of Representatives;

8(F) the Committee on Homeland Security of the House of Representatives;

9(G) the Committee on Transportation and Infrastructure of the House of Representatives;

10(H) the Committee on Ways and Means of the House of Representatives; and

11(I) other congressional committees, as appropriate.

12The term "Commercial Operations Advisory Committee" means the Advisory Committee established pursuant to section 9503(c) of the Omnibus Budget Reconciliation Act of 1987 (19 U.S.C. 2071 note) 1 or any successor committee.

13The term "commercial seaport personnel" includes any person engaged in an activity relating to the loading or unloading of cargo or passengers, the movement or tracking of cargo, the maintenance and repair of intermodal equipment, the operation of cargo-related equipment (whether or not integral to the vessel), and the handling of mooring lines on the dock when a vessel is made fast or let go in the United States.

14The term "Commissioner" means the Commissioner responsible for the United States Customs and Border Protection of the Department of Homeland Security.

15The term "container" has the meaning given the term in the International Convention for Safe Containers, with annexes, done at Geneva, December 2, 1972 (29 UST 3707).

16The term "container security device" means a device, or system, designed, at a minimum, to identify positively a container, to detect and record the unauthorized intrusion of a container, and to secure a container against tampering throughout the supply chain. Such a device, or system, shall have a low false alarm rate as determined by the Secretary.

17The term "Department" means the Department of Homeland Security.

18The term "examination" means an inspection of cargo to detect the presence of misdeclared, restricted, or prohibited items that utilizes nonintrusive imaging and detection technology.

19The term "inspection" means the comprehensive process used by the United States Customs and Border Protection to assess goods entering the United States to appraise them for duty purposes, to detect the presence of restricted or prohibited items, and to ensure compliance with all applicable laws. The process may include screening, conducting an examination, or conducting a search.

20The term "international supply chain" means the end-to-end process for shipping goods to or from the United States beginning at the point of origin (including manufacturer, supplier, or vendor) through a point of distribution to the destination.

21The term "radiation detection equipment" means any technology that is capable of detecting or identifying nuclear and radiological material or nuclear and radiological explosive devices.

22The term "scan" means utilizing nonintrusive imaging equipment, radiation detection equipment, or both, to capture data, including images of a container.

23The term "screening" means a visual or automated review of information about goods, including manifest or entry documentation accompanying a shipment being imported into the United States, to determine the presence of misdeclared, restricted, or prohibited items and assess the level of threat posed by such cargo.

24The term "search" means an intrusive examination in which a container is opened and its contents are devanned and visually inspected for the presence of misdeclared, restricted, or prohibited items.

25The term "Secretary" means the Secretary of Homeland Security.

26The term "transportation disruption" means any significant delay, interruption, or stoppage in the flow of trade caused by a natural disaster, heightened threat level, an act of terrorism, or any transportation security incident (as defined in section 70101(6) 1 of title 46).

27The term "transportation security incident" has the meaning given the term in section 70101(6) 1 of title 46.

911.

Repealed. Pub. L. 111–281, title VIII, §821(b), Oct. 15, 2010, 124 Stat. 3003

912.

Port Security Exercise Program

1The Secretary, acting through the Under Secretary for Preparedness and in coordination with the Commandant of the Coast Guard, shall establish a Port Security Exercise Program (referred to in this section as the "Exercise Program") for the purpose of testing and evaluating the capabilities of Federal, State, local, and foreign governments, commercial seaport personnel and management, governmental and nongovernmental emergency response providers, the private sector, or any other organization or entity, as the Secretary determines to be appropriate, to prevent, prepare for, mitigate against, respond to, and recover from acts of terrorism, natural disasters, and other emergencies at facilities required to submit a plan under section 70103(c) of title 46.

2The Secretary shall ensure that the Exercise Program—

3(1) conducts, on a periodic basis, port security exercises at such facilities that are—

4(A) scaled and tailored to the needs of each facility;

5(B) live, in the case of the most at-risk facilities;

6(C) as realistic as practicable and based on current risk assessments, including credible threats, vulnerabilities, and consequences;

7(D) consistent with the National Incident Management System, the National Response Plan, the National Infrastructure Protection Plan, the National Preparedness Guidance, the National Preparedness Goal, the National Maritime Transportation Security Plan, and other such national initiatives;

8(E) evaluated against clear and consistent performance measures;

9(F) assessed to learn best practices, which shall be shared with appropriate Federal, State, and local officials, commercial seaport personnel and management, governmental and nongovernmental emergency response providers, and the private sector; and

10(G) followed by remedial action in response to lessons learned; and

11(2) assists State and local governments and facilities in designing, implementing, and evaluating exercises that—

12(A) conform to the requirements of paragraph (1); and

13(B) are consistent with any applicable Area Maritime Transportation Security Plan and State or Urban Area Homeland Security Plan.

14The Secretary shall establish a port security exercise improvement plan process to—

15(1) identify and analyze each port security exercise for lessons learned and best practices;

16(2) disseminate lessons learned and best practices to participants in the Exercise Program;

17(3) monitor the implementation of lessons learned and best practices by participants in the Exercise Program; and

18(4) conduct remedial action tracking and long-term trend analysis.

913.

Facility exercise requirements

1The Secretary of the Department in which the Coast Guard is operating shall require each high risk facility to conduct live or full-scale exercises described in section 105.220(c) of title 33, Code of Federal Regulations, not less frequently than once every 2 years, in accordance with the facility security plan required under section 70103(c) of title 46.

921.

Domestic radiation detection and imaging

1Subject to section 1318 of title 19, not later than December 31, 2007, all containers entering the United States through the 22 ports through which the greatest volume of containers enter the United States by vessel shall be scanned for radiation. To the extent practicable, the Secretary shall deploy next generation radiation detection technology.

2The Secretary shall develop a strategy for the deployment of radiation detection capabilities that includes—

3(1) a risk-based prioritization of ports of entry at which radiation detection equipment will be deployed;

4(2) a proposed timeline of when radiation detection equipment will be deployed at each port of entry identified under paragraph (1);

5(3) the type of equipment to be used at each port of entry identified under paragraph (1), including the joint deployment and utilization of radiation detection equipment and nonintrusive imaging equipment;

6(4) standard operating procedures for examining containers with such equipment, including sensor alarming, networking, and communications and response protocols;

7(5) operator training plans;

8(6) an evaluation of the environmental health and safety impacts of nonintrusive imaging technology and a radiation risk reduction plan, in consultation with the Nuclear Regulatory Commission, the Occupational Safety and Health Administration, and the National Institute for Occupational Safety and Health, that seeks to minimize radiation exposure of workers and the public to levels as low as reasonably achievable;

9(7) the policy of the Department for using nonintrusive imaging equipment in tandem with radiation detection equipment; and

10(8) a classified annex that—

11(A) details plans for covert testing; and

12(B) outlines the risk-based prioritization of ports of entry identified under paragraph (1).

13The Secretary, acting through the Director for Domestic Nuclear Detection 1 and in collaboration with the National Institute of Standards and Technology, shall publish technical capability standards and recommended standard operating procedures for the use of nonintrusive imaging and radiation detection equipment in the United States. Such standards and procedures—

14(1) should take into account relevant standards and procedures utilized by other Federal departments or agencies as well as those developed by international bodies; and

15(2) shall not be designed so as to endorse specific companies or create sovereignty conflicts with participating countries.

16Not later than 3 years after October 13, 2006, the Secretary shall fully implement the strategy developed under subsection (b).

17As soon as practicable after—

18(A) implementation of the program for the examination of containers for radiation at ports of entry described in subsection (a); and

19(B) submission of the strategy developed under subsection (b),

20but not later than December 31, 2008, the Secretary shall expand the strategy developed under subsection (b), in a manner consistent with the requirements of subsection (b), to provide for the deployment of radiation detection capabilities at all other United States ports of entry not covered by the strategy developed under subsection (b).

21In expanding the strategy under paragraph (1), the Secretary shall identify and assess the risks to those other ports of entry in order to determine what equipment and practices will best mitigate the risks.

22In accordance with subsection (b), and in order to comply with this section, the Secretary shall establish an Intermodal Rail Radiation Detection Test Center (referred to in this subsection as the "Test Center").

23The Secretary shall conduct multiple, concurrent projects at the Test Center to rapidly identify and test concepts specific to the challenges posed by on-dock rail.

24The Test Center shall be located within a public port facility at which a majority of the containerized cargo is directly laden from (or unladen to) on-dock, intermodal rail.

921a.

Integration of detection equipment and technologies

1The Secretary of Homeland Security shall have responsibility for ensuring that domestic chemical, biological, radiological, and nuclear detection equipment and technologies are integrated, as appropriate, with other border security systems and detection technologies.

2Not later than 6 months after August 3, 2007, the Secretary shall submit a report to Congress that contains a plan to develop a departmental technology assessment process to determine and certify the technology readiness levels of chemical, biological, radiological, and nuclear detection technologies before the full deployment of such technologies within the United States.

922.

Repealed. Pub. L. 115–254, div. J, §1816(c), Oct. 5, 2018, 132 Stat. 3541

923.

Random searches of containers

1Not later than 1 year after October 13, 2006, the Secretary, acting through the Commissioner, shall develop and implement a plan, utilizing best practices for empirical scientific research design and random sampling, to conduct random searches of containers in addition to any targeted or preshipment inspection of such containers required by law or regulation or conducted under any other program conducted by the Secretary. Nothing in this section shall be construed to mean that implementation of the random sampling plan precludes additional searches of containers not inspected pursuant to the plan.

924.

Threat assessment screening of port truck drivers

1Not later than 90 days after October 13, 2006, the Secretary shall implement a threat assessment screening, including name-based checks against terrorist watch lists and immigration status check, for all port truck drivers with access to secure areas of a port who have a commercial driver's license but do not have a current and valid hazardous materials endorsement issued in accordance with section 1572 1 of title 49, Code of Federal Regulations, that is the same as the threat assessment screening required for facility employees and longshoremen by the Commandant of the Coast Guard under Coast Guard Notice USCG–2006–24189 (Federal Register, Vol. 71, No. 82, Friday, April 28, 2006).

925.

Border Patrol unit for United States Virgin Islands

1The Secretary may establish at least 1 Border Patrol unit for the United States Virgin Islands.

2Not later than 180 days after October 13, 2006, the Secretary shall submit a report to the appropriate congressional committees that includes the schedule, if any, for carrying out subsection (a).

926.

Center of Excellence for Maritime Domain Awareness

1The Secretary shall establish a university-based Center for Excellence for Maritime Domain Awareness following the merit-review processes and procedures that have been established by the Secretary for selecting university program centers of excellence.

2The Center established under subsection (a) shall—

3(1) prioritize its activities based on the "National Plan To Improve Maritime Domain Awareness" published by the Department in October 2005;

4(2) recognize the extensive previous and ongoing work and existing competence in the field of maritime domain awareness at numerous academic and research institutions, such as the Naval Postgraduate School;

5(3) leverage existing knowledge and continue development of a broad base of expertise within academia and industry in maritime domain awareness; and

6(4) provide educational, technical, and analytical assistance to Federal agencies with responsibilities for maritime domain awareness, including the Coast Guard, to focus on the need for interoperability, information sharing, and common information technology standards and architecture.

941.

Strategic plan to enhance the security of the international supply chain

1The Secretary, in consultation with appropriate Federal, State, local, and tribal government agencies and private sector stakeholders responsible for security matters that affect or relate to the movement of containers through the international supply chain, shall develop, implement, and update, triennially, a strategic plan to enhance the security of the international supply chain.

2The strategic plan required under subsection (a) shall—

3(1) describe the roles, responsibilities, and authorities of Federal, State, local, and tribal government agencies and private-sector stakeholders that relate to the security of the movement of containers through the international supply chain;

4(2) identify and address gaps and unnecessary overlaps in the roles, responsibilities, or authorities described in paragraph (1);

5(3) identify and make recommendations regarding legislative, regulatory, and organizational changes necessary to improve coordination among the entities or to enhance the security of the international supply chain;

6(4) provide measurable goals, including objectives, mechanisms, and a schedule, for furthering the security of commercial operations from point of origin to point of destination;

7(5) build on available resources and consider costs and benefits;

8(6) provide incentives for additional voluntary measures to enhance cargo security, as recommended by the Commissioner;

9(7) consider the impact of supply chain security requirements on small- and medium-sized companies;

10(8) include a process for sharing intelligence and information with private-sector stakeholders to assist in their security efforts;

11(9) identify a framework for prudent and measured response in the event of a transportation security incident involving the international supply chain;

12(10) provide protocols for the expeditious resumption of the flow of trade in accordance with section 942 of this title;

13(11) consider the linkages between supply chain security and security programs within other systems of movement, including travel security and terrorism finance programs; and

14(12) expand upon and relate to existing strategies and plans, including the National Response Plan, the National Maritime Transportation Security Plan, the National Strategy for Maritime Security, and the 8 supporting plans of the Strategy, as required by Homeland Security Presidential Directive 13.

15In developing protocols under subsection (b)(10), the Secretary shall consult with Federal, State, local, and private sector stakeholders, including the National Maritime Security Advisory Committee and the Commercial Operations Advisory Committee.

16To the extent practicable, the strategic plan developed under subsection (a) shall provide for coordination with, and lines of communication among, appropriate Federal, State, local, and private-sector stakeholders on law enforcement actions, intermodal rerouting plans, and other strategic infrastructure issues resulting from a transportation security incident or transportation disruption.

17As part of the consultations described in subsection (a), the Secretary shall, to the extent practicable, utilize the Homeland Security Advisory Committee, the National Maritime Security Advisory Committee, and the Commercial Operations Advisory Committee to review, as necessary, the draft strategic plan and any subsequent updates to the strategic plan.

18In furtherance of the strategic plan required under subsection (a), the Secretary is encouraged to consider proposed or established standards and practices of foreign governments and international organizations, including the International Maritime Organization, the World Customs Organization, the International Labor Organization, and the International Organization for Standardization, as appropriate, to establish standards and best practices for the security of containers moving through the international supply chain.

19Not later than 270 days after October 13, 2006, the Secretary shall submit to the appropriate congressional committees a report that contains the strategic plan required by subsection (a).

20Not later than 270 days after October 5, 2018, and triennially thereafter, the Secretary shall submit to the appropriate congressional committees a report that contains any updates to the strategic plan under subsection (a) since the prior report.

942.

Post-incident resumption of trade

1The Secretary shall develop and update, as necessary, protocols for the resumption of trade in accordance with section 941(b)(10) of this title in the event of a transportation disruption or a transportation security incident. The protocols shall include—

2(1) the identification of the appropriate initial incident commander, if the Commandant of the Coast Guard is not the appropriate person, and lead departments, agencies, or offices to execute such protocols;

3(2) a plan to redeploy resources and personnel, as necessary, to reestablish the flow of trade;

4(3) a plan to provide training for the periodic instruction of personnel of the United States Customs and Border Protection, the Coast Guard, and the Transportation Security Administration in trade resumption functions and responsibilities; and

5(4) appropriate factors for establishing prioritization of vessels and cargo determined by the President to be critical for response and recovery, including factors relating to public health, national security, and economic need.

6In determining the prioritization of vessels accessing facilities (as defined under section 70101 of title 46), the Commandant of the Coast Guard may, to the extent practicable and consistent with the protocols and plans required under this section to ensure the safe and secure transit of vessels to ports in the United States after a transportation security incident, give priority to a vessel—

7(1) that has an approved security plan under section 70103(c) of title 46 or a valid international ship security certificate, as provided under part 104 of title 33, Code of Federal Regulations;

8(2) that is manned by individuals who are described in section 70105(b)(2)(B) of title 46; and

9(3) that is operated by validated participants in the Customs-Trade Partnership Against Terrorism program.

10In determining the prioritization of the resumption of the flow of cargo and consistent with the protocols established under this section, the Commissioner may give preference to cargo—

11(1) entering a port of entry directly from a foreign seaport designated under the Container Security Initiative;

12(2) from the supply chain of a validated C–TPAT participant and other private sector entities, as appropriate; or

13(3) that has undergone—

14(A) a nuclear or radiological detection scan;

15(B) an x-ray, density, or other imaging scan; and

16(C) a system to positively identify the container at the last port of departure prior to arrival in the United States, which data has been evaluated and analyzed by personnel of the United States Customs and Border Protection.

17The Secretary shall ensure that there is appropriate coordination among the Commandant of the Coast Guard, the Commissioner, and other Federal officials following a maritime disruption or maritime transportation security incident in order to provide for the resumption of trade.

18Consistent with section 941 of this title, the Commandant of the Coast Guard, Commissioner, and other appropriate Federal officials, shall promptly communicate any revised procedures or instructions intended for the private sector following a maritime disruption or maritime transportation security incident.

943.

Automated Targeting System

1The Secretary, acting through the Commissioner, shall—

2(1) identify and seek the submission of data related to the movement of a shipment of cargo through the international supply chain; and

3(2) analyze the data described in paragraph (1) to identify high-risk cargo for inspection.

4The Secretary, acting through the Commissioner, shall require the electronic transmission to the Department of additional data elements for improved high-risk targeting, including appropriate security elements of entry data, as determined by the Secretary, to be provided as advanced information with respect to cargo destined for importation into the United States prior to loading of such cargo on vessels at foreign seaports.

5The Secretary, acting through the Commissioner, shall—

6(1) consider the cost, benefit, and feasibility of—

7(A) requiring additional nonmanifest documentation;

8(B) reducing the time period allowed by law for revisions to a container cargo manifest;

9(C) reducing the time period allowed by law for submission of certain elements of entry data, for vessel or cargo; and

10(D) such other actions the Secretary considers beneficial for improving the information relied upon for the Automated Targeting System and any successor targeting system in furthering the security and integrity of the international supply chain; and

11(2) consult with stakeholders, including the Commercial Operations Advisory Committee, and identify to them the need for such information, and the appropriate timing of its submission.

12The Secretary shall promulgate regulations to carry out this section. In promulgating such regulations, the Secretary shall adhere to the parameters applicable to the development of regulations under section 343(a) of the Trade Act of 2002 (19 U.S.C. 2071 note),1 including provisions relating to consultation, technology, analysis, use of information, confidentiality, and timing requirements.

13The Secretary, acting through the Commissioner, shall—

14(1) conduct, through an independent panel, a review of the effectiveness and capabilities of the Automated Targeting System;

15(2) consider future iterations of the Automated Targeting System, which would incorporate smart features, such as more complex algorithms and real-time intelligence, instead of relying solely on rule sets that are periodically updated;

16(3) ensure that the Automated Targeting System has the capability to electronically compare manifest and other available data for cargo entered into or bound for the United States to detect any significant anomalies between such data and facilitate the resolution of such anomalies;

17(4) ensure that the Automated Targeting System has the capability to electronically identify, compile, and compare select data elements for cargo entered into or bound for the United States following a maritime transportation security incident, in order to efficiently identify cargo for increased inspection or expeditious release; and

18(5) develop a schedule to address the recommendations of the Comptroller General of the United States, the Inspector General of the Department of the Treasury, and the Inspector General of the Department with respect to the operation of the Automated Targeting System.

19All information required by the Department from supply chain partners shall be transmitted in a secure fashion, as determined by the Secretary, so as to protect the information from unauthorized access.

20There are authorized to be appropriated to the United States Customs and Border Protection to carry out the Automated Targeting System for identifying high-risk oceanborne container cargo for inspection—

21(1) $33,200,000 for fiscal year 2008;

22(2) $35,700,000 for fiscal year 2009; and

23(3) $37,485,000 for fiscal year 2010.

944.

Container security standards and procedures

1Not later than 90 days after October 13, 2006, the Secretary shall initiate a rulemaking proceeding to establish minimum standards and procedures for securing containers in transit to the United States.

2Not later than 180 days after October 13, 2006, the Secretary shall issue an interim final rule pursuant to the proceeding described in paragraph (1).

3If the Secretary is unable to meet the deadline established pursuant to paragraph (2), the Secretary shall submit a letter to the appropriate congressional committees explaining why the Secretary is unable to meet that deadline and describing what must be done before such minimum standards and procedures can be established.

4Not later than 2 years after the date on which the standards and procedures are established pursuant to paragraph (1), all containers bound for ports of entry in the United States shall meet such standards and procedures.

5If the interim final rule described in paragraph (2) is not issued by April 1, 2008, then—

6(i) effective not later than October 15, 2008, all containers in transit to the United States shall be required to meet the requirements of International Organization for Standardization Publicly Available Specification 17712 standard for sealing containers; and

7(ii) the requirements of this subparagraph shall cease to be effective upon the effective date of the interim final rule issued pursuant to this subsection.

8The Secretary shall regularly review and enhance the standards and procedures established pursuant to subsection (a), as appropriate, based on tests of technologies as they become commercially available to detect container intrusion and the highest consequence threats, particularly weapons of mass destruction.

9The Secretary, in consultation with the Secretary of State, the Secretary of Energy, and other Federal Government officials, as appropriate, and with the Commercial Operations Advisory Committee, the Homeland Security Advisory Committee, and the National Maritime Security Advisory Committee, is encouraged to promote and establish international standards for the security of containers moving through the international supply chain with foreign governments and international organizations, including the International Maritime Organization, the International Organization for Standardization, the International Labor Organization, and the World Customs Organization.

10In carrying out this section, the Secretary shall consult with appropriate Federal departments and agencies and private sector stakeholders and ensure that actions under this section do not violate international trade obligations or other international obligations of the United States.

945.

Container Security Initiative

1The Secretary, acting through the Commissioner, shall establish and implement a program (referred to in this section as the "Container Security Initiative" or "CSI") to identify and examine or search maritime containers that pose a security risk before loading such containers in a foreign port for shipment to the United States, either directly or through a foreign port.

2The Secretary, acting through the Commissioner, may designate foreign seaports to participate in the Container Security Initiative after the Secretary has assessed the costs, benefits, and other factors associated with such designation, including—

3(1) the level of risk for the potential compromise of containers by terrorists, or other threats as determined by the Secretary;

4(2) the volume of cargo being imported to the United States directly from, or being transshipped through, the foreign seaport;

5(3) the results of the Coast Guard assessments conducted pursuant to section 70108 of title 46;

6(4) the commitment of the government of the country in which the foreign seaport is located to cooperating with the Department in sharing critical data and risk management information and to maintain programs to ensure employee integrity; and

7(5) the potential for validation of security practices at the foreign seaport by the Department.

8The Secretary shall notify the appropriate congressional committees of the designation of a foreign port under the Container Security Initiative or the revocation of such a designation before notifying the public of such designation or revocation.

9The Secretary, in cooperation with the Secretary of State and in consultation with the United States Trade Representative, may enter into negotiations with the government of each foreign nation in which a seaport is designated under the Container Security Initiative to ensure full compliance with the requirements under the Container Security Initiative.

10The Secretary shall—

11(A) establish minimum technical capability criteria and standard operating procedures for the use of nonintrusive inspection and nuclear and radiological detection systems in conjunction with CSI;

12(B) require each port designated under CSI to operate nonintrusive inspection and nuclear and radiological detection systems in accordance with the technical capability criteria and standard operating procedures established under subparagraph (A);

13(C) continually monitor the technologies, processes, and techniques used to inspect cargo at ports designated under CSI to ensure adherence to such criteria and the use of such procedures; and

14(D) consult with the Secretary of Energy in establishing the minimum technical capability criteria and standard operating procedures established under subparagraph (A) pertaining to radiation detection technologies to promote consistency in detection systems at foreign ports designated under CSI.

15The criteria and procedures established under paragraph (1)(A)—

16(A) shall be consistent, as practicable, with relevant standards and procedures utilized by other Federal departments or agencies, or developed by international bodies if the United States consents to such standards and procedures;

17(B) shall not apply to activities conducted under the Megaports Initiative of the Department of Energy; and

18(C) shall not be designed to endorse the product or technology of any specific company or to conflict with the sovereignty of a country in which a foreign seaport designated under the Container Security Initiative is located.

19The authority of the Secretary under this section shall not affect any authority or duplicate any efforts or responsibilities of the Federal Government with respect to the deployment of radiation detection equipment outside of the United States.

20The Secretary shall—

21(1) coordinate with the Secretary of Energy, as necessary, to provide radiation detection equipment required to support the Container Security Initiative through the Department of Energy's Second Line of Defense Program and Megaports Initiative; or

22(2) work with the private sector or host governments, when possible, to obtain radiation detection equipment that meets the Department's and the Department of Energy's technical specifications for such equipment.

23The Secretary shall develop a human capital management plan to determine adequate staffing levels in the United States and in foreign seaports including, as appropriate, the remote location of personnel in countries in which foreign seaports are designated under the Container Security Initiative.

24The Secretary, in coordination with the appropriate Federal officials, shall hold annual discussions with foreign governments of countries in which foreign seaports designated under the Container Security Initiative are located regarding best practices, technical assistance, training needs, and technological developments that will assist in ensuring the efficient and secure movement of international cargo.

25The Secretary, acting through the Commissioner, may treat cargo loaded in a foreign seaport designated under the Container Security Initiative as presenting a lesser risk than similar cargo loaded in a foreign seaport that is not designated under the Container Security Initiative, for the purpose of clearing such cargo into the United States.

26The Secretary shall issue a "do not load" order, using existing authorities, to prevent the onload of any cargo loaded at a port designated under CSI that has been identified as high risk, including by the Automated Targeting System, unless the cargo is determined to no longer be high risk through—

27(A) a scan of the cargo with nonintrusive imaging equipment and radiation detection equipment;

28(B) a search of the cargo; or

29(C) additional information received by the Department.

30Nothing in this subsection shall be construed to interfere with the ability of the Secretary to deny entry of any cargo into the United States.

31Not later than 270 days after October 5, 2018, the Secretary, acting through the Commissioner, shall, in consultation with other appropriate government officials and the Commercial Operations Advisory Committee, submit a report to the appropriate congressional committees on the effectiveness of, and the need for any improvements to, the Container Security Initiative. The report shall include—

32(1) a description of the technical assistance delivered to, as well as needed at, each designated seaport;

33(2) a description of the human capital management plan at each designated seaport;

34(3) a summary of the requests made by the United States to foreign governments to conduct physical or nonintrusive inspections of cargo at designated seaports, and whether each such request was granted or denied by the foreign government;

35(4) an assessment of the effectiveness of screening, scanning, and inspection protocols and technologies utilized at designated seaports and the effect on the flow of commerce at such seaports, as well as any recommendations for improving the effectiveness of screening, scanning, and inspection protocols and technologies utilized at designated seaports;

36(5) a description and assessment of the outcome of any security incident involving a foreign seaport designated under the Container Security Initiative;

37(6) the rationale for the continuance of each port designated under CSI;

38(7) a description of the potential for remote targeting to decrease the number of personnel who are deployed at foreign ports under CSI; and

39(8) a summary and assessment of the aggregate number and extent of trade compliance lapses at each seaport designated under the Container Security Initiative.

40There are authorized to be appropriated to the United States Customs and Border Protection to carry out the provisions of this section—

41(1) $144,000,000 for fiscal year 2008;

42(2) $146,000,000 for fiscal year 2009; and

43(3) $153,300,000 for fiscal year 2010.

961.

Establishment

1The Secretary, acting through the Commissioner, is authorized to establish a voluntary government-private sector program (to be known as the "Customs–Trade Partnership Against Terrorism" or "C–TPAT") to strengthen and improve the overall security of the international supply chain and United States border security, and to facilitate the movement of secure cargo through the international supply chain, by providing benefits to participants meeting or exceeding the program requirements. Participants in C–TPAT shall include Tier 1 participants, Tier 2 participants, and Tier 3 participants.

2The Secretary, acting through the Commissioner, shall review the minimum security requirements of C–TPAT at least once every year and update such requirements as necessary.

962.

Eligible entities

1Importers, customs brokers, forwarders, air, sea, land carriers, contract logistics providers, and other entities in the international supply chain and intermodal transportation system are eligible to apply to voluntarily enter into partnerships with the Department under C–TPAT.

963.

Minimum requirements

1An applicant seeking to participate in C–TPAT shall—

2(1) demonstrate a history of moving cargo in the international supply chain;

3(2) conduct an assessment of its supply chain based upon security criteria established by the Secretary, acting through the Commissioner, including—

4(A) business partner requirements;

5(B) container security;

6(C) physical security and access controls;

7(D) personnel security;

8(E) procedural security;

9(F) security training and threat awareness; and

10(G) information technology security;

11(3) implement and maintain security measures and supply chain security practices meeting security criteria established by the Commissioner; and

12(4) meet all other requirements established by the Commissioner, in consultation with the Commercial Operations Advisory Committee.

964.

Tier 1 participants in C–TPAT

1The Secretary, acting through the Commissioner, shall offer limited benefits to a Tier 1 participant who has been certified in accordance with the guidelines referred to in subsection (b). Such benefits may include a reduction in the score assigned pursuant to the Automated Targeting System of not greater than 20 percent of the high-risk threshold established by the Secretary.

2Not later than 180 days after October 13, 2006, the Secretary, acting through the Commissioner, shall update the guidelines for certifying a C–TPAT participant's security measures and supply chain security practices under this section. Such guidelines shall include a background investigation and extensive documentation review.

3To the extent practicable, the Secretary, acting through the Commissioner, shall complete the Tier 1 certification process within 90 days of receipt of an application for participation in C–TPAT.

965.

Tier 2 participants in C–TPAT

1The Secretary, acting through the Commissioner, shall validate the security measures and supply chain security practices of a Tier 1 participant in accordance with the guidelines referred to in subsection (c). Such validation shall include on-site assessments at appropriate foreign locations utilized by the Tier 1 participant in its supply chain and shall, to the extent practicable, be completed not later than 1 year after certification as a Tier 1 participant.

2The Secretary, acting through the Commissioner, shall extend benefits to each C–TPAT participant that has been validated as a Tier 2 participant under this section, which may include—

3(1) reduced scores in the Automated Targeting System;

4(2) reduced examinations of cargo; and

5(3) priority searches of cargo.

6Not later than 180 days after October 13, 2006, the Secretary, acting through the Commissioner, shall develop a schedule and update the guidelines for validating a participant's security measures and supply chain security practices under this section.

966.

Tier 3 participants in C–TPAT

1The Secretary, acting through the Commissioner, shall establish a third tier of C–TPAT participation that offers additional benefits to participants who demonstrate a sustained commitment to maintaining security measures and supply chain security practices that exceed the guidelines established for validation as a Tier 2 participant in C–TPAT under section 965 of this title.

2The Secretary, acting through the Commissioner, shall designate criteria for validating a C–TPAT participant as a Tier 3 participant under this section. Such criteria may include—

3(1) compliance with any additional guidelines established by the Secretary that exceed the guidelines established pursuant to section 965 of this title for validating a C–TPAT participant as a Tier 2 participant, particularly with respect to controls over access to cargo throughout the supply chain;

4(2) submission of additional information regarding cargo prior to loading, as determined by the Secretary;

5(3) utilization of container security devices, technologies, policies, or practices that meet standards and criteria established by the Secretary; and

6(4) compliance with any other cargo requirements established by the Secretary.

7The Secretary, acting through the Commissioner, in consultation with the Commercial Operations Advisory Committee and the National Maritime Security Advisory Committee, shall extend benefits to each C–TPAT participant that has been validated as a Tier 3 participant under this section, which may include—

8(1) the expedited release of a Tier 3 participant's cargo in destination ports within the United States during all threat levels designated by the Secretary;

9(2) further reduction in examinations of cargo;

10(3) priority for examinations of cargo; and

11(4) further reduction in the risk score assigned pursuant to the Automated Targeting System; and

12(5) inclusion in joint incident management exercises, as appropriate.

13Not later than 2 years after October 13, 2006, the Secretary, acting through the Commissioner, shall designate appropriate criteria pursuant to subsection (b) and provide benefits to validated Tier 3 participants pursuant to subsection (c).

967.

Consequences for lack of compliance

1If at any time a C–TPAT participant's security measures and supply chain security practices fail to meet any of the requirements under this part, the Commissioner may deny the participant benefits otherwise available under this part, in whole or in part. The Commissioner shall develop procedures that provide appropriate protections to C–TPAT participants before benefits are revoked. Such procedures may not limit the ability of the Commissioner to take actions to protect the national security of the United States.

2If a C–TPAT participant knowingly provides false or misleading information to the Commissioner during the validation process provided for under this part, the Commissioner shall suspend or expel the participant from C–TPAT for an appropriate period of time. The Commissioner, after the completion of the process under subsection (c), may publish in the Federal Register a list of participants who have been suspended or expelled from C–TPAT pursuant to this subsection, and may make such list available to C–TPAT participants.

3A C–TPAT participant may appeal a decision of the Commissioner pursuant to subsection (a). Such appeal shall be filed with the Secretary not later than 90 days after the date of the decision, and the Secretary shall issue a determination not later than 180 days after the appeal is filed.

4A C–TPAT participant may appeal a decision of the Commissioner pursuant to subsection (b). Such appeal shall be filed with the Secretary not later than 30 days after the date of the decision, and the Secretary shall issue a determination not later than 180 days after the appeal is filed.

968.

Third party validations

1The Secretary, acting through the Commissioner, shall develop a plan to implement a 1-year voluntary pilot program to test and assess the feasibility, costs, and benefits of using third party entities to conduct validations of C–TPAT participants.

2Not later than 120 days after October 13, 2006, after consulting with private sector stakeholders, including the Commercial Operations Advisory Committee, the Secretary shall submit a report to the appropriate congressional committees on the plan described in subsection (a).

3Not later than 1 year after the consultations described in subsection (b), the Secretary shall carry out the 1-year pilot program to conduct validations of C–TPAT participants using third party entities described in subsection (a).

4The decision to validate a C–TPAT participant is solely within the discretion of the Secretary, or the Secretary's designee.

5The Secretary shall certify a third party entity to conduct validations under subsection (c) if the entity—

6(1) demonstrates to the satisfaction of the Secretary that the entity has the ability to perform validations in accordance with standard operating procedures and requirements designated by the Secretary; and

7(2) agrees—

8(A) to perform validations in accordance with such standard operating procedures and requirements (and updates to such procedures and requirements); and

9(B) to maintain liability insurance coverage at policy limits and in accordance with conditions to be established by the Secretary; and

10(3) signs an agreement to protect all proprietary information of C–TPAT participants with respect to which the entity will conduct validations.

11A third party entity seeking a certificate under subsection (d) shall submit to the Secretary necessary information for establishing the limits of liability insurance required to be maintained by the entity under this Act.

12The Secretary shall ensure that—

13(1) any third party entity certified under this section does not have—

14(A) any beneficial interest in or any direct or indirect control over the C–TPAT participant for which the validation services are performed; or

15(B) any other conflict of interest with respect to the C–TPAT participant; and

16(2) the C–TPAT participant has entered into a contract with the third party entity under which the C–TPAT participant agrees to pay all costs associated with the validation.

17The Secretary shall regularly monitor and inspect the operations of a third party entity conducting validations under subsection (c) to ensure that the entity is meeting the minimum standard operating procedures and requirements for the validation of C–TPAT participants established by the Secretary and all other applicable requirements for validation services.

18If the Secretary determines that a third party entity is not meeting the minimum standard operating procedures and requirements designated by the Secretary under subsection (d)(1), the Secretary shall—

19(A) revoke the entity's certificate of conformance issued under subsection (d)(1); and

20(B) review any validations conducted by the entity.

21The Secretary may only grant a C–TPAT validation by a third party entity pursuant to subsection (c) if the C–TPAT participant voluntarily submits to validation by such third party entity.

22Not later than 30 days after the completion of the pilot program conducted pursuant to subsection (c), the Secretary shall submit a report to the appropriate congressional committees that contains—

23(1) the results of the pilot program, including the extent to which the pilot program ensured sufficient protection for proprietary commercial information;

24(2) the cost and efficiency associated with validations under the pilot program;

25(3) the impact of the pilot program on the rate of validations conducted under C–TPAT;

26(4) any impact on national security of the pilot program; and

27(5) any recommendations by the Secretary based upon the results of the pilot program.

969.

Revalidation

1The Secretary, acting through the Commissioner, shall develop and implement—

2(1) a revalidation process for Tier 2 and Tier 3 participants;

3(2) a framework based upon objective criteria for identifying participants for periodic revalidation not less frequently than once during each 4-year period following the initial validation; and

4(3) an annual plan for revalidation that includes—

5(A) performance measures;

6(B) an assessment of the personnel needed to perform the revalidations; and

7(C) the number of participants that will be revalidated during the following year.

970.

Noncontainerized cargo

1The Secretary, acting through the Commissioner, shall consider the potential for participation in C–TPAT by importers of noncontainerized cargoes that otherwise meet the requirements under this part.

971.

C–TPAT program management

1The Secretary, acting through the Commissioner, shall establish sufficient internal quality controls and record management to support the management systems of C–TPAT. In managing the program, the Secretary shall ensure that the program includes:

2A 5-year plan to identify outcome-based goals and performance measures of the program.

3An annual plan for each fiscal year designed to match available resources to the projected workload.

4A standardized work program to be used by agency personnel to carry out the certifications, validations, and revalidations of participants. The Secretary shall keep records and monitor staff hours associated with the completion of each such review.

5The Secretary, acting through the Commissioner, shall maintain a record management system to document determinations on the reviews of each C–TPAT participant, including certifications, validations, and revalidations.

6In consultation with the Commercial Operations Advisory Committee, the Secretary, acting through the Commissioner, shall develop and implement procedures to ensure the protection of confidential data collected, stored, or shared with government agencies or as part of the application, certification, validation, and revalidation processes.

7The Secretary, acting through the Commissioner, shall—

8(1) develop a staffing plan to recruit and train staff (including a formalized training program) to meet the objectives identified in the strategic plan of the C–TPAT program; and

9(2) provide cross-training in postincident trade resumption for personnel who administer the C–TPAT program.

10In connection with the President's annual budget submission for the Department, the Secretary shall report to the appropriate congressional committees on the progress made by the Commissioner to certify, validate, and revalidate C–TPAT participants. Such report shall be due on the same date that the President's budget is submitted to the Congress.

972.

Additional personnel

1For fiscal years 2008 and 2009, the Commissioner shall increase by not less than 50 the number of full-time personnel engaged in the validation and revalidation of C–TPAT participants (over the number of such personnel on the last day of the previous fiscal year), and shall provide appropriate training and support to such additional personnel.

973.

Authorization of appropriations

1There are authorized to be appropriated to the United States Customs and Border Protection to carry out the provisions of sections 961 through 971 of this title to remain available until expended—

2(1) $65,000,000 for fiscal year 2008;

3(2) $72,000,000 for fiscal year 2009; and

4(3) $75,600,000 for fiscal year 2010.

5In addition to any amounts otherwise appropriated to the United States Customs and Border Protection, there are authorized to be appropriated for the purpose of meeting the staffing requirement provided for in section 972 of this title, to remain available until expended—

6(1) $8,500,000 for fiscal year 2008;

7(2) $17,600,000 for fiscal year 2009;

8(3) $19,000,000 for fiscal year 2010;

9(4) $20,000,000 for fiscal year 2011; and

10(5) $21,000,000 for fiscal year 2012.

981.

Pilot integrated scanning system

1Not later than 90 days after October 13, 2006, the Secretary shall designate 3 foreign seaports through which containers pass or are transshipped to the United States for the establishment of pilot integrated scanning systems that couple nonintrusive imaging equipment and radiation detection equipment. In making the designations under this subsection, the Secretary shall consider 3 distinct ports with unique features and differing levels of trade volume.

2The Secretary shall—

3(1) coordinate with the Secretary of Energy, as necessary, to provide radiation detection equipment through the Department of Energy's Second Line of Defense and Megaports programs; or

4(2) work with the private sector or, when possible, host governments to obtain radiation detection equipment that meets both the Department's and the Department of Energy's technical specifications for such equipment.

5Not later than 1 year after October 13, 2006, the Secretary shall achieve a full-scale implementation of the pilot integrated scanning system at the ports designated under subsection (a), which—

6(1) shall scan all containers destined for the United States that are loaded in such ports;

7(2) shall electronically transmit the images and information to appropriate United States Government personnel in the country in which the port is located or in the United States for evaluation and analysis;

8(3) shall resolve every radiation alarm according to established Department procedures;

9(4) shall utilize the information collected to enhance the Automated Targeting System or other relevant programs;

10(5) shall store the information for later retrieval and analysis; and

11(6) may provide an automated notification of questionable or high-risk cargo as a trigger for further inspection by appropriately trained personnel.

12Not later than 180 days after achieving full-scale implementation under subsection (c), the Secretary, in consultation with the Secretary of State and, as appropriate, the Secretary of Energy, shall submit a report to the appropriate congressional committees, that includes—

13(1) an evaluation of the lessons derived from the pilot system implemented under this subsection;

14(2) an analysis of the efficacy of the Automated Targeting System or other relevant programs in utilizing the images captured to examine high-risk containers;

15(3) an evaluation of the effectiveness of the integrated scanning system in detecting shielded and unshielded nuclear and radiological material;

16(4) an evaluation of software and other technologies that are capable of automatically identifying potential anomalies in scanned containers; and

17(5) an analysis of the need and feasibility of expanding the integrated scanning system to other container security initiative ports, including—

18(A) an analysis of the infrastructure requirements;

19(B) a projection of the effect on current average processing speed of containerized cargo;

20(C) an evaluation of the scalability of the system to meet both current and future forecasted trade flows;

21(D) the ability of the system to automatically maintain and catalog appropriate data for reference and analysis in the event of a transportation disruption;

22(E) an analysis of requirements, including costs, to install and maintain an integrated scanning system;

23(F) the ability of administering personnel to efficiently manage and utilize the data produced by a nonintrusive scanning system;

24(G) the ability to safeguard commercial data generated by, or submitted to, a nonintrusive scanning system; and

25(H) an assessment of the reliability of currently available technology to implement an integrated scanning system.

981a.

Pilot integrated scanning system

1Not later than 90 days after October 4, 2006, the Secretary of Homeland Security (referred to in this section as the "Secretary") shall designate three foreign seaports through which containers pass or are transshipped to the United States to pilot an integrated scanning system that couples nonintrusive imaging equipment and radiation detection equipment, which may be provided by the Megaports Initiative of the Department of Energy. In making designations under this subsection, the Secretary shall consider three distinct ports with unique features and differing levels of trade volume.

2The Secretary shall collaborate with the Secretary of Energy and cooperate with the private sector and host foreign government to implement the pilot program under this subsection.

3Not later than one year after October 4, 2006, the Secretary shall achieve a full-scale implementation of the pilot integrated screening system, which shall—

4(1) scan all containers destined for the United States that transit through the terminal;

5(2) electronically transmit the images and information to the container security initiative personnel in the host country and/or Customs and Border Protection personnel in the United States for evaluation and analysis;

6(3) resolve every radiation alarm according to established Department procedures;

7(4) utilize the information collected to enhance the Automated Targeting System or other relevant programs; and

8(5) store the information for later retrieval and analysis.

9The Secretary shall evaluate the pilot program in subsection (b) to determine whether such a system—

10(1) has a sufficiently low false alarm rate for use in the supply chain;

11(2) is capable of being deployed and operated at ports overseas, including consideration of cost, personnel, and infrastructure required to operate the system;

12(3) is capable of integrating, where necessary, with existing systems;

13(4) does not significantly impact trade capacity and flow of cargo at foreign or United States ports; and

14(5) provides an automated notification of questionable or high-risk cargo as a trigger for further inspection by appropriately trained personnel.

15Not later than 120 days after achieving full-scale implementation under subsection (b), the Secretary, in consultation with the Secretary of Energy and the Secretary of State, shall submit a report, to the appropriate congressional committees, that includes—

16(1) an evaluation of the lessons derived from the pilot program implemented under this section;

17(2) an analysis of the efficacy of the Automated Targeted System or other relevant programs in utilizing the images captured to examine high-risk containers;

18(3) an evaluation of software that is capable of automatically identifying potential anomalies in scanned containers; and

19(4) a plan and schedule to expand the integrated scanning system developed under this section to other container security initiative ports.

20If the Secretary determines the available technology meets the criteria outlined in subsection (c), the Secretary, in cooperation with the Secretary of State, shall seek to secure the cooperation of foreign governments to initiate and maximize the use of such technology at foreign ports to scan all cargo bound for the United States as quickly as possible.

982.

Screening and scanning of cargo containers

1The Secretary shall ensure that 100 percent of the cargo containers originating outside the United States and unloaded at a United States seaport undergo a screening to identify high-risk containers.

2The Secretary shall ensure that 100 percent of the containers that have been identified as high-risk under paragraph (1), or through other means, are scanned or searched before such containers leave a United States seaport facility.

3A container that was loaded on a vessel in a foreign port shall not enter the United States (either directly or via a foreign port) unless the container was scanned by nonintrusive imaging equipment and radiation detection equipment at a foreign port before it was loaded on a vessel.

4Paragraph (1) shall apply with respect to containers loaded on a vessel in a foreign country on or after the earlier of—

5(A) July 1, 2012; or

6(B) such other date as may be established by the Secretary under paragraph (3).

7The Secretary shall establish a date under (2)(B) 1 pursuant to the lessons learned through the pilot integrated scanning systems established under section 981 of this title.

8The Secretary may extend the date specified in paragraph (2)(A) or (2)(B) for 2 years, and may renew the extension in additional 2-year increments, for containers loaded in a port or ports, if the Secretary certifies to Congress that at least two of the following conditions exist:

9(A) Systems to scan containers in accordance with paragraph (1) are not available for purchase and installation.

10(B) Systems to scan containers in accordance with paragraph (1) do not have a sufficiently low false alarm rate for use in the supply chain.

11(C) Systems to scan containers in accordance with paragraph (1) cannot be purchased, deployed, or operated at ports overseas, including, if applicable, because a port does not have the physical characteristics to install such a system.

12(D) Systems to scan containers in accordance with paragraph (1) cannot be integrated, as necessary, with existing systems.

13(E) Use of systems that are available to scan containers in accordance with paragraph (1) will significantly impact trade capacity and the flow of cargo.

14(F) Systems to scan containers in accordance with paragraph (1) do not adequately provide an automated notification of questionable or high-risk cargo as a trigger for further inspection by appropriately trained personnel.

15Notwithstanding any other provision in the section, supplies bought by the Secretary of Defense and transported in compliance section 2631 of title 10 and military cargo of foreign countries are exempt from the requirements of this section.

16An extension under paragraph (4) for a port or ports shall take effect upon the expiration of the 60-day period beginning on the date the Secretary provides a report to Congress that—

17(A) states what container traffic will be affected by the extension;

18(B) provides supporting evidence to support the Secretary's certification of the basis for the extension; and

19(C) explains what measures the Secretary is taking to ensure that scanning can be implemented as early as possible at the port or ports that are the subject of the report.

20If an extension under paragraph (4) takes effect, the Secretary shall, after one year, submit a report to Congress on whether the Secretary expects to seek to renew the extension.

21In implementing paragraph (1), the Secretary shall—

22(A) establish technological and operational standards for systems to scan containers;

23(B) ensure that the standards are consistent with the global nuclear detection architecture developed under the Homeland Security Act of 2002 [6 U.S.C. 101 et seq.]; and

24(C) coordinate with other Federal agencies that administer scanning or detection programs at foreign ports.

25In carrying out this subsection, the Secretary shall consult with appropriate Federal departments and agencies and private sector stakeholders, and ensure that actions under this section do not violate international trade obligations, and are consistent with the World Customs Organization framework, or other international obligations of the United States.

26Not later than 6 months after the submission of a report under section 981(d) of this title, and every 6 months thereafter, the Secretary shall submit a report to the appropriate congressional committees describing the status of full-scale deployment under subsection (b) and the cost of deploying the system at each foreign port at which the integrated scanning systems are deployed.

983.

Inspection technology and training

1The Secretary, in coordination with the Secretary of State, the Secretary of Energy, and appropriate representatives of other Federal agencies, may provide technical assistance, equipment, and training to facilitate the implementation of supply chain security measures at ports designated under the Container Security Initiative.

2Unless otherwise prohibited by law, the Secretary may—

3(1) lease, loan, provide, or otherwise assist in the deployment of nonintrusive inspection and radiation detection equipment at foreign land and sea ports under such terms and conditions as the Secretary prescribes, including nonreimbursable loans or the transfer of ownership of equipment; and

4(2) provide training and technical assistance for domestic or foreign personnel responsible for operating or maintaining such equipment.

984.

Repealed. Pub. L. 115–254, div. J, §1816(f), Oct. 5, 2018, 132 Stat. 3541

985.

Information sharing relating to supply chain security cooperation

1The purposes of this section are—

2(1) to establish continuing liaison and to provide for supply chain security cooperation between Department and the private sector; and

3(2) to provide for regular and timely interchange of information between the private sector and the Department concerning developments and security risks in the supply chain environment.

4The Secretary shall develop a system to collect from and share appropriate risk information related to the supply chain with the private sector entities determined appropriate by the Secretary.

5In developing the system under subsection (b), the Secretary shall consult with the Commercial Operations Advisory Committee and a broad range of public and private sector entities likely to utilize the system, including importers, exporters, carriers, customs brokers, and freight forwarders, among other parties.

6Nothing in this section shall be construed to limit or otherwise affect the ability of a Federal, State, or local government entity, under applicable law, to obtain supply chain security information, including any information lawfully and properly disclosed generally or broadly to the public and to use such information in any manner permitted by law.

7The Secretary may provide advisories, alerts, and warnings to relevant companies, targeted sectors, other governmental entities, or the general public regarding potential risks to the supply chain as appropriate. In issuing a warning, the Secretary shall take appropriate actions to protect from disclosure—

8(1) the source of any voluntarily submitted supply chain security information that forms the basis for the warning; and

9(2) information that is proprietary, business sensitive, relates specifically to the submitting person or entity, or is otherwise not appropriately in the public domain.

1001.

Designation of liaison office of Department of State

1The Secretary of State shall designate a liaison office within the Department of State to assist the Secretary, as appropriate, in negotiating cargo security-related international agreements.

1002.

Homeland Security Science and Technology Advisory Committee

1The Under Secretary for Science and Technology shall utilize the Homeland Security Science and Technology Advisory Committee, as appropriate, to provide outside expertise in advancing cargo security technology.

1003.

Research, development, test, and evaluation efforts in furtherance of maritime and cargo security

1The Secretary shall—

2(1) direct research, development, testing, and evaluation efforts in furtherance of maritime and cargo security;

3(2) coordinate with public and private sector entities to develop and test technologies, and process innovations in furtherance of these objectives; and

4(3) evaluate such technologies.

5The Secretary, in coordination with the Under Secretary for Science and Technology, the Assistant Secretary for Policy, the Commandant of the Coast Guard, the Director for Domestic Nuclear Detection,1 the Chief Financial Officer, and the heads of other appropriate offices or entities of the Department, shall ensure that—

6(1) research, development, testing, and evaluation efforts funded by the Department in furtherance of maritime and cargo security are coordinated within the Department and with other appropriate Federal agencies to avoid duplication of efforts; and

7(2) the results of such efforts are shared throughout the Department and with other Federal, State, and local agencies, as appropriate.

CHAPTER 4—TRANSPORTATION SECURITY

1101.

Definitions

1For purposes of this subchapter, the following terms apply:

2The term "Department" means the Department of Homeland Security.

3The term "Secretary" means the Secretary of Homeland Security.

1102.

National Domestic Preparedness Consortium

1The Secretary is authorized to establish, operate, and maintain a National Domestic Preparedness Consortium within the Department.

2Members of the National Domestic Preparedness Consortium shall consist of—

3(1) the Center for Domestic Preparedness;

4(2) the National Energetic Materials Research and Testing Center, New Mexico Institute of Mining and Technology;

5(3) the National Center for Biomedical Research and Training, Louisiana State University;

6(4) the National Emergency Response and Rescue Training Center, Texas A&M University;

7(5) the National Exercise, Test, and Training Center, Nevada Test Site;

8(6) the Transportation Technology Center, Incorporated, in Pueblo, Colorado; and

9(7) the National Disaster Preparedness Training Center, University of Hawaii.

10The National Domestic Preparedness Consortium shall identify, develop, test, and deliver training to State, local, and tribal emergency response providers, provide on-site and mobile training at the performance and management and planning levels, and facilitate the delivery of training by the training partners of the Department.

11There are authorized to be appropriated to the Secretary—

12(1) for the Center for Domestic Preparedness—

13(A) $57,000,000 for fiscal year 2008;

14(B) $60,000,000 for fiscal year 2009;

15(C) $63,000,000 for fiscal year 2010; and

16(D) $66,000,000 for fiscal year 2011; and

17(2) for the National Energetic Materials Research and Testing Center, the National Center for Biomedical Research and Training, the National Emergency Response and Rescue Training Center, the National Exercise, Test, and Training Center, the Transportation Technology Center, Incorporated, and the National Disaster Preparedness Training Center each—

18(A) $22,000,000 for fiscal year 2008;

19(B) $23,000,000 for fiscal year 2009;

20(C) $24,000,000 for fiscal year 2010; and

21(D) $25,500,000 for fiscal year 2011.

22From the amounts appropriated pursuant to this section, the Secretary shall ensure that future amounts provided to each of the following entities are not less than the amounts provided to each such entity for participation in the Consortium in fiscal year 2007—

23(1) the Center for Domestic Preparedness;

24(2) the National Energetic Materials Research and Testing Center, New Mexico Institute of Mining and Technology;

25(3) the National Center for Biomedical Research and Training, Louisiana State University;

26(4) the National Emergency Response and Rescue Training Center, Texas A&M University; and

27(5) the National Exercise, Test, and Training Center, Nevada Test Site.

1103.

National Transportation Security Center of Excellence

1The Secretary shall establish a National Transportation Security Center of Excellence to conduct research and education activities, and to develop or provide professional security training, including the training of transportation employees and transportation professionals.

2The Secretary shall select one of the institutions identified in subsection (c) as the lead institution responsible for coordinating the National Transportation Security Center of Excellence.

3The institution of higher education selected under subsection (b) shall execute agreements with the other institutions of higher education identified in this subsection and other institutions designated by the Secretary to develop a consortium to assist in accomplishing the goals of the Center.

4The National Transportation Security Center of Excellence shall consist of—

5(A) Texas Southern University in Houston, Texas;

6(B) the National Transit Institute at Rutgers, The State University of New Jersey;

7(C) Tougaloo College;

8(D) the Connecticut Transportation Institute at the University of Connecticut;

9(E) the Homeland Security Management Institute, Long Island University;

10(F) the Mack-Blackwell National Rural Transportation Study Center at the University of Arkansas; and

11(G) any additional institutions or facilities designated by the Secretary.

12To the extent practicable, the Secretary shall ensure that an appropriate number of any additional consortium colleges or universities designated by the Secretary under this subsection are Historically Black Colleges and Universities, Hispanic Serving Institutions, and Indian Tribally Controlled Colleges and Universities.

13There are authorized to be appropriated to carry out this section—

14(1) $18,000,000 for fiscal year 2008;

15(2) $18,000,000 for fiscal year 2009;

16(3) $18,000,000 for fiscal year 2010; and

17(4) $18,000,000 for fiscal year 2011.

1104.

Immunity for reports of suspected terrorist activity or suspicious behavior and response

1Any person who, in good faith and based on objectively reasonable suspicion, makes, or causes to be made, a voluntary report of covered activity to an authorized official shall be immune from civil liability under Federal, State, and local law for such report.

2Paragraph (1) shall not apply to any report that the person knew to be false or was made with reckless disregard for the truth at the time that person made that report.

3Any authorized official who observes, or receives a report of, covered activity and takes reasonable action in good faith to respond to such activity shall have qualified immunity from civil liability for such action, consistent with applicable law in the relevant jurisdiction. An authorized official as defined by subsection (d)(1)(A) not entitled to assert the defense of qualified immunity shall nevertheless be immune from civil liability under Federal, State, and local law if such authorized official takes reasonable action, in good faith, to respond to the reported activity.

4Nothing in this subsection shall affect the ability of any authorized official to assert any defense, privilege, or immunity that would otherwise be available, and this subsection shall not be construed as affecting any such defense, privilege, or immunity.

5Any person or authorized official found to be immune from civil liability under this section shall be entitled to recover from the plaintiff all reasonable costs and attorney fees.

6In this section:

7The term "authorized official" means—

8(A) any employee or agent of a passenger transportation system or other person with responsibilities relating to the security of such systems;

9(B) any officer, employee, or agent of the Department of Homeland Security, the Department of Transportation, or the Department of Justice with responsibilities relating to the security of passenger transportation systems; or

10(C) any Federal, State, or local law enforcement officer.

11The term "covered activity" means any suspicious transaction, activity, or occurrence that involves, or is directed against, a passenger transportation system or vehicle or its passengers indicating that an individual may be engaging, or preparing to engage, in a violation of law relating to—

12(A) a threat to a passenger transportation system or passenger safety or security; or

13(B) an act of terrorism (as that term is defined in section 3077 of title 18).

14The term "passenger transportation" means—

15(A) public transportation, as defined in section 5302 of title 49;

16(B) over-the-road bus transportation, as defined in subchapter IV, and school bus transportation;

17(C) intercity passenger rail 1 transportation 2 as defined in section 24102 of title 49;

18(D) the transportation of passengers onboard a passenger vessel 2 as defined in section 2101 of title 46;

19(E) other regularly scheduled waterborne transportation service of passengers by vessel of at least 20 gross tons; and

20(F) air transportation, as defined in section 40102 of title 49, of passengers.

21The term "passenger transportation system" means an entity or entities organized to provide passenger transportation using vehicles, including the infrastructure used to provide such transportation.

22The term "vehicle" has the meaning given to that term in section 1992(16) 3 of title 18.

23This section shall take effect on October 1, 2006, and shall apply to all activities and claims occurring on or after such date.

1111.

Definitions

1For purposes of this subchapter, the following terms apply:

2The term "appropriate congressional committees" means the Committee on Commerce, Science, and Transportation, the Committee on Banking, Housing, and Urban Affairs, and the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Transportation and Infrastructure of the House of Representatives.

3The term "Department" means the Department of Homeland Security.

4The term "Secretary" means the Secretary of Homeland Security.

5The term "State" means any one of the 50 States, the District of Columbia, Puerto Rico, the Northern Mariana Islands, the Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.

6The term "terrorism" has the meaning that term has in section 101 of this title.

7The term "United States" means the 50 States, the District of Columbia, Puerto Rico, the Northern Mariana Islands, the Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.

1112.

Authorization of Visible Intermodal Prevention and Response teams

1The Secretary, acting through the Administrator of the Transportation Security Administration, may develop Visible Intermodal Prevention and Response (referred to in this section as "VIPR") teams to augment the security of any mode of transportation at any location within the United States. In forming a VIPR team, the Secretary—

2(1) may use any asset of the Department, including Federal air marshals, surface transportation security inspectors, canine detection teams, and advanced screening technology;

3(2) may determine when a VIPR team shall be deployed, as well as the duration of the deployment;

4(3) shall, prior to and during the deployment, consult with local security and law enforcement officials in the jurisdiction where the VIPR team is or will be deployed, to develop and agree upon the appropriate operational protocols and provide relevant information about the mission of the VIPR team, as appropriate;

5(4) shall, prior to and during the deployment, consult with all transportation entities directly affected by the deployment of a VIPR team as to specific locations and times within the facilities of such entities at which VIPR teams are to be deployed to maximize the effectiveness of such deployment, as appropriate, including railroad carriers, air carriers, airport owners, over-the-road bus operators and terminal owners and operators, motor carriers, public transportation agencies, owners or operators of highways, port operators and facility owners, vessel owners and operators and pipeline operators; and

6(5) shall require, as appropriate based on risk, in the case of a VIPR team deployed to an airport, that the VIPR team conduct operations—

7(A) in the sterile area and any other areas to which only individuals issued security credentials have unescorted access; and

8(B) in nonsterile areas.

9Not later than 1 year after October 5, 2018, the Administrator shall develop and implement a system of qualitative performance measures and objectives by which to assess the roles, activities, and effectiveness of VIPR team operations on an ongoing basis, including a mechanism through which the transportation entities referred to in subsection (a)(4) may submit feedback on VIPR team operations involving their systems or facilities.

10Not later than 1 year after October 5, 2018, the Administrator shall develop and implement a plan for ensuring the interoperability of communications among VIPR team participants and between VIPR teams and any transportation entities with systems or facilities that are involved in VIPR team operations. Such plan shall include an analysis of the costs and resources required to carry out such plan.

1113.

Surface transportation security inspectors

1The Secretary, acting through the Administrator of the Transportation Security Administration, is authorized to train, employ, and utilize surface transportation security inspectors.

2The Secretary shall use surface transportation security inspectors to assist surface transportation carriers, operators, owners, entities, and facilities to enhance their security against terrorist attack and other security threats and to assist the Secretary in enforcing applicable surface transportation security regulations and directives.

3Surface transportation security inspectors employed pursuant to this section shall be authorized such powers and delegated such responsibilities as the Secretary determines appropriate, subject to subsection (e).

4The Secretary shall require that surface transportation security inspectors have relevant transportation experience and other security and inspection qualifications, as determined appropriate.

5Surface transportation inspectors shall be prohibited from issuing fines to public transportation agencies, as defined in subchapter III, for violations of the Department's regulations or orders except through the process described in paragraph (2).

6The Secretary shall be prohibited from assessing civil penalties against public transportation agencies, as defined in subchapter III, for violations of the Department's regulations or orders, except in accordance with the following:

7(A) In the case of a public transportation agency that is found to be in violation of a regulation or order issued by the Secretary, the Secretary shall seek correction of the violation through a written notice to the public transportation agency and shall give the public transportation agency reasonable opportunity to correct the violation or propose an alternative means of compliance acceptable to the Secretary.

8(B) If the public transportation agency does not correct the violation or propose an alternative means of compliance acceptable to the Secretary within a reasonable time period that is specified in the written notice, the Secretary may take any action authorized in section 114 of title 49.

9The Secretary shall not initiate civil enforcement actions for violations of administrative and procedural requirements pertaining to the application for, and expenditure of, funds awarded under transportation security grant programs under this Act.

10The Secretary shall employ up to a total of—

11(1) 100 surface transportation security inspectors in fiscal year 2007;

12(2) 150 surface transportation security inspectors in fiscal year 2008;

13(3) 175 surface transportation security inspectors in fiscal year 2009; and

14(4) 200 surface transportation security inspectors in fiscal years 2010 and 2011.

15The Secretary shall ensure that the mission of the surface transportation security inspectors is consistent with any relevant risk assessments required by this Act or completed by the Department, the modal plans required under section 114(t) 1 of title 49, the Memorandum of Understanding between the Department and the Department of Transportation on Roles and Responsibilities, dated September 28, 2004, and any and all subsequent annexes to this Memorandum of Understanding, and other relevant documents setting forth the Department's transportation security strategy, as appropriate.

16The Secretary shall periodically consult with the surface transportation entities which are or may be inspected by the surface transportation security inspectors, including, as appropriate, railroad carriers, over-the-road bus operators and terminal owners and operators, motor carriers, public transportation agencies, owners or operators of highways, and pipeline operators on—

17(1) the inspectors' duties, responsibilities, authorities, and mission; and

18(2) strategies to improve transportation security and to ensure compliance with transportation security requirements.

19Not later than September 30, 2008, the Department of Homeland Security Inspector General shall transmit a report to the appropriate congressional committees on the performance and effectiveness of surface transportation security inspectors, whether there is a need for additional inspectors, and other recommendations.

20There are authorized to be appropriated to the Secretary to carry out this section—

21(1) $11,400,000 for fiscal year 2007;

22(2) $17,100,000 for fiscal year 2008;

23(3) $19,950,000 for fiscal year 2009;

24(4) $22,800,000 for fiscal year 2010; and

25(5) $22,800,000 for fiscal year 2011.

1114.

Surface transportation security technology information sharing

1The Secretary, in consultation with the Secretary of Transportation, shall establish a program to provide appropriate information that the Department has gathered or developed on the performance, use, and testing of technologies that may be used to enhance railroad, public transportation, and surface transportation security to surface transportation entities, including railroad carriers, over-the-road bus operators and terminal owners and operators, motor carriers, public transportation agencies, owners or operators of highways, pipeline operators, and State, local, and tribal governments that provide security assistance to such entities.

2The Secretary shall include in such information provided in paragraph (1) whether the technology is designated as a qualified antiterrorism technology under the Support Anti-terrorism by Fostering Effective Technologies Act of 2002 (Public Law 107–296) [6 U.S.C. 441 et seq.], as appropriate.

3The purpose of the program is to assist eligible grant recipients under this Act and others, as appropriate, to purchase and use the best technology and equipment available to meet the security needs of the Nation's surface transportation system.

4The Secretary shall ensure that the program established under this section makes use of and is consistent with other Department technology testing, information sharing, evaluation, and standards-setting programs, as appropriate.

1115.

TSA personnel limitations

1Any statutory limitation on the number of employees in the Transportation Security Administration does not apply to employees carrying out this chapter.

1116.

National explosives detection canine team training program

1For purposes of this section, the term "explosives detection canine team" means a canine and a canine handler that are trained to detect explosives, radiological materials, chemical, nuclear or biological weapons, or other threats as defined by the Secretary.

2Not later than 180 days after August 3, 2007, the Secretary of Homeland Security shall—

3(A) begin to increase the number of explosives detection canine teams certified by the Transportation Security Administration for the purposes of transportation-related security by up to 200 canine teams annually by the end of 2010; and

4(B) encourage State, local, and tribal governments and private owners of high-risk transportation facilities to strengthen security through the use of highly trained explosives detection canine teams.

5The Secretary of Homeland Security shall increase the number of explosives detection canine teams by—

6(A) using the Transportation Security Administration's National Explosives Detection Canine Team Training Center, including expanding and upgrading existing facilities, procuring and breeding additional canines, and increasing staffing and oversight commensurate with the increased training and deployment capabilities;

7(B) partnering with other Federal, State, or local agencies, nonprofit organizations, universities, or the private sector to increase the training capacity for canine detection teams;

8(C) procuring explosives detection canines trained by nonprofit organizations, universities, or the private sector provided they are trained in a manner consistent with the standards and requirements developed pursuant to subsection (c) or other criteria developed by the Secretary; or

9(D) a combination of subparagraphs (A), (B), and (C), as appropriate.

10Based on the feasibility in meeting the ongoing demand for quality explosives detection canine teams, the Secretary shall establish criteria, including canine training curricula, performance standards, and other requirements approved by the Transportation Security Administration necessary to ensure that explosives detection canine teams trained by nonprofit organizations, universities, and private sector entities are adequately trained and maintained.

11In developing and implementing such curriculum, performance standards, and other requirements, the Secretary shall—

12(A) coordinate with key stakeholders, including international, Federal, State, and local officials, and private sector and academic entities to develop best practice guidelines for such a standardized program, as appropriate;

13(B) require that explosives detection canine teams trained by nonprofit organizations, universities, or private sector entities that are used or made available by the Secretary be trained consistent with specific training criteria developed by the Secretary; and

14(C) review the status of the private sector programs on at least an annual basis to ensure compliance with training curricula, performance standards, and other requirements.

15The Secretary shall—

16(1) use the additional explosives detection canine teams as part of the Department's efforts to strengthen security across the Nation's transportation network, and may use the canine teams on a more limited basis to support other homeland security missions, as determined appropriate by the Secretary;

17(2) make available explosives detection canine teams to all modes of transportation, for high-risk areas or to address specific threats, on an as-needed basis and as otherwise determined appropriate by the Secretary;

18(3) encourage, but not require, any transportation facility or system to deploy TSA-certified explosives detection canine teams developed under this section; and

19(4) consider specific needs and training requirements for explosives detection canine teams to be deployed across the Nation's transportation network, including in venues of multiple modes of transportation, as appropriate.

20The Secretary, acting through the Administrator of the Transportation Security Administration, shall work to ensure that explosives detection canine teams are procured as efficiently as possible and at the best price, while maintaining the needed level of quality, including, if appropriate, through increased domestic breeding.

21Not later than 1 year after August 3, 2007, the Comptroller General shall report to the appropriate congressional committees on the utilization of explosives detection canine teams to strengthen security and the capacity of the national explosive detection canine team program.

22There are authorized to be appropriated to the Secretary such sums as may be necessary to carry out this section for fiscal years 2007 through 2011.

23In order to enhance the screening of air cargo and ensure that third party explosives detection canine assets are leveraged for such purpose, the Administrator shall, not later than 180 days after October 5, 2018—

24(A) develop and issue standards for the use of such third party explosives detection canine assets for the primary screening of air cargo;

25(B) develop a process to identify qualified non-Federal entities that will certify canine assets that meet the standards established by the Administrator under subparagraph (A);

26(C) ensure that entities qualified to certify canine assets shall be independent from entities that will train and provide canines to end users of such canine assets;

27(D) establish a system of Transportation Security Administration audits of the process developed under subparagraph (B); and

28(E) provide that canines certified for the primary screening of air cargo can be used by air carriers, foreign air carriers, freight forwarders, and shippers.

29Beginning on the date that the development of the process under paragraph (1)(B) is complete, the Administrator shall—

30(A) facilitate the deployment of such assets that meet the certification standards of the Administration, as determined by the Administrator;

31(B) make such standards available to vendors seeking to train and deploy third party explosives detection canine assets; and

32(C) ensure that all costs for the training and certification of canines, and for the use of supplied canines, are borne by private industry and not the Federal Government.

33In this subsection:

34The term "air carrier" has the meaning given the term in section 40102 of title 49.

35The term "foreign air carrier" has the meaning given the term in section 40102 of title 49.

36The term "third party explosives detection canine asset" means any explosives detection canine or handler not owned or employed, respectively, by the Transportation Security Administration.

1117.

Roles of the Department of Homeland Security and the Department of Transportation

1The Secretary of Homeland Security is the principal Federal official responsible for transportation security. The roles and responsibilities of the Department of Homeland Security and the Department of Transportation in carrying out this chapter are the roles and responsibilities of such Departments pursuant to the Aviation and Transportation Security Act (Public Law 107–71); the Intelligence Reform and Terrorism Prevention Act of 2004 (Public Law 108–458); the National Infrastructure Protection Plan required by Homeland Security Presidential Directive–7; The 1 Homeland Security Act of 2002 [6 U.S.C. 101 et seq.]; The 1 National Response Plan; Executive Order No. 13416: Strengthening Surface Transportation Security, dated December 5, 2006; the Memorandum of Understanding between the Department and the Department of Transportation on Roles and Responsibilities, dated September 28, 2004, and any and all subsequent annexes to this Memorandum of Understanding; and any other relevant agreements between the two Departments.

1118.

Biometrics expansion

1The Administrator and the Commissioner of U.S. Customs and Border Protection shall consult with each other on the deployment of biometric technologies.

2Nothing in this section shall be construed to permit the Commissioner of U.S. Customs and Border Protection to facilitate or expand the deployment of biometric technologies, or otherwise collect, use, or retain biometrics, not authorized by any provision of or amendment made by the Intelligence Reform and Terrorism Prevention Act of 2004 (Public Law 108–458; 118 Stat. 3638) or the Implementing Recommendations of the 9/11 Commission Act of 2007 (Public Law 110–53; 121 Stat. 266).

3Not later than 270 days after October 5, 2018, the Secretary shall submit to the appropriate committees of Congress, and to any Member of Congress upon the request of that Member, a report that includes specific assessments from the Administrator and the Commissioner of U.S. Customs and Border Protection with respect to the following:

4(1) The operational and security impact of using biometric technology to identify travelers.

5(2) The potential effects on privacy of the expansion of the use of biometric technology under paragraph (1), including methods proposed or implemented to mitigate any risks to privacy identified by the Administrator or the Commissioner related to the active or passive collection of biometric data.

6(3) Methods to analyze and address any matching performance errors related to race, gender, or age identified by the Administrator with respect to the use of biometric technology, including the deployment of facial recognition technology; 1

7(4) With respect to the biometric entry-exit program, the following:

8(A) Assessments of—

9(i) the error rates, including the rates of false positives and false negatives, and accuracy of biometric technologies;

10(ii) the effects of biometric technologies, to ensure that such technologies do not unduly burden categories of travelers, such as a certain race, gender, or nationality;

11(iii) the extent to which and how biometric technologies could address instances of travelers to the United States overstaying their visas, including—

12(I) an estimate of how often biometric matches are contained in an existing database;

13(II) an estimate of the rate at which travelers using fraudulent credentials identifications are accurately rejected; and

14(III) an assessment of what percentage of the detection of fraudulent identifications could have been accomplished using conventional methods;

15(iv) the effects on privacy of the use of biometric technologies, including methods to mitigate any risks to privacy identified by the Administrator or the Commissioner of U.S. Customs and Border Protection related to the active or passive collection of biometric data; and

16(v) the number of individuals who stay in the United States after the expiration of their visas each year.

17(B) A description of—

18(i) all audits performed to assess—

19(I) error rates in the use of biometric technologies; or

20(II) whether the use of biometric technologies and error rates in the use of such technologies disproportionately affect a certain race, gender, or nationality; and

21(ii) the results of the audits described in clause (i).

22(C) A description of the process by which domestic travelers are able to opt-out of scanning using biometric technologies.

23(D) A description of—

24(i) what traveler data is collected through scanning using biometric technologies, what agencies have access to such data, and how long the agencies possess such data;

25(ii) specific actions that the Department and other relevant Federal departments and agencies take to safeguard such data; and

26(iii) a short-term goal for the prompt deletion of the data of individual United States citizens after such data is used to verify traveler identities.

27The Secretary, the Administrator, and the Commissioner shall, if practicable, publish a public version of the assessment required by subsection (c)(2) on the Internet website of the TSA and of the U.S. Customs and Border Protection.

1119.

Voluntary use of credentialing

1An applicable individual who is subject to credentialing or a background investigation may satisfy that requirement by obtaining a valid transportation security card.

2The Secretary of Homeland Security—

3(1) shall expand the transportation security card program, consistent with section 70105 of title 46, to allow an applicable individual who is subject to credentialing or a background investigation to apply for a transportation security card; and

4(2) may charge reasonable fees, in accordance with section 469(a) of this title, for providing the necessary credentialing and background investigation.

5The Administrator shall develop and implement a plan to utilize, in addition to any background check required for initial issue, the Federal Bureau of Investigation's Rap Back Service and other vetting tools as appropriate, including the No-Fly and Selectee lists, to get immediate notification of any criminal activity relating to any person with a valid transportation security card.

6In this section:

7The term "applicable individual who is subject to credentialing or a background investigation" means only an individual who—

8(A) because of employment is regulated by the Transportation Security Administration, Department of Transportation, or Coast Guard and is required to have a background records check to obtain a hazardous materials endorsement on a commercial driver's license issued by a State under section 5103a of title 49; or

9(B) is required to have a credential and background records check under section 622(d)(2) 1 of this title at a facility with activities that are regulated by the Transportation Security Administration, Department of Transportation, or Coast Guard.

10The term "valid transportation security card" means a transportation security card that is—

11(A) issued under section 70105 of title 46;

12(B) not expired;

13(C) shows 2 no signs of tampering; and

14(D) bears 2 a photograph of the individual representing such card.

1131.

Definitions

1For purposes of this subchapter, the following terms apply:

2The term "appropriate congressional committees" means the Committee on Banking, Housing, and Urban Affairs, and the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Transportation and Infrastructure of the House of Representatives.

3The term "Department" means the Department of Homeland Security.

4The term "disadvantaged business concerns" means small businesses that are owned and controlled by socially and economically disadvantaged individuals as defined in section 1 124, title 13, Code of Federal Regulations.

5The term "frontline employee" means an employee of a public transportation agency who is a transit vehicle driver or operator, dispatcher, maintenance and maintenance support employee, station attendant, customer service employee, security employee, or transit police, or any other employee who has direct contact with riders on a regular basis, and any other employee of a public transportation agency that the Secretary determines should receive security training under section 1137 of this title.

6The term "public transportation agency" means a publicly owned operator of public transportation eligible to receive Federal assistance under chapter 53 of title 49.

7The term "Secretary" means the Secretary of Homeland Security.

1132.

Findings

1Congress finds that—

2(1) 182 public transportation systems throughout the world have been primary targets of terrorist attacks;

3(2) more than 6,000 public transportation agencies operate in the United States;

4(3) people use public transportation vehicles 33,000,000 times each day;

5(4) the Federal Transit Administration has invested $93,800,000,000 since 1992 for construction and improvements;

6(5) the Federal investment in transit security has been insufficient; and

7(6) greater Federal investment in transit security improvements per passenger boarding is necessary to better protect the American people, given transit's vital importance in creating mobility and promoting our Nation's economy.

1133.

National Strategy for Public Transportation Security

1Not later than 9 months after August 3, 2007, and based upon the previous and ongoing security assessments conducted by the Department and the Department of Transportation, the Secretary, consistent with and as required by section 114(t) 1 of title 49, shall develop and implement the modal plan for public transportation, entitled the "National Strategy for Public Transportation Security".

2In developing the National Strategy for Public Transportation Security, the Secretary shall establish guidelines for public transportation security that—

3(A) minimize security threats to public transportation systems; and

4(B) maximize the abilities of public transportation systems to mitigate damage resulting from terrorist attack or other major incident.

5In developing the National Strategy for Public Transportation Security, the Secretary shall—

6(A) use established and ongoing public transportation security assessments as the basis of the National Strategy for Public Transportation Security; and

7(B) consult with all relevant stakeholders, including public transportation agencies, nonprofit labor organizations representing public transportation employees, emergency responders, public safety officials, and other relevant parties.

8In the National Strategy for Public Transportation Security, the Secretary shall describe prioritized goals, objectives, policies, actions, and schedules to improve the security of public transportation.

9The Secretary shall include in the National Strategy for Public Transportation Security a description of the roles, responsibilities, and authorities of Federal, State, and local agencies, tribal governments, and appropriate stakeholders. The plan shall also include—

10(1) the identification of, and a plan to address, gaps and unnecessary overlaps in the roles, responsibilities, and authorities of Federal agencies; and

11(2) a process for coordinating existing or future security strategies and plans for public transportation, including the National Infrastructure Protection Plan required by Homeland Security Presidential Directive–7; Executive Order No. 13416: Strengthening Surface Transportation Security dated December 5, 2006; the Memorandum of Understanding between the Department and the Department of Transportation on Roles and Responsibilities dated September 28, 2004; and subsequent annexes and agreements.

12In developing the National Strategy for Public Transportation Security, the Secretary shall use relevant existing risk assessments and strategies developed by the Department or other Federal agencies, including those developed or implemented pursuant to section 114(t) 1 of title 49 or Homeland Security Presidential Directive–7.

13There is authorized to be appropriated to the Secretary to carry out this section $2,000,000 for fiscal year 2008.

1134.

Security assessments and plans

1Not later than 30 days after August 3, 2007, the Administrator of the Federal Transit Administration of the Department of Transportation shall submit all public transportation security assessments and all other relevant information to the Secretary.

2Not later than 60 days after receiving the submission under paragraph (1), the Secretary shall review and augment the security assessments received, and conduct additional security assessments as necessary to ensure that at a minimum, all high risk public transportation agencies, as determined by the Secretary, will have a completed security assessment.

3The Secretary shall ensure that each completed security assessment includes—

4(A) identification of critical assets, infrastructure, and systems and their vulnerabilities; and

5(B) identification of any other security weaknesses, including weaknesses in emergency response planning and employee training.

6Not later than 180 days after August 3, 2007, the Secretary shall—

7(1) conduct security assessments, based on a representative sample, to determine the specific needs of—

8(A) local bus-only public transportation systems; and

9(B) public transportation systems that receive funds under section 5311 of title 49; and

10(2) make the representative assessments available for use by similarly situated systems.

11The Secretary shall require public transportation agencies determined by the Secretary to be at high risk for terrorism to develop a comprehensive security plan. The Secretary shall provide technical assistance and guidance to public transportation agencies in preparing and implementing security plans under this section.

12Provided that no public transportation agency that has not been designated high risk shall be required to develop a security plan, the Secretary may also establish a security program for public transportation agencies not designated high risk by the Secretary, to assist those public transportation agencies which request assistance, including—

13(i) guidance to assist such agencies in conducting security assessments and preparing and implementing security plans; and

14(ii) a process for the Secretary to review and approve such assessments and plans, as appropriate.

15The Secretary shall ensure that security plans include, as appropriate—

16(A) a prioritized list of all items included in the public transportation agency's security assessment that have not yet been addressed;

17(B) a detailed list of any additional capital and operational improvements identified by the Department or the public transportation agency and a certification of the public transportation agency's technical capacity for operating and maintaining any security equipment that may be identified in such list;

18(C) specific procedures to be implemented or used by the public transportation agency in response to a terrorist attack, including evacuation and passenger communication plans and appropriate evacuation and communication measures for the elderly and individuals with disabilities;

19(D) a coordinated response plan that establishes procedures for appropriate interaction with State and local law enforcement agencies, emergency responders, and Federal officials in order to coordinate security measures and plans for response in the event of a terrorist attack or other major incident;

20(E) a strategy and timeline for conducting training under section 1137 of this title;

21(F) plans for providing redundant and other appropriate backup systems necessary to ensure the continued operation of critical elements of the public transportation system in the event of a terrorist attack or other major incident;

22(G) plans for providing service capabilities throughout the system in the event of a terrorist attack or other major incident in the city or region which the public transportation system serves;

23(H) methods to mitigate damage within a public transportation system in case of an attack on the system, including a plan for communication and coordination with emergency responders; and

24(I) other actions or procedures as the Secretary determines are appropriate to address the security of the public transportation system.

25Not later than 6 months after receiving the plans required under this section, the Secretary shall—

26(A) review each security plan submitted;

27(B) require the public transportation agency to make any amendments needed to ensure that the plan meets the requirements of this section; and

28(C) approve any security plan that meets the requirements of this section.

29The Secretary shall not require a public transportation agency to develop a security plan under paragraph (1) if the agency does not receive a grant under section 1135 of this title.

30The Secretary may waive the exemption provided in paragraph (4) to require a public transportation agency to develop a security plan under paragraph (1) in the absence of grant funds under section 1135 of this title if not less than 3 days after making the determination the Secretary provides the appropriate congressional committees and the public transportation agency written notification detailing the need for the security plan, the reasons grant funding has not been made available, and the reason the agency has been designated high risk.

31The Secretary shall ensure that the security plans developed by public transportation agencies under this section are consistent with the security assessments developed by the Department and the National Strategy for Public Transportation Security developed under section 1133 of this title.

32Not later than September 30, 2008, and annually thereafter, the Secretary shall—

33(1) update the security assessments referred to in subsection (a);

34(2) update the security improvement priorities required under subsection (f); and

35(3) require public transportation agencies to update the security plans required under subsection (c) as appropriate.

36Beginning in fiscal year 2008 and each fiscal year thereafter, the Secretary, after consultation with management and nonprofit employee labor organizations representing public transportation employees as appropriate, and with appropriate State and local officials, shall utilize the information developed or received in this section to establish security improvement priorities unique to each individual public transportation agency that has been assessed.

37The Secretary shall use the security improvement priorities established in paragraph (1) as the basis for allocating risk-based grant funds under section 1135 of this title, unless the Secretary notifies the appropriate congressional committees that the Secretary has determined an adjustment is necessary to respond to an urgent threat or other significant national security factors.

38The Secretary shall encourage the development and implementation of coordinated assessments and security plans to the extent a public transportation agency shares facilities (such as tunnels, bridges, stations, or platforms) with another public transportation agency, a freight or passenger railroad carrier, or over-the-road bus operator that are geographically close or otherwise co-located.

39Nothing in this section shall be construed as authorizing the withholding of any information from Congress.

40Nothing in this section shall be construed as affecting any authority or obligation of a Federal agency to disclose any record or information that the Federal agency obtains from a public transportation agency under any other Federal law.

41In response to a petition by a public transportation agency or at the discretion of the Secretary, the Secretary may recognize existing procedures, protocols, and standards of a public transportation agency that the Secretary determines meet all or part of the requirements of this section regarding security assessments or security plans.

1135.

Public transportation security assistance

1The Secretary shall establish a program for making grants to eligible public transportation agencies for security improvements described in subsection (b).

2A public transportation agency is eligible for a grant under this section if the Secretary has performed a security assessment or the agency has developed a security plan under section 1134 of this title. Grant funds shall only be awarded for permissible uses under subsection (b) to—

3(A) address items included in a security assessment; or

4(B) further a security plan.

5A recipient of a grant under subsection (a) shall use the grant funds for one or more of the following:

6(1) Capital uses of funds, including—

7(A) tunnel protection systems;

8(B) perimeter protection systems, including access control, installation of improved lighting, fencing, and barricades;

9(C) redundant critical operations control systems;

10(D) chemical, biological, radiological, or explosive detection systems, including the acquisition of canines used for such detection;

11(E) surveillance equipment;

12(F) communications equipment, including mobile service equipment to provide access to wireless Enhanced 911 (E911) emergency services in an underground fixed guideway system;

13(G) emergency response equipment, including personal protective equipment;

14(H) fire suppression and decontamination equipment;

15(I) global positioning or tracking and recovery equipment, and other automated-vehicle-locator-type system equipment;

16(J) evacuation improvements;

17(K) purchase and placement of bomb-resistant trash cans throughout public transportation facilities, including subway exits, entrances, and tunnels;

18(L) capital costs associated with security awareness, security preparedness, and security response training, including training under section 1137 of this title and exercises under section 1136 of this title;

19(M) security improvements for public transportation systems, including extensions thereto, in final design or under construction;

20(N) security improvements for stations and other public transportation infrastructure, including stations and other public transportation infrastructure owned by State or local governments; and

21(O) other capital security improvements determined appropriate by the Secretary.

22(2) Operating uses of funds, including—

23(A) security training and associated backfill, including training under section 1137 of this title and training developed by institutions of higher education and by nonprofit employee labor organizations, for public transportation employees, including frontline employees;

24(B) live or simulated exercises under section 1136 of this title;

25(C) public awareness campaigns for enhanced public transportation security;

26(D) canine patrols for chemical, radiological, biological, or explosives detection;

27(E) development of security plans under section 1134 of this title;

28(F) overtime reimbursement including reimbursement of State, local, and tribal governments, for costs for enhanced security personnel during significant national and international public events;

29(G) operational costs, including reimbursement of State, local, and tribal governments for costs for personnel assigned to full-time or part-time security or counterterrorism duties related to public transportation, provided that this expense totals no more than 10 percent of the total grant funds received by a public transportation agency in any 1 year; and

30(H) other operational security costs determined appropriate by the Secretary, excluding routine, ongoing personnel costs, other than those set forth in this section.

31In carrying out the responsibilities under subsection (a), the Secretary shall—

32(1) determine the requirements for recipients of grants under this section, including application requirements;

33(2) pursuant to subsection (a)(2), select the recipients of grants based solely on risk; and

34(3) pursuant to subsection (b), establish the priorities for which grant funds may be used under this section.

35Not later than 90 days after August 3, 2007, the Secretary and the Secretary of Transportation shall determine the most effective and efficient way to distribute grant funds to the recipients of grants determined by the Secretary under subsection (a). Subject to the determination made by the Secretaries, the Secretary may transfer funds to the Secretary of Transportation for the purposes of disbursing funds to the grant recipient.

36Except as otherwise specifically provided in this section, a grant provided under this section shall be subject to the terms and conditions applicable to a grant made under section 5307 of title 49, as in effect on January 1, 2007, and such other terms and conditions as are determined necessary by the Secretary.

37Grants made under this section may not be used to make any State or local government cost-sharing contribution under any other Federal law.

38Each recipient of a grant under this section shall report annually to the Secretary on the use of the grant funds.

39Before distribution of funds to recipients of grants, the Secretary shall issue guidelines to ensure that, to the extent that recipients of grants under this section use contractors or subcontractors, such recipients shall use small, minority, women-owned, or disadvantaged business concerns as contractors or subcontractors to the extent practicable.

40In establishing security improvement priorities under section 1134 of this title and in awarding grants for capital security improvements and operational security improvements under subsection (b), the Secretary shall act consistently with relevant State homeland security plans.

41In cases in which a public transportation system operates in more than one State, the Secretary shall give appropriate consideration to the risks of the entire system, including those portions of the States into which the system crosses, in establishing security improvement priorities under section 1134 of this title and in awarding grants for capital security improvements and operational security improvements under subsection (b).

42Not later than 3 days before the award of any grant under this section, the Secretary shall notify simultaneously, the appropriate congressional committees of the intent to award such grant.

43The Secretary shall establish a process to require the return of any misspent grant funds received under this section determined to have been spent for a purpose other than those specified in the grant award.

44Except as provided in paragraph (2), funds provided pursuant to a grant awarded under this section for a use specified in subsection (b) shall remain available for use by a grant recipient for a period of not fewer than 36 months.

45Funds provided pursuant to a grant awarded under this section for a use specified in subparagraph (M) or (N) of subsection (b)(1) shall remain available for use by a grant recipient for a period of not fewer than 48 months.

46(1) There are authorized to be appropriated to the Secretary to make grants under this section—

47(A) such sums as are necessary for fiscal year 2007;

48(B) $650,000,000 for fiscal year 2008, except that not more than 50 percent of such funds may be used for operational costs under subsection (b)(2);

49(C) $750,000,000 for fiscal year 2009, except that not more than 30 percent of such funds may be used for operational costs under subsection (b)(2);

50(D) $900,000,000 for fiscal year 2010, except that not more than 20 percent of such funds may be used for operational costs under subsection (b)(2); and

51(E) $1,100,000,000 for fiscal year 2011, except that not more than 10 percent of such funds may be used for operational costs under subsection (b)(2).

52(2) Period of availability.—Sums appropriated to carry out this section shall remain available until expended.

53(3) Waiver.—The Secretary may waive the limitation on operational costs specified in subparagraphs (B) through (E) of paragraph (1) if the Secretary determines that such a waiver is required in the interest of national security, and if the Secretary provides a written justification to the appropriate congressional committees prior to any such action.

54(4) Effective date.—Funds provided for fiscal year 2007 transit security grants under Public Law 110–28 shall be allocated based on security assessments that are in existence as of August 3, 2007.

1136.

Security exercises

1The Secretary shall establish a program for conducting security exercises for public transportation agencies for the purpose of assessing and improving the capabilities of entities described in subsection (b) to prevent, prepare for, mitigate against, respond to, and recover from acts of terrorism.

2Entities to be assessed under the program shall include—

3(1) Federal, State, and local agencies and tribal governments;

4(2) public transportation agencies;

5(3) governmental and nongovernmental emergency response providers and law enforcement personnel, including transit police; and

6(4) any other organization or entity that the Secretary determines appropriate.

7The Secretary shall ensure that the program—

8(1) requires, for public transportation agencies which the Secretary deems appropriate, exercises to be conducted that are—

9(A) scaled and tailored to the needs of specific public transportation systems, and include taking into account the needs of the elderly and individuals with disabilities;

10(B) live;

11(C) coordinated with appropriate officials;

12(D) as realistic as practicable and based on current risk assessments, including credible threats, vulnerabilities, and consequences;

13(E) inclusive, as appropriate, of frontline employees and managers; and

14(F) consistent with the National Incident Management System, the National Response Plan, the National Infrastructure Protection Plan, the National Preparedness Guidance, the National Preparedness Goal, and other such national initiatives;

15(2) provides that exercises described in paragraph (1) will be—

16(A) evaluated by the Secretary against clear and consistent performance measures;

17(B) assessed by the Secretary to learn best practices, which shall be shared with appropriate Federal, State, local, and tribal officials, governmental and nongovernmental emergency response providers, law enforcement personnel, including railroad and transit police, and appropriate stakeholders; and

18(C) followed by remedial action by covered entities in response to lessons learned;

19(3) involves individuals in neighborhoods around the infrastructure of a public transportation system; and

20(4) assists State, local, and tribal governments and public transportation agencies in designing, implementing, and evaluating exercises that conform to the requirements of paragraph (2).

21The Secretary shall ensure that the exercise program developed under subsection (a) is a component of the National Exercise Program established under section 748 of this title.

22This section does not apply to any ferry system for which drills are required to be conducted pursuant to section 70103 of title 46.

1137.

Public transportation security training program

1Not later than 90 days after August 3, 2007, the Secretary shall develop and issue detailed interim final regulations, and not later than 1 year after August 3, 2007, the Secretary shall develop and issue detailed final regulations, for a public transportation security training program to prepare public transportation employees, including frontline employees, for potential security threats and conditions.

2The Secretary shall develop the interim final and final regulations under subsection (a) in consultation with—

3(1) appropriate law enforcement, fire service, security, and terrorism experts;

4(2) representatives of public transportation agencies; and

5(3) nonprofit employee labor organizations representing public transportation employees or emergency response personnel.

6The interim final and final regulations developed under subsection (a) shall require security training programs to include, at a minimum, elements to address the following:

7(1) Determination of the seriousness of any occurrence or threat.

8(2) Crew and passenger communication and coordination.

9(3) Appropriate responses to defend oneself, including using nonlethal defense devices.

10(4) Use of personal protective devices and other protective equipment.

11(5) Evacuation procedures for passengers and employees, including individuals with disabilities and the elderly.

12(6) Training related to behavioral and psychological understanding of, and responses to, terrorist incidents, including the ability to cope with hijacker behavior, and passenger responses.

13(7) Live situational training exercises regarding various threat conditions, including tunnel evacuation procedures.

14(8) Recognition and reporting of dangerous substances and suspicious packages, persons, and situations.

15(9) Understanding security incident procedures, including procedures for communicating with governmental and nongovernmental emergency response providers and for on scene interaction with such emergency response providers.

16(10) Operation and maintenance of security equipment and systems.

17(11) Other security training activities that the Secretary deems appropriate.

18Not later than 90 days after a public transportation agency meets the requirements under subsection (e), each such public transportation agency shall develop a security training program in accordance with the regulations developed under subsection (a) and submit the program to the Secretary for approval.

19Not later than 60 days after receiving a security training program proposal under this subsection, the Secretary shall approve the program or require the public transportation agency that developed the program to make any revisions to the program that the Secretary determines necessary for the program to meet the requirements of the regulations. A public transportation agency shall respond to the Secretary's comments within 30 days after receiving them.

20Not later than 1 year after the Secretary approves a security training program proposal in accordance with this subsection, the public transportation agency that developed the program shall complete the training of all employees covered under the program.

21The Secretary shall periodically review and update, as appropriate, the training regulations issued under subsection (a) to reflect new or changing security threats. Each public transportation agency shall revise its training program accordingly and provide additional training as necessary to its workers within a reasonable time after the regulations are updated.

22A public transportation agency that receives a grant award under this subchapter shall be required to develop and implement a security training program pursuant to this section.

23Any public transportation agency required to develop a security training program pursuant to this section shall provide routine and ongoing training for employees covered under the program, regardless of whether the public transportation agency receives subsequent grant awards.

24The Secretary shall ensure that the training program developed under subsection (a) is a component of the National Training Program established under section 748 of this title.

25This section shall not apply to any ferry system for which training is required to be conducted pursuant to section 70103 of title 46.

26Not later than 2 years after the date of issuance of the final regulation, the Comptroller General shall review implementation of the training program, including interviewing a representative sample of public transportation agencies and employees, and report to the appropriate congressional committees, on the number of reviews conducted and the results. The Comptroller General may submit the report in both classified and redacted formats as necessary.

1137a.

Local law enforcement security training

1The Secretary of Homeland Security, in consultation with public and private sector stakeholders, may in a manner consistent with the protection of privacy rights, civil rights, and civil liberties, develop, through the Federal Law Enforcement Training Centers, a training program to enhance the protection, preparedness, and response capabilities of law enforcement agencies with respect to threats of terrorism and other threats, including targeted violence, at a surface transportation asset.

2If the Secretary of Homeland Security develops the training program described in subsection (a), such training program shall—

3(1) be informed by current information regarding tactics used by terrorists and others engaging in targeted violence;

4(2) include tactical instruction tailored to the diverse nature of the surface transportation asset operational environment; and

5(3) prioritize training officers from law enforcement agencies that are eligible for or receive grants under sections 1 2003 or 1 2004 of the Homeland Security Act of 2002 (6 U.S.C. 604 and 1 605) and officers employed by railroad carriers that operate passenger service, including interstate passenger service.

6If the Secretary of Homeland Security develops the training program described in subsection (a), not later than one year after the date on which the Secretary first implements the program, and annually thereafter during each year the Secretary carries out the program, the Secretary shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the program. Each such report shall include, for the year covered by the report—

7(1) a description of the curriculum for the training and any changes to such curriculum;

8(2) an identification of any contracts entered into for the development or provision of training under the program;

9(3) information on the law enforcement agencies the personnel of which received the training, and for each such agency, the number of participants; and

10(4) a description of the measures used to ensure the program was carried out to provide for protections of privacy rights, civil rights, and civil liberties.

11In this section:

12(1) The term "public and private sector stakeholders" has the meaning given such term in section 114(t)(1)(c) 2 of title 49.

13(2) The term "surface transportation asset" includes facilities, equipment, or systems used to provide transportation services by—

14(A) a public transportation agency (as such term is defined in section 1131(5) of this title);

15(B) a railroad carrier (as such term is defined in section 20102(3) of title 49);

16(C) an owner or operator of—

17(i) an entity offering scheduled, fixed-route transportation services by over-the-road bus (as such term is defined in section 1151(4) of this title); or

18(ii) a bus terminal; or

19(D) other transportation facilities, equipment, or systems, as determined by the Secretary.

20(3) The term "targeted violence" means an incident of violence in which an attacker selected a particular target in order to inflict mass injury or death with no discernable political or ideological motivation beyond mass injury or death.

21(4) The term "terrorism" means the terms—

22(A) domestic terrorism (as such term is defined in section 2331(5) of title 18); and

23(B) international terrorism (as such term is defined in section 2331(1) of title 18).

1138.

Public transportation research and development

1The Secretary shall carry out a research and development program through the Homeland Security Advanced Research Projects Agency in the Science and Technology Directorate and in consultation with the Transportation Security Administration and with the Federal Transit Administration, for the purpose of improving the security of public transportation systems.

2The Secretary shall award grants or contracts to public or private entities to conduct research and demonstrate technologies and methods to reduce and deter terrorist threats or mitigate damages resulting from terrorist attacks against public transportation systems.

3Grants or contracts awarded under subsection (a)—

4(1) shall be coordinated with activities of the Homeland Security Advanced Research Projects Agency; and

5(2) may be used to—

6(A) research chemical, biological, radiological, or explosive detection systems that do not significantly impede passenger access;

7(B) research imaging technologies;

8(C) conduct product evaluations and testing;

9(D) improve security and redundancy for critical communications, electrical power, and computer and train control systems;

10(E) develop technologies for securing tunnels, transit bridges and aerial structures;

11(F) research technologies that mitigate damages in the event of a cyber attack; and

12(G) research other technologies or methods for reducing or deterring terrorist attacks against public transportation systems, or mitigating damage from such attacks.

13In carrying out research and development projects under this section, the Secretary shall consult with the Chief Privacy Officer of the Department and the Officer for Civil Rights and Civil Liberties of the Department, as appropriate, and in accordance with section 142 of this title.

14In accordance with sections 142 and 345 of this title, the Chief Privacy Officer shall conduct privacy impact assessments and the Officer for Civil Rights and Civil Liberties shall conduct reviews, as appropriate, for research and development initiatives developed under this section.

15Each entity that is awarded a grant or contract under this section shall report annually to the Department on the use of grant or contract funds received under this section to ensure that the awards made are expended in accordance with the purposes of this subchapter and the priorities developed by the Secretary.

16The Secretary shall ensure that the research is consistent with the priorities established in the National Strategy for Public Transportation Security and is coordinated, to the extent practicable, with other Federal, State, local, tribal, and private sector public transportation, railroad, commuter railroad, and over-the-road bus research initiatives to leverage resources and avoid unnecessary duplicative efforts.

17If the Secretary determines that a grantee or contractor used any portion of the grant or contract funds received under this section for a purpose other than the allowable uses specified under subsection (c), the grantee or contractor shall return any amount so used to the Treasury of the United States.

18There are authorized to be appropriated to the Secretary to make grants under this section—

19(1) such sums as necessary for fiscal year 2007;

20(2) $25,000,000 for fiscal year 2008;

21(3) $25,000,000 for fiscal year 2009;

22(4) $25,000,000 for fiscal year 2010; and

23(5) $25,000,000 for fiscal year 2011.

1139.

Information sharing

1The Secretary shall ensure that the Department of Transportation receives appropriate and timely notification of all credible terrorist threats against public transportation assets in the United States.

2The Secretary shall provide for the reasonable costs of the Information Sharing and Analysis Center for Public Transportation (referred to in this subsection as the "ISAC").

3The Secretary—

4(A) shall require public transportation agencies that the Secretary determines to be at high risk of terrorist attack to participate in the ISAC;

5(B) shall encourage all other public transportation agencies to participate in the ISAC;

6(C) shall encourage the participation of nonprofit employee labor organizations representing public transportation employees, as appropriate; and

7(D) shall not charge a fee for participating in the ISAC.

8The Comptroller General shall report, not less than 3 years after August 3, 2007, to the appropriate congressional committees, as to the value and efficacy of the ISAC along with any other public transportation information-sharing programs ongoing at the Department. The report shall include an analysis of the user satisfaction of public transportation agencies on the state of information-sharing and the value that each system provides the user, the costs and benefits of all centers and programs, the coordination among centers and programs, how each center or program contributes to implementing the information sharing plan under section 1203,1 and analysis of the extent to which the ISAC is duplicative with the Department's information-sharing program.

9There are authorized to be appropriated to the Secretary to carry out this section—

10(A) $600,000 for fiscal year 2008;

11(B) $600,000 for fiscal year 2009;

12(C) $600,000 for fiscal year 2010; and

13(D) such sums as may be necessary for 2011, provided the report required in subsection (c) of this section has been submitted to Congress.

14Such sums shall remain available until expended.

1140.

Threat assessments

1Not later than 1 year after August 3, 2007, the Secretary shall complete a name-based security background check against the consolidated terrorist watchlist and an immigration status check for all public transportation frontline employees, similar to the threat assessment screening program required for facility employees and longshoremen by the Commandant of the Coast Guard under Coast Guard Notice USCG–2006–24189 (71 Fed. Reg. 25066 (April 8, 2006)).

1141.

Reporting requirements

1Not later than March 31 of each year, the Secretary shall submit a report, containing the information described in paragraph (2), to the appropriate congressional committees.

2The report submitted under paragraph (1) shall include—

3(A) a description of the implementation of the provisions of this subchapter;

4(B) the amount of funds appropriated to carry out the provisions of this subchapter that have not been expended or obligated;

5(C) the National Strategy for Public Transportation Security required under section 1133 of this title;

6(D) an estimate of the cost to implement the National Strategy for Public Transportation Security which shall break out the aggregated total cost of needed capital and operational security improvements for fiscal years 2008–2018; and

7(E) the state of public transportation security in the United States, which shall include detailing the status of security assessments, the progress being made around the country in developing prioritized lists of security improvements necessary to make public transportation facilities and passengers more secure, the progress being made by agencies in developing security plans and how those plans differ from the security assessments and a prioritized list of security improvements being compiled by other agencies, as well as a random sample of an equal number of large- and small-scale projects currently underway.

8The Secretary may submit the report in both classified and redacted formats if the Secretary determines that such action is appropriate or necessary.

9Not later than March 31 of each year, the Secretary shall submit a report to the Governor of each State with a public transportation agency that has received a grant under this Act.

10The report submitted under paragraph (1) shall specify—

11(A) the amount of grant funds distributed to each such public transportation agency; and

12(B) the use of such grant funds.

1142.

Public transportation employee protections

1A public transportation agency, a contractor or a subcontractor of such agency, or an officer or employee of such agency, shall not discharge, demote, suspend, reprimand, or in any other way discriminate against an employee if such discrimination is due, in whole or in part, to the employee's lawful, good faith act done, or perceived by the employer to have been done or about to be done—

2(1) to provide information, directly cause information to be provided, or otherwise directly assist in any investigation regarding any conduct which the employee reasonably believes constitutes a violation of any Federal law, rule, or regulation relating to public transportation safety or security, or fraud, waste, or abuse of Federal grants or other public funds intended to be used for public transportation safety or security, if the information or assistance is provided to or an investigation stemming from the provided information is conducted by—

3(A) a Federal, State, or local regulatory or law enforcement agency (including an office of the Inspector General under chapter 4 of title 5; 1

4(B) any Member of Congress, any Committee of Congress, or the Government Accountability Office; or

5(C) a person with supervisory authority over the employee or such other person who has the authority to investigate, discover, or terminate the misconduct;

6(2) to refuse to violate or assist in the violation of any Federal law, rule, or regulation relating to public transportation safety or security;

7(3) to file a complaint or directly cause to be brought a proceeding related to the enforcement of this section or to testify in that proceeding;

8(4) to cooperate with a safety or security investigation by the Secretary of Transportation, the Secretary of Homeland Security, or the National Transportation Safety Board; or

9(5) to furnish information to the Secretary of Transportation, the Secretary of Homeland Security, the National Transportation Safety Board, or any Federal, State, or local regulatory or law enforcement agency as to the facts relating to any accident or incident resulting in injury or death to an individual or damage to property occurring in connection with public transportation.

10(1) A public transportation agency, or a contractor or a subcontractor of such agency, or an officer or employee of such agency, shall not discharge, demote, suspend, reprimand, or in any other way discriminate against an employee for—

11(A) reporting a hazardous safety or security condition;

12(B) refusing to work when confronted by a hazardous safety or security condition related to the performance of the employee's duties, if the conditions described in paragraph (2) exist; or

13(C) refusing to authorize the use of any safety- or security-related equipment, track, or structures, if the employee is responsible for the inspection or repair of the equipment, track, or structures, when the employee believes that the equipment, track, or structures are in a hazardous safety or security condition, if the conditions described in paragraph (2) of this subsection exist.

14(2) A refusal is protected under paragraph (1)(B) and (C) if—

15(A) the refusal is made in good faith and no reasonable alternative to the refusal is available to the employee;

16(B) a reasonable individual in the circumstances then confronting the employee would conclude that—

17(i) the hazardous condition presents an imminent danger of death or serious injury; and

18(ii) the urgency of the situation does not allow sufficient time to eliminate the danger without such refusal; and

19(C) the employee, where possible, has notified the public transportation agency of the existence of the hazardous condition and the intention not to perform further work, or not to authorize the use of the hazardous equipment, track, or structures, unless the condition is corrected immediately or the equipment, track, or structures are repaired properly or replaced.

20(3) In this subsection, only subsection (b)(1)(A) shall apply to security personnel, including transit police, employed or utilized by a public transportation agency to protect riders, equipment, assets, or facilities.

21A person who believes that he or she has been discharged or otherwise discriminated against by any person in violation of subsection (a) or (b) may, not later than 180 days after the date on which such violation occurs, file (or have any person file on his or her behalf) a complaint with the Secretary of Labor alleging such discharge or discrimination. Upon receipt of a complaint filed under this paragraph, the Secretary of Labor shall notify, in writing, the person named in the complaint and the person's employer of the filing of the complaint, of the allegations contained in the complaint, of the substance of evidence supporting the complaint, and of the opportunities that will be afforded to such person under paragraph (2).

22Not later than 60 days after the date of receipt of a complaint filed under paragraph (1) and after affording the person named in the complaint an opportunity to submit to the Secretary of Labor a written response to the complaint and an opportunity to meet with a representative of the Secretary of Labor to present statements from witnesses, the Secretary of Labor shall conduct an investigation and determine whether there is reasonable cause to believe that the complaint has merit and notify, in writing, the complainant and the person alleged to have committed a violation of subsection (a) or (b) of the Secretary of Labor's findings. If the Secretary of Labor concludes that there is a reasonable cause to believe that a violation of subsection (a) or (b) has occurred, the Secretary of Labor shall accompany the Secretary of Labor's findings with a preliminary order providing the relief prescribed by paragraph (3)(B). Not later than 30 days after the date of notification of findings under this paragraph, either the person alleged to have committed the violation or the complainant may file objections to the findings or preliminary order, or both, and request a hearing on the record. The filing of such objections shall not operate to stay any reinstatement remedy contained in the preliminary order. Such hearings shall be conducted expeditiously. If a hearing is not requested in such 30-day period, the preliminary order shall be deemed a final order that is not subject to judicial review.

23The Secretary of Labor shall dismiss a complaint filed under this subsection and shall not conduct an investigation otherwise required under subparagraph (A) unless the complainant makes a prima facie showing that any behavior described in subsection (a) or (b) was a contributing factor in the unfavorable personnel action alleged in the complaint.

24Notwithstanding a finding by the Secretary of Labor that the complainant has made the showing required under clause (i), no investigation otherwise required under paragraph (A) shall be conducted if the employer demonstrates, by clear and convincing evidence, that the employer would have taken the same unfavorable personnel action in the absence of that behavior.

25The Secretary of Labor may determine that a violation of subsection (a) or (b) has occurred only if the complainant demonstrates that any behavior described in subsection (a) or (b) was a contributing factor in the unfavorable personnel action alleged in the complaint.

26Relief may not be ordered under paragraph (A) if the employer demonstrates by clear and convincing evidence that the employer would have taken the same unfavorable personnel action in the absence of that behavior.

27Not later than 120 days after the date of conclusion of a hearing under paragraph (2), the Secretary of Labor shall issue a final order providing the relief prescribed by this paragraph or denying the complaint. At any time before issuance of a final order, a proceeding under this subsection may be terminated on the basis of a settlement agreement entered into by the Secretary of Labor, the complainant, and the person alleged to have committed the violation.

28If, in response to a complaint filed under paragraph (1), the Secretary of Labor determines that a violation of subsection (a) or (b) has occurred, the Secretary of Labor shall order the person who committed such violation to—

29(i) take affirmative action to abate the violation; and

30(ii) provide the remedies described in subsection (d).

31If an order is issued under subparagraph (B), the Secretary of Labor, at the request of the complainant, shall assess against the person against whom the order is issued a sum equal to the aggregate amount of all costs and expenses (including attorney and expert witness fees) reasonably incurred, as determined by the Secretary of Labor, by the complainant for, or in connection with, bringing the complaint upon which the order was issued.

32If the Secretary of Labor finds that a complaint under paragraph (1) is frivolous or has been brought in bad faith, the Secretary of Labor may award to the prevailing employer reasonable attorney fees not exceeding $1,000.

33Any person adversely affected or aggrieved by an order issued under paragraph (3) may obtain review of the order in the United States Court of Appeals for the circuit in which the violation, with respect to which the order was issued, allegedly occurred or the circuit in which the complainant resided on the date of such violation. The petition for review must be filed not later than 60 days after the date of the issuance of the final order of the Secretary of Labor. Review shall conform to chapter 7 of title 5. The commencement of proceedings under this subparagraph shall not, unless ordered by the court, operate as a stay of the order.

34An order of the Secretary of Labor with respect to which review could have been obtained under subparagraph (A) shall not be subject to judicial review in any criminal or other civil proceeding.

35Whenever any person has failed to comply with an order issued under paragraph (3), the Secretary of Labor may file a civil action in the United States district court for the district in which the violation was found to occur to enforce such order. In actions brought under this paragraph, the district courts shall have jurisdiction to grant all appropriate relief including, but not limited to, injunctive relief and compensatory damages.

36A person on whose behalf an order was issued under paragraph (3) may commence a civil action against the person to whom such order was issued to require compliance with such order. The appropriate United States district court shall have jurisdiction, without regard to the amount in controversy or the citizenship of the parties, to enforce such order.

37The court, in issuing any final order under this paragraph, may award costs of litigation (including reasonable attorney and expert witness fees) to any party whenever the court determines such award is appropriate.

38With respect to a complaint under paragraph (1), if the Secretary of Labor has not issued a final decision within 210 days after the filing of the complaint and if the delay is not due to the bad faith of the employee, the employee may bring an original action at law or equity for de novo review in the appropriate district court of the United States, which shall have jurisdiction over such an action without regard to the amount in controversy, and which action shall, at the request of either party to such action, be tried by the court with a jury. The action shall be governed by the same legal burdens of proof specified in paragraph (2)(B) for review by the Secretary of Labor.

39An employee prevailing in any action under subsection (c) shall be entitled to all relief necessary to make the employee whole.

40Relief in an action under subsection (c) (including an action described in (c)(7)) 2 shall include—

41(A) reinstatement with the same seniority status that the employee would have had, but for the discrimination;

42(B) any backpay, with interest; and

43(C) compensatory damages, including compensation for any special damages sustained as a result of the discrimination, including litigation costs, expert witness fees, and reasonable attorney fees.

44Relief in any action under subsection (c) may include punitive damages in an amount not to exceed $250,000.

45An employee may not seek protection under both this section and another provision of law for the same allegedly unlawful act of the public transportation agency.

46Nothing in this section preempts or diminishes any other safeguards against discrimination, demotion, discharge, suspension, threats, harassment, reprimand, retaliation, or any other manner of discrimination provided by Federal or State law.

47Nothing in this section shall be construed to diminish the rights, privileges, or remedies of any employee under any Federal or State law or under any collective bargaining agreement. The rights and remedies in this section may not be waived by any agreement, policy, form, or condition of employment.

48(1) Except as provided in paragraph (2) of this subsection, or with the written consent of the employee, the Secretary of Transportation or the Secretary of Homeland Security may not disclose the name of an employee who has provided information described in subsection (a)(1).

49(2) The Secretary of Transportation or the Secretary of Homeland Security shall disclose to the Attorney General the name of an employee described in paragraph (1) of this subsection if the matter is referred to the Attorney General for enforcement. The Secretary making such disclosure shall provide reasonable advance notice to the affected employee if disclosure of that person's identity or identifying information is to occur.

50The Secretary shall establish through regulations after an opportunity for notice and comment, and provide information to the public regarding, a process by which any person may submit a report to the Secretary regarding public transportation security problems, deficiencies, or vulnerabilities.

51If a report submitted under paragraph (1) identifies the person making the report, the Secretary shall respond promptly to such person and acknowledge receipt of the report.

52The Secretary shall review and consider the information provided in any report submitted under paragraph (1) and shall take appropriate steps to address any problems or deficiencies identified.

1143.

Security background checks of covered individuals for public transportation

1In this section, the following definitions apply:

2The term "security background check" means reviewing the following for the purpose of identifying individuals who may pose a threat to transportation security, national security, or of terrorism:

3(A) Relevant criminal history databases.

4(B) In the case of an alien (as defined in section 101 of the Immigration and Nationality Act (8 U.S.C. 1101(a)(3))), the relevant databases to determine the status of the alien under the immigration laws of the United States.

5(C) Other relevant information or databases, as determined by the Secretary.

6The term "covered individual" means an employee of a public transportation agency or a contractor or subcontractor of a public transportation agency.

7(1) Any guidance, recommendations, suggested action items, or any other widely disseminated voluntary action item issued by the Secretary to a public transportation agency or a contractor or subcontractor of a public transportation agency relating to performing a security background check of a covered individual shall contain recommendations on the appropriate scope and application of such a security background check, including the time period covered, the types of disqualifying offenses, and a redress process for adversely impacted covered individuals consistent with subsections (c) and (d) of this section.

8(2) Not later than 60 days after August 3, 2007, any guidance, recommendations, suggested action items, or any other widely disseminated voluntary action item issued by the Secretary prior to August 3, 2007, to a public transportation agency or a contractor or subcontractor of a public transportation agency relating to performing a security background check of a covered individual shall be updated in compliance with paragraph (b)(1).

9(3) If a public transportation agency or a contractor or subcontractor of a public transportation agency performs a security background check on a covered individual to fulfill guidance issued by the Secretary under paragraph (1) or (2), the Secretary shall not consider such guidance fulfilled unless an adequate redress process as described in subsection (d) is provided to covered individuals.

10If the Secretary issues a rule, regulation or directive requiring a public transportation agency or contractor or subcontractor of a public transportation agency to perform a security background check of a covered individual, then the Secretary shall prohibit a public transportation agency or contractor or subcontractor of a public transportation agency from making an adverse employment decision, including removal or suspension of the employee, due to such rule, regulation, or directive with respect to a covered individual unless the public transportation agency or contractor or subcontractor of a public transportation agency determines that the covered individual—

11(1) has been convicted of, has been found not guilty of by reason of insanity, or is under want, warrant, or indictment for a permanent disqualifying criminal offense listed in part 1572 of title 49, Code of Federal Regulations;

12(2) was convicted of or found not guilty by reason of insanity of an interim disqualifying criminal offense listed in part 1572 of title 49, Code of Federal Regulations, within 7 years of the date that the public transportation agency or contractor or subcontractor of the public transportation agency performs the security background check; or

13(3) was incarcerated for an interim disqualifying criminal offense listed in part 1572 of title 49, Code of Federal Regulations, and released from incarceration within 5 years of the date that the public transportation agency or contractor or subcontractor of a public transportation agency performs the security background check.

14If the Secretary issues a rule, regulation, or directive requiring a public transportation agency or contractor or subcontractor of a public transportation agency to perform a security background check of a covered individual, the Secretary shall—

15(1) provide an adequate redress process for a covered individual subjected to an adverse employment decision, including removal or suspension of the employee, due to such rule, regulation, or directive that is consistent with the appeals and waiver process established for applicants for commercial motor vehicle hazardous materials endorsements and transportation workers at ports, as required by section 70105(c) of title 49; 1 and

16(2) have the authority to order an appropriate remedy, including reinstatement of the covered individual, should the Secretary determine that a public transportation agency or contractor or subcontractor of a public transportation agency wrongfully made an adverse employment decision regarding a covered individual pursuant to such rule, regulation, or directive.

17A public transportation agency or a contractor or subcontractor of a public transportation agency may not knowingly misrepresent to an employee or other relevant person, including an arbiter involved in a labor arbitration, the scope, application, or meaning of any rules, regulations, directives, or guidance issued by the Secretary related to security background check requirements for covered individuals when conducting a security background check. Not later than 1 year after August 3, 2007, the Secretary shall issue a regulation that prohibits a public transportation agency or a contractor or subcontractor of a public transportation agency from knowingly misrepresenting to an employee or other relevant person, including an arbiter involved in a labor arbitration, the scope, application, or meaning of any rules, regulations, directives, or guidance issued by the Secretary related to security background check requirements for covered individuals when conducting a security background check.

18Nothing in this section shall be construed to abridge a public transportation agency's or a contractor or subcontractor of a public transportation agency's rights or responsibilities to make adverse employment decisions permitted by other Federal, State, or local laws. Nothing in the 2 section shall be construed to abridge rights and responsibilities of covered individuals, a public transportation agency, or a contractor or subcontractor of a public transportation agency under any other Federal, State, or local laws or collective bargaining agreement.

19Nothing in this section shall be construed to preempt a Federal, State, or local law that requires criminal history background checks, immigration status checks, or other background checks of covered individuals.

20Nothing in this section shall be construed to affect the process for review established under section 70105(c) of title 46, including regulations issued pursuant to such section.

1144.

Limitation on fines and civil penalties

1Surface transportation inspectors shall be prohibited from issuing fines to public transportation agencies for violations of the Department's regulations or orders except through the process described in subsection (b).

2The Secretary shall be prohibited from assessing civil penalties against public transportation agencies for violations of the Department's regulations or orders, except in accordance with the following:

3(1) In the case of a public transportation agency that is found to be in violation of a regulation or order issued by the Secretary, the Secretary shall seek correction of the violation through a written notice to the public transportation agency and shall give the public transportation agency reasonable opportunity to correct the violation or propose an alternative means of compliance acceptable to the Secretary.

4(2) If the public transportation agency does not correct the violation or propose an alternative means of compliance acceptable to the Secretary within a reasonable time period that is specified in the written notice, the Secretary may take any action authorized in section 114 of title 49.

5The Secretary shall not initiate civil enforcement actions for violations of administrative and procedural requirements pertaining to the application for and expenditure of funds awarded under transportation security grant programs under this subchapter.

1151.

Definitions

1In this subchapter, the following definitions apply:

2The term "appropriate congressional committees" means the Committee on Commerce, Science, and Transportation and the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Transportation and Infrastructure of the House of Representatives.

3The term "Secretary" means the Secretary of Homeland Security.

4The term "Department" means the Department of Homeland Security.

5The term "over-the-road bus" means a bus characterized by an elevated passenger deck located over a baggage compartment.

6In this section,1 the term "over-the-road bus frontline employees" means over-the-road bus drivers, security personnel, dispatchers, maintenance and maintenance support personnel, ticket agents, other terminal employees, and other employees of an over-the-road bus operator or terminal owner or operator that the Secretary determines should receive security training under this subchapter.

7In this section,1 the term "railroad frontline employees" means security personnel, dispatchers, locomotive engineers, conductors, trainmen, other onboard employees, maintenance and maintenance support personnel, bridge tenders, and any other employees of railroad carriers that the Secretary determines should receive security training under this subchapter.

8The term "railroad" has the meaning that term has in section 20102 of title 49.

9The term "railroad carrier" has the meaning that term has in section 20102 of title 49.

10The term "State" means any one of the 50 States, the District of Columbia, Puerto Rico, the Northern Mariana Islands, the Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.

11The term "terrorism" has the meaning that term has in section 101 of this title.

12The term "transportation", as used with respect to an over-the-road bus, means the movement of passengers or property by an over-the-road bus—

13(A) in the jurisdiction of the United States between a place in a State and a place outside the State (including a place outside the United States); or

14(B) in a State that affects trade, traffic, and transportation described in subparagraph (A).

15The term "United States" means the 50 States, the District of Columbia, Puerto Rico, the Northern Mariana Islands, the Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.

16The term "security-sensitive material" means a material, or a group or class of material, in a particular amount and form that the Secretary, in consultation with the Secretary of Transportation, determines, through a rulemaking with opportunity for public comment, poses a significant risk to national security while being transported in commerce due to the potential use of the material in an act of terrorism. In making such a designation, the Secretary shall, at a minimum, consider the following:

17(A) Class 7 radioactive materials.

18(B) Division 1.1, 1.2, or 1.3 explosives.

19(C) Materials poisonous or toxic by inhalation, including Division 2.3 gases and Division 6.1 materials.

20(D) A select agent or toxin regulated by the Centers for Disease Control and Prevention under part 73 of title 42, Code of Federal Regulations.

21The term "disadvantaged business concerns" means small businesses that are owned and controlled by socially and economically disadvantaged individuals as defined in section 124,2 of title 13, Code of Federal Regulations.

22The term "Amtrak" means the National Railroad Passenger Corporation.

1152.

Oversight and grant procedures

1The Secretary, in coordination with 1 Secretary of Transportation for grants awarded to Amtrak, shall establish necessary procedures, including monitoring and audits, to ensure that grants made under this subchapter are expended in accordance with the purposes of this subchapter and the priorities and other criteria developed by the Secretary.

2The Secretary, and the Secretary of Transportation for grants awarded to Amtrak, may award contracts to undertake additional audits and reviews of the safety, security, procurement, management, and financial compliance of a recipient of amounts under this subchapter.

3Not later than 180 days after August 3, 2007, the Secretary shall prescribe procedures and schedules for the awarding of grants under this subchapter, including application and qualification procedures, and a record of decision on applicant eligibility. The procedures shall include the execution of a grant agreement between the grant recipient and the Secretary and shall be consistent, to the extent practicable, with the grant procedures established under section 70107(i) and (j) of title 46.

4The Secretary may issue non-binding letters of intent to recipients of a grant under this subchapter, to commit funding from future budget authority of an amount, not more than the Federal Government's share of the project's cost, for a capital improvement project.

5The letter of intent under this subsection shall establish a schedule under which the Secretary will reimburse the recipient for the Government's share of the project's costs, as amounts become available, if the recipient, after the Secretary issues that letter, carries out the project without receiving amounts under a grant issued under this subchapter.

6A recipient that has been issued a letter of intent under this section shall notify the Secretary of the recipient's intent to carry out a project before the project begins.

7The Secretary shall transmit to the appropriate congressional committees a written notification at least 5 days before the issuance of a letter of intent under this subsection.

8A letter of intent issued under this subsection is not an obligation of the Federal Government under section 1501 of title 31, and the letter is not deemed to be an administrative commitment for financing. An obligation or administrative commitment may be made only as amounts are provided in authorization and appropriations laws.

9As part of the grant agreement under subsection (c), the Secretary shall require grant applicants to return any misspent grant funds received under this subchapter that the Secretary considers to have been spent for a purpose other than those specified in the grant award. The Secretary shall take all necessary actions to recover such funds.

10Not later than 5 days before the award of any grant is made under this subchapter, the Secretary shall notify the appropriate congressional committees of the intent to award such grant.

11The Secretary shall ensure, to the extent practicable, that grant recipients under this subchapter who use contractors or subcontractors use small, minority, women-owned, or disadvantaged business concerns as contractors or subcontractors when appropriate.

1153.

Authorization of appropriations

1There are authorized to be appropriated to the Secretary of Transportation to carry out section 1165 of this title—

2(1) $38,000,000 for fiscal year 2008;

3(2) $40,000,000 for fiscal year 2009;

4(3) $55,000,000 for fiscal year 2010; and

5(4) $70,000,000 for fiscal year 2011.

1154.

Public awareness

1Not later than 180 days after August 3, 2007, the Secretary shall develop a national plan for railroad and over-the-road bus security public outreach and awareness. Such a plan shall be designed to increase awareness of measures that the general public, passengers, and employees of railroad carriers and over-the-road bus operators can take to increase the security of the national railroad and over-the-road bus transportation systems. Such a plan shall also provide outreach to railroad carriers and over-the-road bus operators and their employees to improve their awareness of available technologies, ongoing research and development efforts, and available Federal funding sources to improve security. Not later than 9 months after August 3, 2007, the Secretary shall implement the plan developed under this section.

1155.

Security awareness program

1The Administrator shall establish a program to promote surface transportation security through the training of surface transportation operators and frontline employees on each of the skills identified in subsection (c).

2The program established under subsection (a) shall apply to all modes of surface transportation, including public transportation, rail, highway, motor carrier, and pipeline.

3The program established under subsection (a) shall cover, at a minimum, the skills necessary to recognize, assess, and respond to suspicious items or actions that could indicate a threat to transportation.

4The Administrator shall conduct an assessment of current training programs for surface transportation operators and frontline employees.

5The assessment shall identify—

6(A) whether other training is being provided, either voluntarily or in response to other Federal requirements; and

7(B) whether there are any gaps in existing training.

8The Administrator shall ensure the program established under subsection (a) is updated as necessary to address changes in risk and terrorist methods and to close any gaps identified in the assessment under subsection (d).

9The Secretary shall maintain a national telephone number for an individual to use to report suspicious activity under this section to the Administration.

10The Administrator shall establish procedures for the Administration—

11(A) to review and follow-up, as necessary, on each report received under paragraph (1); and

12(B) to share, as necessary and in accordance with law, the report with appropriate Federal, State, local, and tribal entities.

13Nothing in this section may be construed to—

14(A) replace or affect in any way the use of 9–1–1 services in an emergency; or

15(B) replace or affect in any way the security training program requirements specified in sections 1137, 1167, and 1184 of this title.

16In this section, the term "frontline employee" includes—

17(1) an employee of a public transportation agency who is a transit vehicle driver or operator, dispatcher, maintenance and maintenance support employee, station attendant, customer service employee, security employee, or transit police, or any other employee who has direct contact with riders on a regular basis, and any other employee of a public transportation agency that the Administrator determines should receive security training under this section or that is receiving security training under other law;

18(2) over-the-road bus drivers, security personnel, dispatchers, maintenance and maintenance support personnel, ticket agents, other terminal employees, and other employees of an over-the-road bus operator or terminal owner or operator that the Administrator determines should receive security training under this section or that is receiving security training under other law; or

19(3) security personnel, dispatchers, locomotive engineers, conductors, trainmen, other onboard employees, maintenance and maintenance support personnel, bridge tenders, and any other employees of railroad carriers that the Administrator determines should receive security training under this section or that is receiving security training under other law.

1156.

Nuclear material and explosive detection technology

1The Secretary, in coordination with the Director of the National Institute of Standards and Technology and the head of each relevant Federal department or agency researching nuclear material detection systems or explosive detection systems, shall research, facilitate, and, to the extent practicable, deploy next generation technologies, including active neutron interrogation, to detect nuclear material and explosives in transportation systems and transportation facilities.

1161.

Railroad transportation security risk assessment and National Strategy

1The Secretary shall establish a Federal task force, including the Transportation Security Administration and other agencies within the Department, the Department of Transportation, and other appropriate Federal agencies, to complete, within 6 months of August 3, 2007, a nationwide risk assessment of a terrorist attack on railroad carriers. The assessment shall include—

2(1) a methodology for conducting the risk assessment, including timelines, that addresses how the Department will work with the entities described in subsection (c) and make use of existing Federal expertise within the Department, the Department of Transportation, and other appropriate agencies;

3(2) identification and evaluation of critical assets and infrastructure, including tunnels used by railroad carriers in high-threat urban areas;

4(3) identification of risks to those assets and infrastructure;

5(4) identification of risks that are specific to the transportation of hazardous materials via railroad;

6(5) identification of risks to passenger and cargo security, transportation infrastructure protection systems, operations, communications systems, and any other area identified by the assessment;

7(6) an assessment of employee training and emergency response planning;

8(7) an assessment of public and private operational recovery plans, taking into account the plans for the maritime sector required under section 70103 of title 46, to expedite, to the maximum extent practicable, the return of an adversely affected railroad transportation system or facility to its normal performance level after a major terrorist attack or other security event on that system or facility; and

9(8) an account of actions taken or planned by both public and private entities to address identified railroad security issues and an assessment of the effective integration of such actions.

10Not later than 9 months after August 3, 2007, and based upon the assessment conducted under subsection (a), the Secretary, consistent with and as required by section 114(t) 1 of title 49, shall develop and implement the modal plan for railroad transportation, entitled the "National Strategy for Railroad Transportation Security".

11The modal plan shall include prioritized goals, actions, objectives, policies, mechanisms, and schedules for, at a minimum—

12(A) improving the security of railroad tunnels, railroad bridges, railroad switching and car storage areas, other railroad infrastructure and facilities, information systems, and other areas identified by the Secretary as posing significant railroad-related risks to public safety and the movement of interstate commerce, taking into account the impact that any proposed security measure might have on the provision of railroad service or on operations served or otherwise affected by railroad service;

13(B) deploying equipment and personnel to detect security threats, including those posed by explosives and hazardous chemical, biological, and radioactive substances, and any appropriate countermeasures;

14(C) consistent with section 1167 of this title, training railroad employees in terrorism prevention, preparedness, passenger evacuation, and response activities;

15(D) conducting public outreach campaigns for railroads regarding security, including educational initiatives designed to inform the public on how to prevent, prepare for, respond to, and recover from a terrorist attack on railroad transportation;

16(E) providing additional railroad security support for railroads at high or severe threat levels of alert;

17(F) ensuring, in coordination with freight and intercity and commuter passenger railroads, the continued movement of freight and passengers in the event of an attack affecting the railroad system, including the possibility of rerouting traffic due to the loss of critical infrastructure, such as a bridge, tunnel, yard, or station;

18(G) coordinating existing and planned railroad security initiatives undertaken by the public and private sectors;

19(H) assessing—

20(i) the usefulness of covert testing of railroad security systems;

21(ii) the ability to integrate security into infrastructure design; and

22(iii) the implementation of random searches of passengers and baggage; and

23(I) identifying the immediate and long-term costs of measures that may be required to address those risks and public and private sector sources to fund such measures.

24The Secretary shall include in the modal plan a description of the roles, responsibilities, and authorities of Federal, State, and local agencies, government-sponsored entities, tribal governments, and appropriate stakeholders described in subsection (c). The plan shall also include—

25(A) the identification of, and a plan to address, gaps and unnecessary overlaps in the roles, responsibilities, and authorities described in this paragraph;

26(B) a methodology for how the Department will work with the entities described in subsection (c), and make use of existing Federal expertise within the Department, the Department of Transportation, and other appropriate agencies;

27(C) a process for facilitating security clearances for the purpose of intelligence and information sharing with the entities described in subsection (c), as appropriate;

28(D) a strategy and timeline, coordinated with the research and development program established under section 1168 of this title, for the Department, the Department of Transportation, other appropriate Federal agencies and private entities to research and develop new technologies for securing railroad systems; and

29(E) a process for coordinating existing or future security strategies and plans for railroad transportation, including the National Infrastructure Protection Plan required by Homeland Security Presidential Directive–7; Executive Order No. 13416: "Strengthening Surface Transportation Security" dated December 5, 2006; the Memorandum of Understanding between the Department and the Department of Transportation on Roles and Responsibilities dated September 28, 2004, and any and all subsequent annexes to this Memorandum of Understanding, and any other relevant agreements between the two Departments.

30In developing the National Strategy required under this section, the Secretary shall consult with railroad management, nonprofit employee organizations representing railroad employees, owners or lessors of railroad cars used to transport hazardous materials, emergency responders, offerors of security-sensitive materials, public safety officials, and other relevant parties.

31In developing the risk assessment and National Strategy required under this section, the Secretary shall utilize relevant existing plans, strategies, and risk assessments developed by the Department or other Federal agencies, including those developed or implemented pursuant to section 114(t) 1 of title 49 or Homeland Security Presidential Directive–7, and, as appropriate, assessments developed by other public and private stakeholders.

32Not later than 1 year after August 3, 2007, the Secretary shall transmit to the appropriate congressional committees a report containing—

33(A) the assessment and the National Strategy required by this section; and

34(B) an estimate of the cost to implement the National Strategy.

35The Secretary may submit the report in both classified and redacted formats if the Secretary determines that such action is appropriate or necessary.

36Consistent with the requirements of section 114(t) 1 of title 49, the Secretary shall update the assessment and National Strategy each year and transmit a report, which may be submitted in both classified and redacted formats, to the appropriate congressional committees containing the updated assessment and recommendations.

37Out of funds appropriated pursuant to section 114(w) 1 of title 49, there shall be made available to the Secretary to carry out this section $5,000,000 for fiscal year 2008.

1162.

Railroad carrier assessments and plans

1Not later than 12 months after August 3, 2007, the Secretary shall issue regulations that—

2(1) require each railroad carrier assigned to a high-risk tier under this section to—

3(A) conduct a vulnerability assessment in accordance with subsections (c) and (d); and

4(B) to 1 prepare, submit to the Secretary for approval, and implement a security plan in accordance with this section that addresses security performance requirements; and

5(2) establish standards and guidelines, based on and consistent with the risk assessment and National Strategy for Railroad Transportation Security developed under section 1161 of this title, for developing and implementing the vulnerability assessments and security plans for railroad carriers assigned to high-risk tiers.

6The Secretary may establish a security program for railroad carriers not assigned to a high-risk tier, including—

7(1) guidance for such carriers in conducting vulnerability assessments and preparing and implementing security plans, as determined appropriate by the Secretary; and

8(2) a process to review and approve such assessments and plans, as appropriate.

9Not later than 9 months after the date of issuance of the regulations under subsection (a), the vulnerability assessments and security plans required by such regulations for railroad carriers assigned to a high-risk tier shall be completed and submitted to the Secretary for review and approval.

10The Secretary shall provide technical assistance and guidance to railroad carriers in conducting vulnerability assessments under this section and shall require that each vulnerability assessment of a railroad carrier assigned to a high-risk tier under this section, include, as applicable—

11(A) identification and evaluation of critical railroad carrier assets and infrastructure, including platforms, stations, intermodal terminals, tunnels, bridges, switching and storage areas, and information systems as appropriate;

12(B) identification of the vulnerabilities to those assets and infrastructure;

13(C) identification of strengths and weaknesses in—

14(i) physical security;

15(ii) passenger and cargo security, including the security of security-sensitive materials being transported by railroad or stored on railroad property;

16(iii) programmable electronic devices, computers, or other automated systems which are used in providing the transportation;

17(iv) alarms, cameras, and other protection systems;

18(v) communications systems and utilities needed for railroad security purposes, including dispatching and notification systems;

19(vi) emergency response planning;

20(vii) employee training; and

21(viii) such other matters as the Secretary determines appropriate; and

22(D) identification of redundant and backup systems required to ensure the continued operation of critical elements of a railroad carrier's system in the event of an attack or other incident, including disruption of commercial electric power or communications network.

23The Secretary shall provide in a timely manner to the appropriate employees of a railroad carrier, as designated by the railroad carrier, threat information that is relevant to the carrier when preparing and submitting a vulnerability assessment and security plan, including an assessment of the most likely methods that could be used by terrorists to exploit weaknesses in railroad security.

24The Secretary shall provide technical assistance and guidance to railroad carriers in preparing and implementing security plans under this section, and shall require that each security plan of a railroad carrier assigned to a high-risk tier under this section include, as applicable—

25(A) identification of a security coordinator having authority—

26(i) to implement security actions under the plan;

27(ii) to coordinate security improvements; and

28(iii) to receive immediate communications from appropriate Federal officials regarding railroad security;

29(B) a list of needed capital and operational improvements;

30(C) procedures to be implemented or used by the railroad carrier in response to a terrorist attack, including evacuation and passenger communication plans that include individuals with disabilities as appropriate;

31(D) identification of steps taken with State and local law enforcement agencies, emergency responders, and Federal officials to coordinate security measures and plans for response to a terrorist attack;

32(E) a strategy and timeline for conducting training under section 1167 of this title;

33(F) enhanced security measures to be taken by the railroad carrier when the Secretary declares a period of heightened security risk;

34(G) plans for providing redundant and backup systems required to ensure the continued operation of critical elements of the railroad carrier's system in the event of a terrorist attack or other incident;

35(H) a strategy for implementing enhanced security for shipments of security-sensitive materials, including plans for quickly locating and securing such shipments in the event of a terrorist attack or security incident; and

36(I) such other actions or procedures as the Secretary determines are appropriate to address the security of railroad carriers.

37The Secretary shall require that the individual serving as the security coordinator identified in paragraph (1)(A) is a citizen of the United States. The Secretary may waive this requirement with respect to an individual if the Secretary determines that it is appropriate to do so based on a background check of the individual and a review of the consolidated terrorist watchlist.

38The Secretary shall ensure that the security plans developed by railroad carriers under this section are consistent with the risk assessment and National Strategy for Railroad Transportation Security developed under section 1161 of this title.

39Not later than 6 months after receiving the assessments and plans required under this section, the Secretary shall—

40(1) review each vulnerability assessment and security plan submitted to the Secretary in accordance with subsection (c);

41(2) require amendments to any security plan that does not meet the requirements of this section; and

42(3) approve any vulnerability assessment or security plan that meets the requirements of this section.

43The Secretary may require railroad carriers, during the period before the deadline established under subsection (c), to submit a security plan under subsection (e) to implement any necessary interim security measures essential to providing adequate security of the railroad carrier's system. An interim plan required under this subsection will be superseded by a plan required under subsection (e).

44Utilizing the risk assessment and National Strategy for Railroad Transportation Security required under section 1161 of this title, the Secretary shall assign each railroad carrier to a risk-based tier established by the Secretary:

45The Secretary may request, and a railroad carrier shall provide, information necessary for the Secretary to assign a railroad carrier to the appropriate tier under this subsection.

46Not later than 60 days after the date a railroad carrier is assigned to a tier under this subsection, the Secretary shall notify the railroad carrier of the tier to which it is assigned and the reasons for such assignment.

47At least one of the tiers established by the Secretary under this subsection shall be designated a tier for high-risk railroad carriers.

48The Secretary may reassign a railroad carrier to another tier, as appropriate, in response to changes in risk. The Secretary shall notify the railroad carrier not later than 60 days after such reassignment and provide the railroad carrier with the reasons for such reassignment.

49Nothing in this section shall be construed as authorizing the withholding of any information from Congress.

50Nothing in this section shall be construed as affecting any authority or obligation of a Federal agency to disclose any record or information that the Federal agency obtains from a railroad carrier under any other Federal law.

51In response to a petition by a railroad carrier or at the discretion of the Secretary, the Secretary may determine that existing procedures, protocols, and standards meet all or part of the requirements of this section, including regulations issued under subsection (a), regarding vulnerability assessments and security plans.

52Upon review and written determination by the Secretary that existing procedures, protocols, or standards of a railroad carrier satisfy the requirements of this section, the railroad carrier may elect to comply with those procedures, protocols, or standards instead of the requirements of this section.

53If the Secretary determines that the existing procedures, protocols, or standards of a railroad carrier satisfy only part of the requirements of this section, the Secretary may accept such submission, but shall require submission by the railroad carrier of any additional information relevant to the vulnerability assessment and security plan of the railroad carrier to ensure that the remaining requirements of this section are fulfilled.

54If the Secretary determines that particular existing procedures, protocols, or standards of a railroad carrier under this subsection do not satisfy the requirements of this section, the Secretary shall provide to the railroad carrier a written notification that includes an explanation of the determination.

55Nothing in this subsection shall relieve the Secretary of the obligation—

56(A) to review the vulnerability assessment and security plan submitted by a railroad carrier under this section; and

57(B) to approve or disapprove each submission on an individual basis.

58Not later than 3 years after the date on which a vulnerability assessment or security plan required to be submitted to the Secretary under subsection (c) is approved, and at least once every 5 years thereafter (or on such a schedule as the Secretary may establish by regulation), a railroad carrier who submitted a vulnerability assessment and security plan and who is still assigned to the high-risk tier must also submit to the Secretary an evaluation of the adequacy of the vulnerability assessment and security plan that includes a description of any material changes made to the vulnerability assessment or security plan.

59Not later than 180 days after the date on which an evaluation is submitted, the Secretary shall review the evaluation and notify the railroad carrier submitting the evaluation of the Secretary's approval or disapproval of the evaluation.

60The Secretary may permit under this section the development and implementation of coordinated vulnerability assessments and security plans to the extent that a railroad carrier shares facilities with, or is colocated with, other transportation entities or providers that are required to develop vulnerability assessments and security plans under Federal law.

61In carrying out this section, the Secretary shall consult with railroad carriers, nonprofit employee labor organizations representation railroad employees, and public safety and law enforcement officials.

1163.

Railroad security assistance

1(1) The Secretary, in consultation with the Administrator of the Transportation Security Administration and other appropriate agencies or officials, is authorized to make grants to railroad carriers, the Alaska Railroad, security-sensitive materials offerors who ship by railroad, owners of railroad cars used in the transportation of security-sensitive materials, State and local governments (for railroad passenger facilities and infrastructure not owned by Amtrak), and Amtrak for intercity passenger railroad and freight railroad security improvements described in subsection (b) as approved by the Secretary.

2(2) A railroad carrier is eligible for a grant under this section if the carrier has completed a vulnerability assessment and developed a security plan that the Secretary has approved in accordance with section 1162 of this title.

3(3) A recipient of a grant under this section may use grant funds only for permissible uses under subsection (b) to further a railroad security plan that meets the requirements of paragraph (2).

4(4) Notwithstanding the requirement for eligibility and uses of funds in paragraphs (2) and (3), a railroad carrier is eligible for a grant under this section if the applicant uses the funds solely for the development of assessments or security plans under section 1162 of this title.

5(5) Notwithstanding the requirements for eligibility and uses of funds in paragraphs (2) and (3), prior to the earlier of 1 year after the date of issuance of final regulations requiring vulnerability assessments and security plans under section 1162 of this title or 3 years after August 3, 2007, the Secretary may award grants under this section for rail security improvements listed under subsection (b) based upon railroad carrier vulnerability assessments and security plans that the Secretary determines are sufficient for the purposes of this section but have not been approved by the Secretary in accordance with section 1162 of this title.

6A recipient of a grant under this section shall use the grant funds for one or more of the following:

7(1) Security and redundancy for critical communications, computer, and train control systems essential for secure railroad operations, including communications interoperability where appropriate with relevant outside agencies and entities.

8(2) Accommodation of railroad cargo or passenger security inspection facilities, related infrastructure, and operations at or near United States international borders or other ports of entry.

9(3) The security of security-sensitive materials transportation by railroad.

10(4) Chemical, biological, radiological, or explosive detection, including canine patrols for such detection.

11(5) The security and preparedness of intercity passenger railroad stations, trains, and infrastructure, including security capital improvement projects that the Secretary determines enhance railroad station security.

12(6) Technologies to reduce the vulnerabilities of railroad cars, including structural modification of railroad cars transporting security-sensitive materials to improve their resistance to acts of terrorism.

13(7) The sharing of intelligence and information about security threats and preparedness, including connectivity to the National Terrorist Screening Center.

14(8) To obtain train tracking and communications equipment, including equipment that is interoperable with Federal, State, and local agencies and tribal governments.

15(9) To hire, train, and employ police, security, and preparedness officers, including canine units, assigned to full-time security or counterterrorism duties related to railroad transportation.

16(10) Overtime reimbursement, including reimbursement of State, local, and tribal governments for costs, for enhanced security personnel assigned to duties related to railroad security during periods of high or severe threat levels and National Special Security Events or other periods of heightened security as determined by the Secretary.

17(11) Perimeter protection systems, including access control, installation of improved lighting, fencing, and barricades at railroad facilities.

18(12) Tunnel protection systems.

19(13) Passenger evacuation and evacuation-related capital improvements.

20(14) Railroad security inspection technologies, including verified visual inspection technologies using hand-held readers.

21(15) Surveillance equipment.

22(16) Cargo or passenger screening equipment.

23(17) Emergency response equipment, including fire suppression and decontamination equipment, personal protective equipment, and defibrillators.

24(18) Operating and capital costs associated with security awareness, preparedness, and response training, including training under section 1167 of this title, and training developed by universities, institutions of higher education, and nonprofit employee labor organizations, for railroad employees, including frontline employees.

25(19) Live or simulated exercises, including exercises described in section 1166 of this title.

26(20) Public awareness campaigns for enhanced railroad security.

27(21) Development of assessments or security plans under section 1162 of this title.

28(22) Other security improvements—

29(A) identified, required, or recommended under sections 1161 and 1162 of this title, including infrastructure, facilities, and equipment upgrades; or

30(B) that the Secretary considers appropriate.

31In carrying out the responsibilities under subsection (a), the Secretary shall—

32(1) determine the requirements for recipients of grants;

33(2) establish priorities for uses of funds for grant recipients;

34(3) award the funds authorized by this section based on risk, as identified by the plans required under sections 1161 and 1162 of this title, or assessment or plan described in subsection (a)(5);

35(4) take into account whether stations or facilities are used by commuter railroad passengers as well as intercity railroad passengers in reviewing grant applications;

36(5) encourage non-Federal financial participation in projects funded by grants; and

37(6) not later than 5 business days after awarding a grant to Amtrak under this section, transfer grant funds to the Secretary of Transportation to be disbursed to Amtrak.

38Grant funds awarded under this section may be awarded for projects that span multiple years.

39A grant made under this section may not be used to make any State or local government cost-sharing contribution under any other Federal law.

40Each recipient of a grant under this section shall report annually to the Secretary on the use of grant funds.

41Not later than 240 days after August 3, 2007, the Secretary shall provide a report to the appropriate congressional committees on the feasibility and appropriateness of requiring a non-Federal match for grants awarded to freight railroad carriers and other private entities under this section.

42A recipient of a grant under this section and sections 1164 and 1165 of this title shall be required to comply with the standards of section 24312 of title 49, as in effect on January 1, 2007, with respect to the project in the same manner as Amtrak is required to comply with such standards for construction work financed under an agreement made under section 24308(a) of that title.

43Out of funds appropriated pursuant to section 114(w) 1 of title 49, there shall be made available to the Secretary to carry out this section—

44(A) $300,000,000 for fiscal year 2008;

45(B) $300,000,000 for fiscal year 2009;

46(C) $300,000,000 for fiscal year 2010; and

47(D) $300,000,000 for fiscal year 2011.

48Sums appropriated to carry out this section shall remain available until expended.

1164.

Systemwide Amtrak security upgrades

1Subject to subsection (b), the Secretary, in consultation with the Administrator of the Transportation Security Administration, is authorized to make grants to Amtrak in accordance with the provisions of this section.

2The Secretary may make such grants for the purposes of—

3(A) protecting underwater and underground assets and systems;

4(B) protecting high-risk and high-consequence assets identified through systemwide risk assessments;

5(C) providing counterterrorism or security training;

6(D) providing both visible and unpredictable deterrence; and

7(E) conducting emergency preparedness drills and exercises.

8The Secretary shall make such grants—

9(A) to secure major tunnel access points and ensure tunnel integrity in New York, New Jersey, Maryland, and Washington, DC;

10(B) to secure Amtrak trains;

11(C) to secure Amtrak stations;

12(D) to obtain a watchlist identification system approved by the Secretary, or to connect to the National Terrorism Screening Center watchlist;

13(E) to obtain train tracking and interoperable communications systems that are coordinated with Federal, State, and local agencies and tribal governments to the maximum extent possible;

14(F) to hire, train, and employ police and security officers, including canine units, assigned to full-time security or counterterrorism duties related to railroad transportation;

15(G) for operating and capital costs associated with security awareness, preparedness, and response training, including training under section 1167 of this title, and training developed by universities, institutions of higher education, and nonprofit employee labor organizations, for railroad employees, including frontline employees;

16(H) for live or simulated exercises, including exercises described in section 1166 of this title;

17(I) for improvements to passenger verification systems;

18(J) for improvements to employee and contractor verification systems, including identity verification technology; or

19(K) for improvements to the security of Amtrak computer systems, including cybersecurity assessments and programs.

20The Secretary shall award grants to Amtrak under this section for projects contained in a systemwide security plan approved by the Secretary developed pursuant to section 1162 of this title. Not later than 5 business days after awarding a grant to Amtrak under this section, the Secretary shall transfer the grant funds to the Secretary of Transportation to be disbursed to Amtrak.

21The Secretary shall ensure that, subject to meeting the highest security needs on Amtrak's entire system and consistent with the risk assessment required under section 1161 of this title and Amtrak's vulnerability assessment and security plan developed under section 1162 of this title, stations and facilities located outside of the Northeast Corridor receive an equitable share of the security funds authorized by this section.

22Out of funds appropriated pursuant to section 114(w) 1 of title 49, there shall be made available to the Secretary and the Administrator of the Transportation Security Administration to carry out this section—

23(A) $150,000,000 for fiscal year 2008;

24(B) $150,000,000 for fiscal year 2009;

25(C) $175,000,000 for fiscal year 2010; and

26(D) $175,000,000 for fiscal year 2011.

27Amounts appropriated pursuant to paragraph (1) shall remain available until expended.

1165.

Fire and life safety improvements

1There are authorized to be appropriated to the Secretary of Transportation for making grants to Amtrak for the purpose of carrying out projects to make fire and life safety improvements to Amtrak tunnels on the Northeast Corridor the following amounts:

2(1) For the 6 New York and New Jersey tunnels to provide ventilation, electrical, and fire safety technology improvements, emergency communication and lighting systems, and emergency access and egress for passengers—

3(A) $25,000,000 for fiscal year 2008;

4(B) $30,000,000 for fiscal year 2009;

5(C) $45,000,000 for fiscal year 2010; and

6(D) $60,000,000 for fiscal year 2011.

7(2) For the Baltimore Potomac Tunnel and the Union Tunnel, together, to provide adequate drainage and ventilation, communication, lighting, standpipe, and passenger egress improvements—

8(A) $5,000,000 for fiscal year 2008;

9(B) $5,000,000 for fiscal year 2009;

10(C) $5,000,000 for fiscal year 2010; and

11(D) $5,000,000 for fiscal year 2011.

12(3) For the Union Station tunnels in the District of Columbia to improve ventilation, communication, lighting, and passenger egress improvements—

13(A) $5,000,000 for fiscal year 2008;

14(B) $5,000,000 for fiscal year 2009;

15(C) $5,000,000 for fiscal year 2010; and

16(D) $5,000,000 for fiscal year 2011.

17Out of funds appropriated pursuant to section 1153 of this title, there shall be made available to the Secretary of Transportation for fiscal year 2008, $3,000,000 for the preliminary design of options for a new tunnel on a different alignment to augment the capacity of the existing Baltimore tunnels.

18Amounts appropriated pursuant to this section shall remain available until expended.

19The Secretary of Transportation may not make amounts available to Amtrak for obligation or expenditure under subsection (a)—

20(1) until Amtrak has submitted to the Secretary of Transportation, and the Secretary of Transportation has approved, an engineering and financial plan for such projects; and

21(2) unless, for each project funded pursuant to this section, the Secretary of Transportation has approved a project management plan prepared by Amtrak.

22The Secretary of Transportation shall complete the review of a plan required under subsection (d) and approve or disapprove the plan within 45 days after the date on which each such plan is submitted by Amtrak.

23If the Secretary of Transportation determines that a plan is incomplete or deficient, the Secretary of Transportation shall notify Amtrak of the incomplete items or deficiencies and Amtrak shall, within 30 days after receiving the Secretary of Transportation's notification, submit a modified plan for the Secretary of Transportation's review.

24Within 15 days after receiving additional information on items previously included in the plan, and within 45 days after receiving items newly included in a modified plan, the Secretary of Transportation shall either approve the modified plan, or if the Secretary of Transportation finds the plan is still incomplete or deficient, the Secretary of Transportation shall—

25(A) identify in writing to the appropriate congressional committees the portions of the plan the Secretary finds incomplete or deficient;

26(B) approve all other portions of the plan;

27(C) obligate the funds associated with those portions; and

28(D) execute an agreement with Amtrak within 15 days thereafter on a process for resolving the remaining portions of the plan.

29The Secretary of Transportation, taking into account the need for the timely completion of all portions of the tunnel projects described in subsection (a), shall—

30(1) consider the extent to which railroad carriers other than Amtrak use or plan to use the tunnels;

31(2) consider the feasibility of seeking a financial contribution from those other railroad carriers toward the costs of the projects; and

32(3) obtain financial contributions or commitments from such other railroad carriers at levels reflecting the extent of their use or planned use of the tunnels, if feasible.

1166.

Railroad carrier exercises

1The Secretary shall establish a program for conducting security exercises for railroad carriers for the purpose of assessing and improving the capabilities of entities described in subsection (b) to prevent, prepare for, mitigate, respond to, and recover from acts of terrorism.

2Entities to be assessed under the program shall include—

3(1) Federal, State, and local agencies and tribal governments;

4(2) railroad carriers;

5(3) governmental and nongovernmental emergency response providers, law enforcement agencies, and railroad and transit police, as appropriate; and

6(4) any other organization or entity that the Secretary determines appropriate.

7The Secretary shall ensure that the program—

8(1) consolidates existing security exercises for railroad carriers administered by the Department and the Department of Transportation, as jointly determined by the Secretary and the Secretary of Transportation, unless the Secretary waives this consolidation requirement as appropriate;

9(2) consists of exercises that are—

10(A) scaled and tailored to the needs of the carrier, including addressing the needs of the elderly and individuals with disabilities;

11(B) live, in the case of the most at-risk facilities to a terrorist attack;

12(C) coordinated with appropriate officials;

13(D) as realistic as practicable and based on current risk assessments, including credible threats, vulnerabilities, and consequences;

14(E) inclusive, as appropriate, of railroad frontline employees; and

15(F) consistent with the National Incident Management System, the National Response Plan, the National Infrastructure Protection Plan, the National Preparedness Guidance, the National Preparedness Goal, and other such national initiatives;

16(3) provides that exercises described in paragraph (2) will be—

17(A) evaluated by the Secretary against clear and consistent performance measures;

18(B) assessed by the Secretary to identify best practices, which shall be shared, as appropriate, with railroad carriers, nonprofit employee organizations that represent railroad carrier employees, Federal, State, local, and tribal officials, governmental and nongovernmental emergency response providers, law enforcement personnel, including railroad carrier and transit police, and other stakeholders; and

19(C) used to develop recommendations, as appropriate, from the Secretary to railroad carriers on remedial action to be taken in response to lessons learned;

20(4) allows for proper advanced notification of communities and local governments in which exercises are held, as appropriate; and

21(5) assists State, local, and tribal governments and railroad carriers in designing, implementing, and evaluating additional exercises that conform to the requirements of paragraph (1) 1.

22The Secretary shall ensure that the exercise program developed under subsection (c) is a component of the National Exercise Program established under section 748 of this title.

1167.

Railroad security training program

1Not later than 6 months after August 3, 2007, the Secretary shall develop and issue regulations for a training program to prepare railroad frontline employees for potential security threats and conditions. The regulations shall take into consideration any current security training requirements or best practices.

2The Secretary shall develop the regulations under subsection (a) in consultation with—

3(1) appropriate law enforcement, fire service, emergency response, security, and terrorism experts;

4(2) railroad carriers;

5(3) railroad shippers; and

6(4) nonprofit employee labor organizations representing railroad employees or emergency response personnel.

7The regulations developed under subsection (a) shall require security training programs described in subsection (a) to include, at a minimum, elements to address the following, as applicable:

8(1) Determination of the seriousness of any occurrence or threat.

9(2) Crew and passenger communication and coordination.

10(3) Appropriate responses to defend or protect oneself.

11(4) Use of personal and other protective equipment.

12(5) Evacuation procedures for passengers and railroad employees, including individuals with disabilities and the elderly.

13(6) Psychology, behavior, and methods of terrorists, including observation and analysis.

14(7) Training related to psychological responses to terrorist incidents, including the ability to cope with hijacker behavior and passenger responses.

15(8) Live situational training exercises regarding various threat conditions, including tunnel evacuation procedures.

16(9) Recognition and reporting of dangerous substances, suspicious packages, and situations.

17(10) Understanding security incident procedures, including procedures for communicating with governmental and nongovernmental emergency response providers and for on-scene interaction with such emergency response providers.

18(11) Operation and maintenance of security equipment and systems.

19(12) Other security training activities that the Secretary considers appropriate.

20Not later than 90 days after the Secretary issues regulations under subsection (a), each railroad carrier shall develop a security training program in accordance with this section and submit the program to the Secretary for approval.

21Not later than 60 days after receiving a security training program proposal under this subsection, the Secretary shall approve the program or require the railroad carrier that developed the program to make any revisions to the program that the Secretary considers necessary for the program to meet the requirements of this section. A railroad carrier shall respond to the Secretary's comments within 30 days after receiving them.

22Not later than 1 year after the Secretary approves a security training program in accordance with this subsection, the railroad carrier that developed the program shall complete the training of all railroad frontline employees who were hired by a carrier more than 30 days preceding such date. For such employees employed less than 30 days by a carrier preceding such date, training shall be completed within the first 60 days of employment.

23The Secretary shall periodically review and update as appropriate the training regulations issued under subsection (a) to reflect new or changing security threats. Each railroad carrier shall revise its training program accordingly and provide additional training as necessary to its frontline employees within a reasonable time after the regulations are updated.

24The Secretary shall ensure that the training program developed under subsection (a) is a component of the National Training Program established under section 748 of this title.

25Not later than 2 years after the date of regulation issuance, the Secretary shall review implementation of the training program of a representative sample of railroad carriers and railroad frontline employees, and report to the appropriate congressional committees on the number of reviews conducted and the results of such reviews. The Secretary may submit the report in both classified and redacted formats as necessary.

26The Secretary shall issue guidance and best practices for a railroad shipper employee security program containing the elements listed under subsection (c).

1168.

Railroad security research and development

1The Secretary, acting through the Under Secretary for Science and Technology and the Administrator of the Transportation Security Administration, shall carry out a research and development program for the purpose of improving the security of railroad transportation systems.

2The research and development program may include projects—

3(1) to reduce the vulnerability of passenger trains, stations, and equipment to explosives and hazardous chemical, biological, and radioactive substances, including the development of technology to screen passengers in large numbers at peak commuting times with minimal interference and disruption;

4(2) to test new emergency response and recovery techniques and technologies, including those used at international borders;

5(3) to develop improved railroad security technologies, including—

6(A) technologies for sealing or modifying railroad tank cars;

7(B) automatic inspection of railroad cars;

8(C) communication-based train control systems;

9(D) emergency response training, including training in a tunnel environment;

10(E) security and redundancy for critical communications, electrical power, computer, and train control systems; and

11(F) technologies for securing bridges and tunnels;

12(4) to test wayside detectors that can detect tampering;

13(5) to support enhanced security for the transportation of security-sensitive materials by railroad;

14(6) to mitigate damages in the event of a cyber attack; and

15(7) to address other vulnerabilities and risks identified by the Secretary.

16The Secretary—

17(1) shall ensure that the research and development program is consistent with the National Strategy for Railroad Transportation Security developed under section 1161 of this title and any other transportation security research and development programs required by this Act;

18(2) shall, to the extent practicable, coordinate the research and development activities of the Department with other ongoing research and development security-related initiatives, including research being conducted by—

19(A) the Department of Transportation, including University Transportation Centers and other institutes, centers, and simulators funded by the Department of Transportation;

20(B) the National Academy of Sciences;

21(C) the Technical Support Working Group;

22(D) other Federal departments and agencies; and

23(E) other Federal and private research laboratories, research entities, and universities and institutions of higher education, including Historically Black Colleges and Universities, Hispanic Serving Institutions, or Indian Tribally Controlled Colleges and Universities;

24(3) shall carry out any research and development project authorized by this section through a reimbursable agreement with an appropriate Federal agency, if the agency—

25(A) is currently sponsoring a research and development project in a similar area; or

26(B) has a unique facility or capability that would be useful in carrying out the project;

27(4) may award grants, or enter into cooperative agreements, contracts, other transactions, or reimbursable agreements to the entities described in paragraph (2) and the eligible grant recipients under section 1163 of this title; and

28(5) shall make reasonable efforts to enter into memoranda of understanding, contracts, grants, cooperative agreements, or other transactions with railroad carriers willing to contribute both physical space and other resources.

29In carrying out research and development projects under this section, the Secretary shall consult with the Chief Privacy Officer of the Department and the Officer for Civil Rights and Civil Liberties of the Department as appropriate and in accordance with section 142 of this title.

30In accordance with sections 142 and 345 of this title, the Chief Privacy Officer shall conduct privacy impact assessments and the Officer for Civil Rights and Civil Liberties shall conduct reviews, as appropriate, for research and development initiatives developed under this section that the Secretary determines could have an impact on privacy, civil rights, or civil liberties.

31Out of funds appropriated pursuant to section 114(w) 1 of title 49, there shall be made available to the Secretary to carry out this section—

32(A) $33,000,000 for fiscal year 2008;

33(B) $33,000,000 for fiscal year 2009;

34(C) $33,000,000 for fiscal year 2010; and

35(D) $33,000,000 for fiscal year 2011.

36Such sums shall remain available until expended.

1169.

Railroad tank car security testing

1The Secretary shall assess the likely methods of a deliberate terrorist attack against a railroad tank car used to transport toxic-inhalation-hazard materials, and for each method assessed, the degree to which it may be successful in causing death, injury, or serious adverse effects to human health, the environment, critical infrastructure, national security, the national economy, or public welfare.

2In carrying out paragraph (1), the Secretary shall consider the most current threat information as to likely methods of a successful terrorist attack on a railroad tank car transporting toxic-inhalation-hazard materials, and may consider the following:

3(A) Explosive devices placed along the tracks or attached to a railroad tank car.

4(B) The use of missiles, grenades, rockets, mortars, or other high-caliber weapons against a railroad tank car.

5In developing the assessment required under paragraph (1), the Secretary shall conduct physical testing of the vulnerability of railroad tank cars used to transport toxic-inhalation-hazard materials to different methods of a deliberate attack, using technical information and criteria to evaluate the structural integrity of railroad tank cars.

6Not later than 30 days after the completion of the assessment under paragraph (1), the Secretary shall provide to the appropriate congressional committees a report, in the appropriate format, on such assessment.

7The Secretary, acting through the National Infrastructure Simulation and Analysis Center, shall conduct an air dispersion modeling analysis of release scenarios of toxic-inhalation-hazard materials resulting from a terrorist attack on a loaded railroad tank car carrying such materials in urban and rural environments.

8The analysis under this subsection shall take into account the following considerations:

9(A) The most likely means of attack and the resulting dispersal rate.

10(B) Different times of day, to account for differences in cloud coverage and other atmospheric conditions in the environment being modeled.

11(C) Differences in population size and density.

12(D) Historically accurate wind speeds, temperatures, and wind directions.

13(E) Differences in dispersal rates or other relevant factors related to whether a railroad tank car is in motion or stationary.

14(F) Emergency response procedures by local officials.

15(G) Any other considerations the Secretary believes would develop an accurate, plausible dispersion model for toxic-inhalation-hazard materials released from a railroad tank car as a result of a terrorist act.

16In conducting the dispersion modeling under paragraph (1), the Secretary shall consult with the Secretary of Transportation, hazardous materials experts, railroad carriers, nonprofit employee labor organizations representing railroad employees, appropriate State, local, and tribal officials, and other Federal agencies, as appropriate.

17Upon completion of the analysis required under paragraph (1), the Secretary shall share the information developed with the appropriate stakeholders, given appropriate information protection provisions as may be required by the Secretary.

18Not later than 30 days after completion of all dispersion analyses under paragraph (1), the Secretary shall submit to the appropriate congressional committees a report detailing the Secretary's conclusions and findings in an appropriate format.

1170.

Security background checks of covered individuals

1In this section, the following definitions apply:

2The term "security background check" means reviewing, for the purpose of identifying individuals who may pose a threat to transportation security or national security, or of terrorism—

3(A) relevant criminal history databases;

4(B) in the case of an alien (as defined in the Immigration and Nationality Act (8 U.S.C. 1101(a)(3)),1 the relevant databases to determine the status of the alien under the immigration laws of the United States; and

5(C) other relevant information or databases, as determined by the Secretary.

6The term "covered individual" means an employee of a railroad carrier or a contractor or subcontractor of a railroad carrier.

7(1) Any guidance, recommendations, suggested action items, or any other widely disseminated voluntary action items issued by the Secretary to a railroad carrier or a contractor or subcontractor of a railroad carrier relating to performing a security background check of a covered individual shall contain recommendations on the appropriate scope and application of such a security background check, including the time period covered, the types of disqualifying offenses, and a redress process for adversely impacted covered individuals consistent with subsections (c) and (d) of this section.

8(2) Within 60 days after August 3, 2007, any guidance, recommendations, suggested action items, or any other widely disseminated voluntary action item issued by the Secretary prior to August 3, 2007, to a railroad carrier or a contractor or subcontractor of a railroad carrier relating to performing a security background check of a covered individual shall be updated in compliance with paragraph (1).

9(3) If a railroad carrier or a contractor or subcontractor of a railroad carrier performs a security background check on a covered individual to fulfill guidance issued by the Secretary under paragraph (1) or (2), the Secretary shall not consider such guidance fulfilled unless an adequate redress process as described in subsection (d) is provided to covered individuals.

10If the Secretary issues a rule, regulation, or directive requiring a railroad carrier or contractor or subcontractor of a railroad carrier to perform a security background check of a covered individual, then the Secretary shall prohibit the railroad carrier or contractor or subcontractor of a railroad carrier from making an adverse employment decision, including removal or suspension of the covered individual, due to such rule, regulation, or directive with respect to a covered individual unless the railroad carrier or contractor or subcontractor of a railroad carrier determines that the covered individual—

11(1) has been convicted of, has been found not guilty by reason of insanity, or is under want, warrant, or indictment for a permanent disqualifying criminal offense listed in part 1572 of title 49, Code of Federal Regulations;

12(2) was convicted of or found not guilty by reason of insanity of an interim disqualifying criminal offense listed in part 1572 of title 49, Code of Federal Regulations, within 7 years of the date that the railroad carrier or contractor or subcontractor of a railroad carrier performs the security background check; or

13(3) was incarcerated for an interim disqualifying criminal offense listed in part 1572 of title 49, Code of Federal Regulations, and released from incarceration within 5 years of the date that the railroad carrier or contractor or subcontractor of a railroad carrier performs the security background check.

14If the Secretary issues a rule, regulation, or directive requiring a railroad carrier or contractor or subcontractor of a railroad carrier to perform a security background check of a covered individual, the Secretary shall—

15(1) provide an adequate redress process for a covered individual subjected to an adverse employment decision, including removal or suspension of the employee, due to such rule, regulation, or directive that is consistent with the appeals and waiver process established for applicants for commercial motor vehicle hazardous materials endorsements and transportation employees at ports, as required by section 70105(c) of title 46; and

16(2) have the authority to order an appropriate remedy, including reinstatement of the covered individual, should the Secretary determine that a railroad carrier or contractor or subcontractor of a railroad carrier wrongfully made an adverse employment decision regarding a covered individual pursuant to such rule, regulation, or directive.

17A railroad carrier or a contractor or subcontractor of a railroad carrier may not knowingly misrepresent to an employee or other relevant person, including an arbiter involved in a labor arbitration, the scope, application, or meaning of any rules, regulations, directives, or guidance issued by the Secretary related to security background check requirements for covered individuals when conducting a security background check. Not later than 1 year after August 3, 2007, the Secretary shall issue a regulation that prohibits a railroad carrier or a contractor or subcontractor of a railroad carrier from knowingly misrepresenting to an employee or other relevant person, including an arbiter involved in a labor arbitration, the scope, application, or meaning of any rules, regulations, directives, or guidance issued by the Secretary related to security background check requirements for covered individuals when conducting a security background check.

18Nothing in this section shall be construed to abridge a railroad carrier's or a contractor or subcontractor of a railroad carrier's rights or responsibilities to make adverse employment decisions permitted by other Federal, State, or local laws. Nothing in the section shall be construed to abridge rights and responsibilities of covered individuals, a railroad carrier, or a contractor or subcontractor of a railroad carrier, under any other Federal, State, or local laws or under any collective bargaining agreement.

19Nothing in this section shall be construed to preempt a Federal, State, or local law that requires criminal history background checks, immigration status checks, or other background checks, of covered individuals.

20Nothing in this section shall be construed to affect the process for review established under section 70105(c) of title 46, including regulations issued pursuant to such section.

1171.

International railroad security program

1(1) The Secretary shall develop a system to detect both undeclared passengers and contraband, with a primary focus on the detection of nuclear and radiological materials entering the United States by railroad.

2(2) System requirements.—In developing the system under paragraph (1), the Secretary may, in consultation with the Domestic Nuclear Detection Office,1 Customs and Border Protection, and the Transportation Security Administration—

3(A) deploy radiation detection equipment and nonintrusive imaging equipment at locations where railroad shipments cross an international border to enter the United States;

4(B) consider the integration of radiation detection technologies with other nonintrusive inspection technologies where feasible;

5(C) ensure appropriate training, operations, and response protocols are established for Federal, State, and local personnel;

6(D) implement alternative procedures to check railroad shipments at locations where the deployment of nonintrusive inspection imaging equipment is determined to not be practicable;

7(E) ensure, to the extent practicable, that such technologies deployed can detect terrorists or weapons, including weapons of mass destruction; and

8(F) take other actions, as appropriate, to develop the system.

9The Secretary shall—

10(1) identify and seek the submission of additional data elements for improved high-risk targeting related to the movement of cargo through the international supply chain utilizing a railroad prior to importation into the United States;

11(2) utilize data collected and maintained by the Secretary of Transportation in the targeting of high-risk cargo identified under paragraph (1); and

12(3) analyze the data provided in this subsection to identify high-risk cargo for inspection.

13Not later than September 30, 2008, the Secretary shall transmit to the appropriate congressional committees a report that describes the progress of the system being developed under subsection (a).

14In this section:

15The term "international supply chain" means the end-to-end process for shipping goods to or from the United States, beginning at the point of origin (including manufacturer, supplier, or vendor) through a point of distribution to the destination.

16The term "radiation detection equipment" means any technology that is capable of detecting or identifying nuclear and radiological material or nuclear and radiological explosive devices.

17The term "inspection" means the comprehensive process used by Customs and Border Protection to assess goods entering the United States to appraise them for duty purposes, to detect the presence of restricted or prohibited items, and to ensure compliance with all applicable laws.

1172.

Railroad security enhancements; Model State legislation

1Not later than November 2, 2007, the Secretary of Transportation shall develop and make available to States model legislation to address the problem of entities that claim to be railroad carriers in order to establish and run a police force when the entities do not in fact provide railroad transportation. In developing the model State legislation the Secretary shall solicit the input of the States, railroads carriers, and railroad carrier employees. The Secretary shall review and, if necessary, revise such model State legislation periodically.

1181.

Over-the-road bus security assessments and plans

1Not later than 18 months after August 3, 2007, the Secretary shall issue regulations that—

2(1) require each over-the-road bus operator assigned to a high-risk tier under this section—

3(A) to conduct a vulnerability assessment in accordance with subsections (c) and (d); and

4(B) to prepare, submit to the Secretary for approval, and implement a security plan in accordance with subsection (e); and

5(2) establish standards and guidelines for developing and implementing the vulnerability assessments and security plans for carriers assigned to high-risk tiers consistent with this section.

6The Secretary may establish a security program for over-the-road bus operators not assigned to a high-risk tier, including—

7(1) guidance for such operators in conducting vulnerability assessments and preparing and implementing security plans, as determined appropriate by the Secretary; and

8(2) a process to review and approve such assessments and plans, as appropriate.

9Not later than 9 months after the date of issuance of the regulations under subsection (a), the vulnerability assessments and security plans required by such regulations for over-the-road bus operators assigned to a high-risk tier shall be completed and submitted to the Secretary for review and approval.

10The Secretary shall provide technical assistance and guidance to over-the-road bus operators in conducting vulnerability assessments under this section and shall require that each vulnerability assessment of an operator assigned to a high-risk tier under this section includes, as appropriate—

11(A) identification and evaluation of critical assets and infrastructure, including platforms, stations, terminals, and information systems;

12(B) identification of the vulnerabilities to those assets and infrastructure; and

13(C) identification of weaknesses in—

14(i) physical security;

15(ii) passenger and cargo security;

16(iii) the security of programmable electronic devices, computers, or other automated systems which are used in providing over-the-road bus transportation;

17(iv) alarms, cameras, and other protection systems;

18(v) communications systems and utilities needed for over-the-road bus security purposes, including dispatching systems;

19(vi) emergency response planning;

20(vii) employee training; and

21(viii) such other matters as the Secretary determines appropriate.

22The Secretary shall provide in a timely manner to the appropriate employees of an over-the-road bus operator, as designated by the over-the-road bus operator, threat information that is relevant to the operator when preparing and submitting a vulnerability assessment and security plan, including an assessment of the most likely methods that could be used by terrorists to exploit weaknesses in over-the-road bus security.

23The Secretary shall provide technical assistance and guidance to over-the-road bus operators in preparing and implementing security plans under this section and shall require that each security plan of an over-the-road bus operator assigned to a high-risk tier under this section includes, as appropriate—

24(A) the identification of a security coordinator having authority—

25(i) to implement security actions under the plan;

26(ii) to coordinate security improvements; and

27(iii) to receive communications from appropriate Federal officials regarding over-the-road bus security;

28(B) a list of needed capital and operational improvements;

29(C) procedures to be implemented or used by the over-the-road bus operator in response to a terrorist attack, including evacuation and passenger communication plans that include individuals with disabilities, as appropriate;

30(D) the identification of steps taken with State and local law enforcement agencies, emergency responders, and Federal officials to coordinate security measures and plans for response to a terrorist attack;

31(E) a strategy and timeline for conducting training under section 1184 of this title;

32(F) enhanced security measures to be taken by the over-the-road bus operator when the Secretary declares a period of heightened security risk;

33(G) plans for providing redundant and backup systems required to ensure the continued operation of critical elements of the over-the-road bus operator's system in the event of a terrorist attack or other incident; and

34(H) such other actions or procedures as the Secretary determines are appropriate to address the security of over-the-road bus operators.

35The Secretary shall require that the individual serving as the security coordinator identified in paragraph (1)(A) is a citizen of the United States. The Secretary may waive this requirement with respect to an individual if the Secretary determines that it is appropriate to do so based on a background check of the individual and a review of the consolidated terrorist watchlist.

36Not later than 6 months after receiving the assessments and plans required under this section, the Secretary shall—

37(1) review each vulnerability assessment and security plan submitted to the Secretary in accordance with subsection (c);

38(2) require amendments to any security plan that does not meet the requirements of this section; and

39(3) approve any vulnerability assessment or security plan that meets the requirements of this section.

40The Secretary may require over-the-road bus operators, during the period before the deadline established under subsection (c), to submit a security plan to implement any necessary interim security measures essential to providing adequate security of the over-the-road bus operator's system. An interim plan required under this subsection shall be superseded by a plan required under subsection (c).

41The Secretary shall assign each over-the-road bus operator to a risk-based tier established by the Secretary:

42The Secretary may request, and an over-the-road bus operator shall provide, information necessary for the Secretary to assign an over-the-road bus operator to the appropriate tier under this subsection.

43Not later than 60 days after the date an over-the-road bus operator is assigned to a tier under this section, the Secretary shall notify the operator of the tier to which it is assigned and the reasons for such assignment.

44At least one of the tiers established by the Secretary under this section shall be a tier designated for high-risk over-the-road bus operators.

45The Secretary may reassign an over-the-road bus operator to another tier, as appropriate, in response to changes in risk and the Secretary shall notify the over-the-road bus operator within 60 days after such reassignment and provide the operator with the reasons for such reassignment.

46In response to a petition by an over-the-road bus operator or at the discretion of the Secretary, the Secretary may determine that existing procedures, protocols, and standards meet all or part of the requirements of this section regarding vulnerability assessments and security plans.

47Upon review and written determination by the Secretary that existing procedures, protocols, or standards of an over-the-road bus operator satisfy the requirements of this section, the over-the-road bus operator may elect to comply with those procedures, protocols, or standards instead of the requirements of this section.

48If the Secretary determines that the existing procedures, protocols, or standards of an over-the-road bus operator satisfy only part of the requirements of this section, the Secretary may accept such submission, but shall require submission by the operator of any additional information relevant to the vulnerability assessment and security plan of the operator to ensure that the remaining requirements of this section are fulfilled.

49If the Secretary determines that particular existing procedures, protocols, or standards of an over-the-road bus operator under this subsection do not satisfy the requirements of this section, the Secretary shall provide to the operator a written notification that includes an explanation of the reasons for nonacceptance.

50Nothing in this subsection shall relieve the Secretary of the obligation—

51(A) to review the vulnerability assessment and security plan submitted by an over-the-road bus operator under this section; and

52(B) to approve or disapprove each submission on an individual basis.

53Not later than 3 years after the date on which a vulnerability assessment or security plan required to be submitted to the Secretary under subsection (c) is approved, and at least once every 5 years thereafter (or on such a schedule as the Secretary may establish by regulation), an over-the-road bus operator who submitted a vulnerability assessment and security plan and who is still assigned to the high-risk tier shall also submit to the Secretary an evaluation of the adequacy of the vulnerability assessment and security plan that includes a description of any material changes made to the vulnerability assessment or security plan.

54Not later than 180 days after the date on which an evaluation is submitted, the Secretary shall review the evaluation and notify the over-the-road bus operator submitting the evaluation of the Secretary's approval or disapproval of the evaluation.

55The Secretary may permit under this section the development and implementation of coordinated vulnerability assessments and security plans to the extent that an over-the-road bus operator shares facilities with, or is colocated with, other transportation entities or providers that are required to develop vulnerability assessments and security plans under Federal law.

56Nothing in this section shall be construed as authorizing the withholding of any information from Congress.

57Nothing in this section shall be construed as affecting any authority or obligation of a Federal agency to disclose any record or information that the Federal agency obtains from an over-the-road bus operator under any other Federal law.

1182.

Over-the-road bus security assistance

1The Secretary shall establish a program for making grants to eligible private operators providing transportation by an over-the-road bus for security improvements described in subsection (b).

2A recipient of a grant received under subsection (a) shall use the grant funds for one or more of the following:

3(1) Constructing and modifying terminals, garages, and facilities, including terminals and other over-the-road bus facilities owned by State or local governments, to increase their security.

4(2) Modifying over-the-road buses to increase their security.

5(3) Protecting or isolating the driver of an over-the-road bus.

6(4) Acquiring, upgrading, installing, or operating equipment, software, or accessorial services for collection, storage, or exchange of passenger and driver information through ticketing systems or other means and for information links with government agencies, for security purposes.

7(5) Installing cameras and video surveillance equipment on over-the-road buses and at terminals, garages, and over-the-road bus facilities.

8(6) Establishing and improving an emergency communications system linking drivers and over-the-road buses to the recipient's operations center or linking the operations center to law enforcement and emergency personnel.

9(7) Implementing and operating passenger screening programs for weapons and explosives.

10(8) Public awareness campaigns for enhanced over-the-road bus security.

11(9) Operating and capital costs associated with over-the-road bus security awareness, preparedness, and response training, including training under section 1184 of this title and training developed by institutions of higher education and by nonprofit employee labor organizations, for over-the-road bus employees, including frontline employees.

12(10) Chemical, biological, radiological, or explosive detection, including canine patrols for such detection.

13(11) Overtime reimbursement, including reimbursement of State, local, and tribal governments for costs, for enhanced security personnel assigned to duties related to over-the-road bus security during periods of high or severe threat levels, National Special Security Events, or other periods of heightened security as determined by the Secretary.

14(12) Live or simulated exercises, including those described in section 1183 of this title.

15(13) Operational costs to hire, train, and employ police and security officers, including canine units, assigned to full-time security or counterterrorism duties related to over-the-road bus transportation, including reimbursement of State, local, and tribal government costs for such personnel.

16(14) Development of assessments or security plans under section 1181 of this title.

17(15) Such other improvements as the Secretary considers appropriate.

18In making grants under this section, the Secretary shall prioritize grant funding based on security risks to bus passengers and the ability of a project to reduce, or enhance response to, that risk, and shall not penalize private operators of over-the-road buses that have taken measures to enhance over-the-road bus transportation security prior to September 11, 2001.

19In carrying out the responsibilities under subsection (a), the Secretary shall—

20(1) determine the requirements for recipients of grants under this section, including application requirements;

21(2) select grant recipients;

22(3) award the funds authorized by this section based on risk, as identified by the plans required under section 1181 of this title or assessment or plan described in subsection (f)(2); and

23(4) pursuant to subsection (c), establish priorities for the use of funds for grant recipients.

24Not later than 90 days after August 3, 2007, the Secretary and the Secretary of Transportation shall determine the most effective and efficient way to distribute grant funds to the recipients of grants determined by the Secretary under subsection (a). Subject to the determination made by the Secretaries, the Secretary may transfer funds to the Secretary of Transportation for the purposes of disbursing funds to the grant recipient.

25(1) A private operator providing transportation by an over-the-road bus is eligible for a grant under this section if the operator has completed a vulnerability assessment and developed a security plan that the Secretary has approved under section 1181 of this title. Grant funds may only be used for permissible uses under subsection (b) to further an over-the-road bus security plan.

26(2) Notwithstanding the requirements for eligibility and uses in paragraph (1), prior to the earlier of 1 year after the date of issuance of final regulations requiring vulnerability assessments and security plans under section 1181 of this title or 3 years after August 3, 2007, the Secretary may award grants under this section for over-the-road bus security improvements listed under subsection (b) based upon over-the-road bus vulnerability assessments and security plans that the Secretary deems are sufficient for the purposes of this section but have not been approved by the Secretary in accordance with section 1181 of this title.

27Except as otherwise specifically provided in this section, a grant made under this section shall be subject to the terms and conditions applicable to subrecipients who provide over-the-road bus transportation under section 5311(f) of title 49 and such other terms and conditions as are determined necessary by the Secretary.

28A grant made under this section may not be used to make any State or local government cost-sharing contribution under any other Federal law.

29Each recipient of a grant under this section shall report annually to the Secretary and on the use of such grant funds.

30In carrying out this section, the Secretary shall consult with over-the-road bus operators and nonprofit employee labor organizations representing over-the-road bus employees, public safety and law enforcement officials.

31From the amounts appropriated pursuant to section 114(w) 1 of title 49, there shall be made available to the Secretary to make grants under this section—

32(A) $12,000,000 for fiscal year 2008;

33(B) $25,000,000 for fiscal year 2009;

34(C) $25,000,000 for fiscal year 2010; and

35(D) $25,000,000 for fiscal year 2011.

36Sums appropriated to carry out this section shall remain available until expended.

1183.

Over-the-road bus exercises

1The Secretary shall establish a program for conducting security exercises for over-the-road bus transportation for the purpose of assessing and improving the capabilities of entities described in subsection (b) to prevent, prepare for, mitigate, respond to, and recover from acts of terrorism.

2Entities to be assessed under the program shall include—

3(1) Federal, State, and local agencies and tribal governments;

4(2) over-the-road bus operators and over-the-road bus terminal owners and operators;

5(3) governmental and nongovernmental emergency response providers and law enforcement agencies; and

6(4) any other organization or entity that the Secretary determines appropriate.

7The Secretary shall ensure that the program—

8(1) consolidates existing security exercises for over-the-road bus operators and terminals administered by the Department and the Department of Transportation, as jointly determined by the Secretary and the Secretary of Transportation, unless the Secretary waives this consolidation requirement, as appropriate;

9(2) consists of exercises that are—

10(A) scaled and tailored to the needs of the over-the-road bus operators and terminals, including addressing the needs of the elderly and individuals with disabilities;

11(B) live, in the case of the most at-risk facilities to a terrorist attack;

12(C) coordinated with appropriate officials;

13(D) as realistic as practicable and based on current risk assessments, including credible threats, vulnerabilities, and consequences;

14(E) inclusive, as appropriate, of over-the-road bus frontline employees; and

15(F) consistent with the National Incident Management System, the National Response Plan, the National Infrastructure Protection Plan, the National Preparedness Guidance, the National Preparedness Goal, and other such national initiatives;

16(3) provides that exercises described in paragraph (2) will be—

17(A) evaluated by the Secretary against clear and consistent performance measures;

18(B) assessed by the Secretary to identify best practices, which shall be shared, as appropriate, with operators providing over-the-road bus transportation, nonprofit employee organizations that represent over-the-road bus employees, Federal, State, local, and tribal officials, governmental and nongovernmental emergency response providers, and law enforcement personnel; and

19(C) used to develop recommendations, as appropriate, provided to over-the-road bus operators and terminal owners and operators on remedial action to be taken in response to lessons learned;

20(4) allows for proper advanced notification of communities and local governments in which exercises are held, as appropriate; and

21(5) assists State, local, and tribal governments and over-the-road bus operators and terminal owners and operators in designing, implementing, and evaluating additional exercises that conform to the requirements of paragraph (2).

22The Secretary shall ensure that the exercise program developed under subsection (c) is consistent with the National Exercise Program established under section 748 of this title.

1184.

Over-the-road bus security training program

1Not later than 6 months after August 3, 2007, the Secretary shall develop and issue regulations for an over-the-road bus training program to prepare over-the-road bus frontline employees for potential security threats and conditions. The regulations shall take into consideration any current security training requirements or best practices.

2The Secretary shall develop regulations under subsection (a) in consultation with—

3(1) appropriate law enforcement, fire service, emergency response, security, and terrorism experts;

4(2) operators providing over-the-road bus transportation; and

5(3) nonprofit employee labor organizations representing over-the-road bus employees and emergency response personnel.

6The regulations developed under subsection (a) shall require security training programs, to include, at a minimum, elements to address the following, as applicable:

7(1) Determination of the seriousness of any occurrence or threat.

8(2) Driver and passenger communication and coordination.

9(3) Appropriate responses to defend or protect oneself.

10(4) Use of personal and other protective equipment.

11(5) Evacuation procedures for passengers and over-the-road bus employees, including individuals with disabilities and the elderly.

12(6) Psychology, behavior, and methods of terrorists, including observation and analysis.

13(7) Training related to psychological responses to terrorist incidents, including the ability to cope with hijacker behavior and passenger responses.

14(8) Live situational training exercises regarding various threat conditions, including tunnel evacuation procedures.

15(9) Recognition and reporting of dangerous substances, suspicious packages, and situations.

16(10) Understanding security incident procedures, including procedures for communicating with emergency response providers and for on-scene interaction with such emergency response providers.

17(11) Operation and maintenance of security equipment and systems.

18(12) Other security training activities that the Secretary considers appropriate.

19Not later than 90 days after the Secretary issues the regulations under subsection (a), each over-the-road bus operator shall develop a security training program in accordance with such regulations and submit the program to the Secretary for approval.

20Not later than 60 days after receiving a security training program under this subsection, the Secretary shall approve the program or require the over-the-road bus operator that developed the program to make any revisions to the program that the Secretary considers necessary for the program to meet the requirements of the regulations. An over-the-road bus operator shall respond to the Secretary's comments not later than 30 days after receiving them.

21Not later than 1 year after the Secretary approves a security training program in accordance with this subsection, the over-the-road bus operator that developed the program shall complete the training of all over-the-road bus frontline employees who were hired by the operator more than 30 days preceding such date. For such employees employed less than 30 days by an operator preceding such date, training shall be completed within the first 60 days of employment.

22The Secretary shall periodically review and update, as appropriate, the training regulations issued under subsection (a) to reflect new or changing security threats. Each over-the-road bus operator shall revise its training program accordingly and provide additional training as necessary to its employees within a reasonable time after the regulations are updated.

23The Secretary shall ensure that the training program developed under subsection (a) is a component of the National Training Program established under section 748 of this title.

24Not later than 2 years after the date of regulation issuance, the Secretary shall review implementation of the training program of a representative sample of over-the-road bus operators and over-the-road bus frontline employees, and report to the appropriate congressional committees of such reviews. The Secretary may submit the report in both classified and redacted formats as necessary.

1185.

Over-the-road bus security research and development

1The Secretary, acting through the Under Secretary for Science and Technology and the Administrator of the Transportation Security Administration, shall carry out a research and development program for the purpose of improving the security of over-the-road buses.

2The research and development program may include projects—

3(1) to reduce the vulnerability of over-the-road buses, stations, terminals, and equipment to explosives and hazardous chemical, biological, and radioactive substances, including the development of technology to screen passengers in large numbers with minimal interference and disruption;

4(2) to test new emergency response and recovery techniques and technologies, including those used at international borders;

5(3) to develop improved technologies, including those for—

6(A) emergency response training, including training in a tunnel environment, if appropriate; and

7(B) security and redundancy for critical communications, electrical power, computer, and over-the-road bus control systems; and

8(4) to address other vulnerabilities and risks identified by the Secretary.

9The Secretary—

10(1) shall ensure that the research and development program is consistent with the other transportation security research and development programs required by this Act;

11(2) shall, to the extent practicable, coordinate the research and development activities of the Department with other ongoing research and development security-related initiatives, including research being conducted by—

12(A) the Department of Transportation, including University Transportation Centers and other institutes, centers, and simulators funded by the Department of Transportation;

13(B) the National Academy of Sciences;

14(C) the Technical Support Working Group;

15(D) other Federal departments and agencies; and

16(E) other Federal and private research laboratories, research entities, and institutions of higher education, including Historically Black Colleges and Universities, Hispanic Serving Institutions, and Indian Tribally Controlled Colleges and Universities;

17(3) shall carry out any research and development project authorized by this section through a reimbursable agreement with an appropriate Federal agency, if the agency—

18(A) is currently sponsoring a research and development project in a similar area; or

19(B) has a unique facility or capability that would be useful in carrying out the project;

20(4) may award grants and enter into cooperative agreements, contracts, other transactions, or reimbursable agreements to the entities described in paragraph (2) and eligible recipients under section 1182 of this title; and

21(5) shall make reasonable efforts to enter into memoranda of understanding, contracts, grants, cooperative agreements, or other transactions with private operators providing over-the-road bus transportation willing to contribute assets, physical space, and other resources.

22In carrying out research and development projects under this section, the Secretary shall consult with the Chief Privacy Officer of the Department and the Officer for Civil Rights and Civil Liberties of the Department as appropriate and in accordance with section 142 of this title.

23In accordance with sections 142 and 345 of this title, the Chief Privacy Officer shall conduct privacy impact assessments and the Officer for Civil Rights and Civil Liberties shall conduct reviews, as appropriate, for research and development initiatives developed under this section that the Secretary determines could have an impact on privacy, civil rights, or civil liberties.

24From the amounts appropriated pursuant to section 114(w) 1 of title 49, there shall be made available to the Secretary to carry out this section—

25(A) $2,000,000 for fiscal year 2008;

26(B) $2,000,000 for fiscal year 2009;

27(C) $2,000,000 for fiscal year 2010; and

28(D) $2,000,000 for fiscal year 2011.

29Such sums shall remain available until expended.

1186.

Memorandum of Understanding annex

1Not later than 1 year after August 3, 2007, the Secretary of Transportation and the Secretary shall execute and develop an annex to the Memorandum of Understanding between the two departments signed on September 28, 2004, governing the specific roles, delineations of responsibilities, resources, and commitments of the Department of Transportation and the Department of Homeland Security, respectively, in addressing motor carrier transportation security matters, including over-the-road bus security matters, and shall cover the processes the Departments will follow to promote communications, efficiency, and nonduplication of effort.

1201.

Railroad routing of security-sensitive materials

1Not later than 9 months after August 3, 2007, the Secretary of Transportation, in consultation with the Secretary, shall publish a final rule based on the Pipeline and Hazardous Materials Safety Administration's Notice of Proposed Rulemaking published on December 21, 2006, entitled "Hazardous Materials: Enhancing Railroad Transportation Safety and Security for Hazardous Materials Shipments". The final rule shall incorporate the requirements of this section and, as appropriate, public comments received during the comment period of the rulemaking.

2The Secretary of Transportation shall ensure that the final rule requires each railroad carrier transporting security-sensitive materials in commerce to, no later than 90 days after the end of each calendar year, compile security-sensitive materials commodity data. Such data must be collected by route, line segment, or series of line segments, as aggregated by the railroad carrier. Within the railroad carrier selected route, the commodity data must identify the geographic location of the route and the total number of shipments by the United Nations identification number for the security-sensitive materials.

3The Secretary of Transportation shall ensure that the final rule requires each railroad carrier transporting security-sensitive materials in commerce to, for each calendar year, provide a written analysis of the safety and security risks for the transportation routes identified in the security-sensitive materials commodity data collected as required by subsection (b). The safety and security risks present shall be analyzed for the route, railroad facilities, railroad storage facilities, and high-consequence targets along or in proximity to the route.

4The Secretary of Transportation shall ensure that the final rule requires each railroad carrier transporting security-sensitive materials in commerce to—

5(1) for each calendar year—

6(A) identify practicable alternative routes over which the railroad carrier has authority to operate as compared to the current route for such a shipment analyzed under subsection (c); and

7(B) perform a safety and security risk assessment of the alternative route for comparison to the route analysis specified in subsection (c);

8(2) ensure that the analysis under paragraph (1) includes—

9(A) identification of safety and security risks for an alternative route;

10(B) comparison of those risks identified under subparagraph (A) to the primary railroad transportation route, including the risk of a catastrophic release from a shipment traveling along the alternate route compared to the primary route;

11(C) any remediation or mitigation measures implemented on the primary or alternative route; and

12(D) potential economic effects of using an alternative route; and

13(3) consider when determining the practicable alternative routes under paragraph (1)(A) the use of interchange agreements with other railroad carriers.

14The Secretary of Transportation shall ensure that the final rule requires each railroad carrier transporting security-sensitive materials in commerce to use the analysis required by subsections (c) and (d) to select the safest and most secure route to be used in transporting security-sensitive materials.

15The Secretary of Transportation shall ensure that the final rule requires each railroad carrier transporting security-sensitive materials in commerce to annually review and select the practicable route posing the least overall safety and security risk in accordance with this section. The railroad carrier must retain in writing all route review and selection decision documentation and restrict the distribution, disclosure, and availability of information contained in the route analysis to appropriate persons. This documentation should include, but is not limited to, comparative analyses, charts, graphics, or railroad system maps.

16The Secretary of Transportation shall ensure that the final rule requires each railroad carrier transporting security-sensitive materials in commerce to, not less than once every 3 years, analyze the route selection determinations required under this section. Such an analysis shall include a comprehensive, systemwide review of all operational changes, infrastructure modifications, traffic adjustments, changes in the nature of high-consequence targets located along or in proximity to the route, or other changes affecting the safety and security of the movements of security-sensitive materials that were implemented since the previous analysis was completed.

17In carrying out subsection (c), railroad carriers transporting security-sensitive materials in commerce shall seek relevant information from State, local, and tribal officials, as appropriate, regarding security risks to high-consequence targets along or in proximity to a route used by a railroad carrier to transport security-sensitive materials.

18In this section:

19(1) The term "route" includes storage facilities and trackage used by railroad cars in transportation in commerce.

20(2) The term "high-consequence target" means a property, natural resource, location, area, or other target designated by the Secretary that is a viable terrorist target of national significance, which may include a facility or specific critical infrastructure, the attack of which by railroad could result in—

21(A) catastrophic loss of life;

22(B) significant damage to national security or defense capabilities; or

23(C) national economic harm.

1202.

Railroad security-sensitive material tracking

1In conjunction with the research and development program established under section 1168 of this title and consistent with the results of research relating to wireless and other tracking technologies, the Secretary, in consultation with the Administrator of the Transportation Security Administration, shall develop a program that will encourage the equipping of railroad cars transporting security-sensitive materials, as defined in section 1151 of this title, with technology that provides—

2(A) car position location and tracking capabilities; and

3(B) notification of railroad car depressurization, breach, unsafe temperature, or release of hazardous materials, as appropriate.

4In developing the program required by paragraph (1), the Secretary shall—

5(A) consult with the Secretary of Transportation to coordinate the program with any ongoing or planned efforts for railroad car tracking at the Department of Transportation; and

6(B) ensure that the program is consistent with recommendations and findings of the Department of Homeland Security's hazardous material railroad tank car tracking pilot programs.

7From the amounts appropriated pursuant to 114(w) of title 49, there shall be made available to the Secretary to carry out this section—

8(1) $3,000,000 for fiscal year 2008;

9(2) $3,000,000 for fiscal year 2009; and

10(3) $3,000,000 for fiscal year 2010.

1203.

Hazardous materials highway routing

1Not later than 1 year after August 3, 2007, the Secretary of Transportation, in consultation with the Secretary, shall—

2(1) document existing and proposed routes for the transportation of radioactive and nonradioactive hazardous materials by motor carrier, and develop a framework for using a geographic information system-based approach to characterize routes in the national hazardous materials route registry;

3(2) assess and characterize existing and proposed routes for the transportation of radioactive and nonradioactive hazardous materials by motor carrier for the purpose of identifying measurable criteria for selecting routes based on safety and security concerns;

4(3) analyze current route-related hazardous materials regulations in the United States, Canada, and Mexico to identify cross-border differences and conflicting regulations;

5(4) document the safety and security concerns of the public, motor carriers, and State, local, territorial, and tribal governments about the highway routing of hazardous materials;

6(5) prepare guidance materials for State officials to assist them in identifying and reducing both safety concerns and security risks when designating highway routes for hazardous materials consistent with the 13 safety-based nonradioactive materials routing criteria and radioactive materials routing criteria in subpart C part 397 of title 49, Code of Federal Regulations;

7(6) develop a tool that will enable State officials to examine potential routes for the highway transportation of hazardous materials, assess specific security risks associated with each route, and explore alternative mitigation measures; and

8(7) transmit to the appropriate congressional committees a report on the actions taken to fulfill paragraphs (1) through (6) and any recommended changes to the routing requirements for the highway transportation of hazardous materials in part 397 of title 49, Code of Federal Regulations.

9Not later than 1 year after August 3, 2007, the Secretary of Transportation shall complete an assessment of the safety and national security benefits achieved under existing requirements for route plans, in written or electronic format, for explosives and radioactive materials. The assessment shall, at a minimum—

10(A) compare the percentage of Department of Transportation recordable incidents and the severity of such incidents for shipments of explosives and radioactive materials for which such route plans are required with the percentage of recordable incidents and the severity of such incidents for shipments of explosives and radioactive materials not subject to such route plans; and

11(B) quantify the security and safety benefits, feasibility, and costs of requiring each motor carrier that is required to have a hazardous material safety permit under part 385 of title 49, Code of Federal Regulations, to maintain, follow, and carry such a route plan that meets the requirements of section 397.101 of that title when transporting the type and quantity of hazardous materials described in section 385.403, taking into account the various segments of the motor carrier industry, including tank truck, truckload and less than truckload carriers.

12Not later than 1 year after August 3, 2007, the Secretary of Transportation shall submit a report to the appropriate congressional committees containing the findings and conclusions of the assessment.

13The Secretary shall require motor carriers that have a hazardous material safety permit under part 385 of title 49, Code of Federal Regulations, to maintain, follow, and carry a route plan, in written or electronic format, that meets the requirements of section 397.101 of that title when transporting the type and quantity of hazardous materials described in section 385.403 if the Secretary determines, under the assessment required in subsection (b), that such a requirement would enhance security and safety without imposing unreasonable costs or burdens upon motor carriers.

1204.

Motor carrier security-sensitive material tracking

1Not later than 6 months after August 3, 2007, consistent with the findings of the Transportation Security Administration's hazardous materials truck security pilot program, the Secretary, through the Administrator of the Transportation Security Administration and in consultation with the Secretary of Transportation, shall develop a program to facilitate the tracking of motor carrier shipments of security-sensitive materials and to equip vehicles used in such shipments with technology that provides—

2(A) frequent or continuous communications;

3(B) vehicle position location and tracking capabilities; and

4(C) a feature that allows a driver of such vehicles to broadcast an emergency distress signal.

5In developing the program required by paragraph (1), the Secretary shall—

6(A) consult with the Secretary of Transportation to coordinate the program with any ongoing or planned efforts for motor carrier or security-sensitive materials tracking at the Department of Transportation;

7(B) take into consideration the recommendations and findings of the report on the hazardous material safety and security operational field test released by the Federal Motor Carrier Safety Administration on November 11, 2004; and

8(C) evaluate—

9(i) any new information related to the costs and benefits of deploying, equipping, and utilizing tracking technology, including portable tracking technology, for motor carriers transporting security-sensitive materials not included in the hazardous material safety and security operational field test report released by the Federal Motor Carrier Safety Administration on November 11, 2004;

10(ii) the ability of tracking technology to resist tampering and disabling;

11(iii) the capability of tracking technology to collect, display, and store information regarding the movement of shipments of security-sensitive materials by commercial motor vehicles;

12(iv) the appropriate range of contact intervals between the tracking technology and a commercial motor vehicle transporting security-sensitive materials;

13(v) technology that allows the installation by a motor carrier of concealed electronic devices on commercial motor vehicles that can be activated by law enforcement authorities to disable the vehicle or alert emergency response resources to locate and recover security-sensitive materials in the event of loss or theft of such materials;

14(vi) whether installation of the technology described in clause (v) should be incorporated into the program under paragraph (1);

15(vii) the costs, benefits, and practicality of such technology described in clause (v) in the context of the overall benefit to national security, including commerce in transportation; and

16(viii) other systems and information the Secretary determines appropriate.

17From the amounts appropriated pursuant to section 114(w) 1 of title 49, there shall be made available to the Secretary to carry out this section—

18(1) $7,000,000 for fiscal year 2008 of which $3,000,000 may be used for equipment;

19(2) $7,000,000 for fiscal year 2009 of which $3,000,000 may be used for equipment; and

20(3) $7,000,000 for fiscal year 2010 of which $3,000,000 may be used for equipment.

21Not later than 1 year after the issuance of regulations under subsection (a), the Secretary shall issue a report to the appropriate congressional committees on the program developed and evaluation carried out under this section.

22The Secretary may not mandate the installation or utilization of a technology described under this section without additional congressional authority provided after August 3, 2007.

1205.

Hazardous materials security inspections and study

1The Secretary of Transportation shall consult with the Secretary to limit, to the extent practicable, duplicative reviews of the hazardous materials security plans required under part 172, title 49, Code of Federal Regulations.

2Within 1 year after August 3, 2007, the Secretary of Transportation, in conjunction with the Secretary, shall study to what extent the insurance, security, and safety costs borne by railroad carriers, motor carriers, pipeline carriers, air carriers, and maritime carriers associated with the transportation of hazardous materials are reflected in the rates paid by offerors of such commodities as compared to the costs and rates, respectively, for the transportation of nonhazardous materials.

1206.

Use of transportation security card in hazmat licensing

1An individual who has a valid transportation employee identification card issued by the Secretary under section 70105 of title 46 shall be deemed to have met the background records check required under section 5103a of title 49.

2Nothing in this section prevents or preempts a State from conducting a criminal records check of an individual that has applied for a license to operate a motor vehicle transporting in commerce a hazardous material.

1207.

Pipeline security inspections and enforcement

1Not later than 9 months after August 3, 2007, consistent with the Annex to the Memorandum of Understanding executed on August 9, 2006, between the Department of Transportation and the Department, the Secretary, in consultation with the Secretary of Transportation, shall establish a program for reviewing pipeline operator adoption of recommendations of the September 5, 2002, Department of Transportation Research and Special Programs Administration's Pipeline Security Information Circular, including the review of pipeline security plans and critical facility inspections.

2Not later than 12 months after August 3, 2007, the Secretary and the Secretary of Transportation shall develop and implement a plan for reviewing the pipeline security plans and an inspection of the critical facilities of the 100 most critical pipeline operators covered by the September 5, 2002, circular, where such facilities have not been inspected for security purposes since September 5, 2002, by either the Department or the Department of Transportation.

3In reviewing pipeline operator compliance under subsections (a) and (b), risk assessment methodologies shall be used to prioritize risks and to target inspection and enforcement actions to the highest risk pipeline assets.

4Not later than 18 months after August 3, 2007, the Secretary and the Secretary of Transportation shall develop and transmit to pipeline operators security recommendations for natural gas and hazardous liquid pipelines and pipeline facilities. If the Secretary determines that regulations are appropriate, the Secretary shall consult with the Secretary of Transportation on the extent of risk and appropriate mitigation measures, and the Secretary or the Secretary of Transportation, consistent with the Annex to the Memorandum of Understanding executed on August 9, 2006, shall promulgate such regulations and carry out necessary inspection and enforcement actions. Any regulations shall incorporate the guidance provided to pipeline operators by the September 5, 2002, Department of Transportation Research and Special Programs Administration's Pipeline Security Information Circular and contain additional requirements as necessary based upon the results of the inspections performed under subsection (b). The regulations shall include the imposition of civil penalties for noncompliance.

5From the amounts appropriated pursuant to section 114(w) 1 of title 49, there shall be made available to the Secretary to carry out this section—

6(1) $2,000,000 for fiscal year 2008;

7(2) $2,000,000 for fiscal year 2009; and

8(3) $2,000,000 for fiscal year 2010.

1208.

Pipeline security and incident recovery plan

1The Secretary, in consultation with the Secretary of Transportation and the Administrator of the Pipeline and Hazardous Materials Safety Administration, and in accordance with the Annex to the Memorandum of Understanding executed on August 9, 2006, the National Strategy for Transportation Security, and Homeland Security Presidential Directive–7, shall develop a pipeline security and incident recovery protocols plan. The plan shall include—

2(1) for the Government to provide increased security support to the most critical interstate and intrastate natural gas and hazardous liquid transmission pipeline infrastructure and operations as determined under section 1207 of this title when—

3(A) under severe security threat levels of alert; or

4(B) under specific security threat information relating to such pipeline infrastructure or operations exists; and

5(2) an incident recovery protocol plan, developed in conjunction with interstate and intrastate transmission and distribution pipeline operators and terminals and facilities operators connected to pipelines, to develop protocols to ensure the continued transportation of natural gas and hazardous liquids to essential markets and for essential public health or national defense uses in the event of an incident affecting the interstate and intrastate natural gas and hazardous liquid transmission and distribution pipeline system, which shall include protocols for restoring essential services supporting pipelines and granting access to pipeline operators for pipeline infrastructure repair, replacement, or bypass following an incident.

6The plan shall take into account actions taken or planned by both private and public entities to address identified pipeline security issues and assess the effective integration of such actions.

7In developing the plan under subsection (a), the Secretary shall consult with the Secretary of Transportation, interstate and intrastate transmission and distribution pipeline operators, nonprofit employee organizations representing pipeline employees, emergency responders, offerors, State pipeline safety agencies, public safety officials, and other relevant parties.

8Not later than 2 years after August 3, 2007, the Secretary shall transmit to the appropriate congressional committees a report containing the plan required by subsection (a), including an estimate of the private and public sector costs to implement any recommendations.

9The Secretary may submit the report in both classified and redacted formats if the Secretary determines that such action is appropriate or necessary.

CHAPTER 5—BORDER INFRASTRUCTURE AND TECHNOLOGY MODERNIZATION

1401.

Definitions

1In this chapter:

2The term "Commissioner" means the Commissioner of U.S. Customs and Border Protection of the Department of Homeland Security.

3The term "maquiladora" means an entity located in Mexico that assembles and produces goods from imported parts for export to the United States.

4The term "northern border" means the international border between the United States and Canada.

5The term "Secretary" means the Secretary of the Department of Homeland Security.

6The term "southern border" means the international border between the United States and Mexico.

1402

, 1403. Repealed. Pub. L. 113–188, title X, §1001(b), Nov. 26, 2014, 128 Stat. 2022

1404.

Repealed. Pub. L. 114–4, title V, §566, Mar. 4, 2015, 129 Stat. 73

1405.

Authorization of appropriations

1In addition to any funds otherwise available, there are authorized to be appropriated such sums as may be necessary to carry out this chapter for fiscal years 2009 through 2013.

2Funds authorized to be appropriated under this chapter may be used for the implementation of projects described in the Declaration on Embracing Technology and Cooperation to Promote the Secure and Efficient Flow of People and Commerce across our Shared Border between the United States and Mexico, agreed to March 22, 2002, Monterrey, Mexico (commonly known as the Border Partnership Action Plan) or the Smart Border Declaration between the United States and Canada, agreed to December 12, 2001, Ottawa, Canada that are consistent with the provisions of this chapter.

CHAPTER 6—CYBERSECURITY

1500.

National Cyber Director

1There is established, within the Executive Office of the President, the Office of the National Cyber Director (in this section referred to as the "Office").

2The Office shall be headed by the National Cyber Director (in this section referred to as the "Director") who shall be appointed by the President, by and with the advice and consent of the Senate.

3The Director shall hold office at the pleasure of the President.

4The Director shall be entitled to receive the same pay and allowances as are provided for level II of the Executive Schedule under section 5313 of title 5.

5Subject to the authority, direction, and control of the President, the Director shall—

6(A) serve as the principal advisor to the President on cybersecurity policy and strategy relating to the coordination of—

7(i) information security and data protection;

8(ii) programs and policies intended to improve the cybersecurity posture of the United States;

9(iii) efforts to understand and deter malicious cyber activity;

10(iv) efforts to increase the security of information and communications technology and services and to promote national supply chain risk management and vendor security;

11(v) diplomatic and other efforts to develop norms and international consensus around responsible state behavior in cyberspace;

12(vi) awareness and adoption of emerging technology that may enhance, augment, or degrade the cybersecurity posture of the United States; and

13(vii) such other cybersecurity matters as the President considers appropriate;

14(B) offer advice and consultation to the National Security Council and its staff, the Homeland Security Council and its staff, and relevant Federal departments and agencies, for their consideration, relating to the development and coordination of national cyber policy and strategy, including the National Cyber Strategy;

15(C) lead the coordination of implementation of national cyber policy and strategy, including the National Cyber Strategy, by—

16(i) in coordination with the heads of relevant Federal departments or agencies, monitoring and assessing the effectiveness, including cost-effectiveness, of the implementation of such national cyber policy and strategy by Federal departments and agencies;

17(ii) making recommendations, relevant to changes in the organization, personnel, and resource allocation and to policies of Federal departments and agencies, to the heads of relevant Federal departments and agencies in order to implement such national cyber policy and strategy;

18(iii) reviewing the annual budget proposals for relevant Federal departments and agencies and advising the heads of such departments and agencies whether such proposals are consistent with such national cyber policy and strategy;

19(iv) continuously assessing and making relevant recommendations to the President on the appropriate level of integration and interoperability across the Federal cyber centers;

20(v) coordinating with the Attorney General, the Federal Chief Information Officer, the Director of the Office of Management and Budget, the Director of National Intelligence, and the Director of the Cybersecurity and Infrastructure Security Agency, on the streamlining of Federal policies and guidelines, including with respect to implementation of subchapter II of chapter 35 of title 44, and, as appropriate or applicable, regulations relating to cybersecurity;

21(vi) reporting annually to the President, the Assistant to the President for National Security Affairs, and Congress on the state of the cybersecurity posture of the United States, the effectiveness of such national cyber policy and strategy, and the status of the implementation of such national cyber policy and strategy by Federal departments and agencies; and

22(vii) such other activity as the President considers appropriate to further such national cyber policy and strategy;

23(D) lead coordination of the development and ensuring implementation by the Federal Government of integrated incident response to cyberattacks and cyber campaigns of significant consequence, including—

24(i) ensuring and facilitating coordination among relevant Federal departments and agencies in the development of integrated operational plans, processes, and playbooks, including for incident response, that feature—

25(I) clear lines of authority and lines of effort across the Federal Government;

26(II) authorities that have been delegated to an appropriate level to facilitate effective operational responses across the Federal Government; and

27(III) support for the integration of defensive cyber plans and capabilities with offensive cyber plans and capabilities in a manner consistent with improving the cybersecurity posture of the United States;

28(ii) ensuring the exercising of defensive operational plans, processes, and playbooks for incident response;

29(iii) ensuring the updating of defensive operational plans, processes, and playbooks for incident response as needed to keep them updated; and

30(iv) reviewing and ensuring that defensive operational plans, processes, and playbooks improve coordination with relevant private sector entities, as appropriate;

31(E) preparing the response by the Federal Government to cyberattacks and cyber campaigns of significant consequence across Federal departments and agencies with responsibilities pertaining to cybersecurity and with the relevant private sector entities, including—

32(i) developing for the approval of the President, in coordination with the Assistant to the President for National Security Affairs and the heads of relevant Federal departments and agencies, operational priorities, requirements, and plans;

33(ii) ensuring incident response is executed consistent with the plans described in clause (i); and

34(iii) ensuring relevant Federal department and agency consultation with relevant private sector entities in incident response;

35(F) coordinate and consult with private sector leaders on cybersecurity and emerging technology issues in support of, and in coordination with, the Director of the Cybersecurity and Infrastructure Security Agency, the Director of National Intelligence, and the heads of other Federal departments and agencies, as appropriate;

36(G) annually report to Congress on cybersecurity threats and issues facing the United States, including any new or emerging technologies that may affect national security, economic prosperity, or enforcing the rule of law; and

37(H) be responsible for such other functions as the President may direct.

38(A) The Director may—

39(i) serve as the senior representative to any organization that the President may establish for the purpose of providing the President advice on cybersecurity;

40(ii) subject to subparagraph (B), be included as a participant in preparations for and, when appropriate, the execution of domestic and international summits and other international meetings at which cybersecurity is a major topic;

41(iii) delegate any of the Director's functions, powers, and duties to such officers and employees of the Office as the Director considers appropriate; and

42(iv) authorize such successive re-delegations of such functions, powers, and duties to such officers and employees of the Office as the Director considers appropriate.

43(B) In acting under subparagraph (A)(ii) in the case of a summit or a meeting with an international partner, the Director shall act in coordination with the Secretary of State.

44The Director may, for the purposes of carrying out the functions of the Director under this section—

45(A) subject to the civil service and classification laws, select, appoint, employ, and fix the compensation of such officers and employees as are necessary and prescribe their duties, except that not more than 75 individuals may be employed without regard to any provision of law regulating the employment or compensation at rates not to exceed the basic rate of basic pay payable for level IV of the Executive Schedule under section 5315 of title 5;

46(B) employ experts and consultants in accordance with section 3109 of title 5, and compensate individuals so employed for each day (including travel time) at rates not in excess of the maximum rate of basic pay for grade GS–15 as provided in section 5332 of such title, and while such experts and consultants are so serving away from their homes or regular place of business, to pay such employees travel expenses and per diem in lieu of subsistence at rates authorized by section 5703 of such title 5 for persons in Federal Government service employed intermittently;

47(C) accept officers or employees of the United States or members of the Armed Forces on a detail from an element of the intelligence community (as such term is defined in section 3003(4) of title 50) or from another element of the Federal Government on a nonreimbursable basis, as jointly agreed to by the heads of the receiving and detailing elements, for a period not to exceed three years;

48(D) promulgate such rules and regulations as may be necessary to carry out the functions, powers, and duties vested in the Director;

49(E) utilize, with their consent, the services, personnel, and facilities of other Federal agencies;

50(F) enter into and perform such contracts, leases, cooperative agreements, or other transactions as may be necessary in the conduct of the work of the Office and on such terms as the Director may determine appropriate, with any Federal agency, or with any public or private person or entity;

51(G) accept voluntary and uncompensated services, notwithstanding the provisions of section 1342 of title 31;

52(H) adopt an official seal, which shall be judicially noticed; and

53(I) provide, where authorized by law, copies of documents to persons at cost, except that any funds so received shall be credited to, and be available for use from, the account from which expenditures relating thereto were made.

54Nothing in paragraph (1)(C) may be construed as imposing any limitation on any other authority for reimbursable or nonreimbursable details. A nonreimbursable detail made pursuant to such paragraph shall not be considered an augmentation of the appropriations of the receiving element of the Office of the National Cyber Director.

55Nothing in this section may be construed as—

56(1) modifying any authority or responsibility, including any operational authority or responsibility of any head of a Federal department or agency;

57(2) authorizing the Director or any person acting under the authority of the Director to interfere with or to direct a criminal or national security investigation, arrest, search, seizure, or disruption operation;

58(3) amending a legal restriction that was in effect on the day before January 1, 2021 that requires a law enforcement agency to keep confidential information learned in the course of a criminal or national security investigation;

59(4) authorizing the Director or any person acting under the authority of the Director to interfere with or to direct a military operation;

60(5) authorizing the Director or any person acting under the authority of the Director to interfere with or to direct any diplomatic or consular activity;

61(6) authorizing the Director or any person acting under the authority of the Director to interfere with or to direct an intelligence activity, resource, or operation; or

62(7) authorizing the Director or any person acting under the authority of the Director to modify the classification of intelligence information.

63In this section:

64(1) The term "cybersecurity posture" means the ability to identify, to protect against, to detect, to respond to, and to recover from an intrusion in an information system the compromise of which could constitute a cyber attack or cyber campaign of significant consequence.

65(2) The term "cyber attack and cyber campaign of significant consequence" means an incident or series of incidents that has the purpose or effect of—

66(A) causing a significant disruption to the confidentiality, integrity, or availability of a Federal information system;

67(B) harming, or otherwise significantly compromising the provision of service by, a computer or network of computers that support one or more entities in a critical infrastructure sector;

68(C) significantly compromising the provision of services by one or more entities in a critical infrastructure sector;

69(D) causing a significant misappropriation of funds or economic resources, trade secrets, personal identifiers, or financial information for commercial or competitive advantage or private financial gain; or

70(E) otherwise constituting a significant threat to the national security, foreign policy, or economic health or financial stability of the United States.

71(3) The term "incident" has the meaning given such term in section 3552 of title 44.

72(4) The term "incident response" means a government or private sector activity that detects, mitigates, or recovers from a cyber attack or cyber campaign of significant consequence.

73(5) The term "information security" has the meaning given such term in section 3552 of title 44.

74(6) The term "intelligence" has the meaning given such term in section 3003 of title 50.

1501.

Definitions

1In this subchapter:

2The term "agency" has the meaning given the term in section 3502 of title 44.

3The term "antitrust laws"—

4(A) has the meaning given the term in section 12 of title 15;

5(B) includes section 45 of title 15 to the extent that section 45 of title 15 applies to unfair methods of competition; and

6(C) includes any State antitrust law, but only to the extent that such law is consistent with the law referred to in subparagraph (A) or the law referred to in subparagraph (B).

7The term "appropriate Federal entities" means the following:

8(A) The Department of Commerce.

9(B) The Department of Defense.

10(C) The Department of Energy.

11(D) The Department of Homeland Security.

12(E) The Department of Justice.

13(F) The Department of the Treasury.

14(G) The Office of the Director of National Intelligence.

15The term "cybersecurity purpose" has the meaning given the term in section 650 of this title.

16The term "cybersecurity threat" has the meaning given the term in section 650 of this title.

17The term "cyber threat indicator" has the meaning given the term in section 650 of this title.

18The term "defensive measure" has the meaning given the term in section 650 of this title.

19The term "Federal entity" means a department or agency of the United States or any component of such department or agency.

20The term "information system" has the meaning given the term in section 650 of this title.

21The term "local government" means any borough, city, county, parish, town, township, village, or other political subdivision of a State.

22The term "malicious cyber command and control" has the meaning given the term in section 650 of this title.

23The term "malicious reconnaissance" has the meaning given the term in section 650 of this title.

24The term "monitor" has the meaning given the term in section 650 of this title.

25Except as otherwise provided in this paragraph, the term "non-Federal entity" means any private entity, non-Federal government agency or department, or State, tribal, or local government (including a political subdivision, department, or component thereof).

26The term "non-Federal entity" includes a government agency or department of the District of Columbia, the Commonwealth of Puerto Rico, the United States Virgin Islands, Guam, American Samoa, the Northern Mariana Islands, and any other territory or possession of the United States.

27The term "non-Federal entity" does not include a foreign power as defined in section 1801 of title 50.

28Except as otherwise provided in this paragraph, the term "private entity" means any person or private group, organization, proprietorship, partnership, trust, cooperative, corporation, or other commercial or nonprofit entity, including an officer, employee, or agent thereof.

29The term "private entity" includes a State, tribal, or local government performing utility services, such as electric, natural gas, or water services.

30The term "private entity" does not include a foreign power as defined in section 1801 of title 50.

31The term "security control" has the meaning given the term in section 650 of this title.

32The term "security vulnerability" has the meaning given the term in section 650 of this title.

33The term "tribal" has the meaning given the term "Indian tribe" in section 5304 of title 25.

1502.

Sharing of information by the Federal Government

1Consistent with the protection of classified information, intelligence sources and methods, and privacy and civil liberties, the Director of National Intelligence, the Secretary of Homeland Security, the Secretary of Defense, and the Attorney General, in consultation with the heads of the appropriate Federal entities, shall jointly develop and issue procedures to facilitate and promote—

2(1) the timely sharing of classified cyber threat indicators and defensive measures in the possession of the Federal Government with representatives of relevant Federal entities and non-Federal entities that have appropriate security clearances;

3(2) the timely sharing with relevant Federal entities and non-Federal entities of cyber threat indicators, defensive measures, and information relating to cybersecurity threats or authorized uses under this subchapter, in the possession of the Federal Government that may be declassified and shared at an unclassified level;

4(3) the timely sharing with relevant Federal entities and non-Federal entities, or the public if appropriate, of unclassified, including controlled unclassified, cyber threat indicators and defensive measures in the possession of the Federal Government;

5(4) the timely sharing with Federal entities and non-Federal entities, if appropriate, of information relating to cybersecurity threats or authorized uses under this subchapter, in the possession of the Federal Government about cybersecurity threats to such entities to prevent or mitigate adverse effects from such cybersecurity threats; and

6(5) the periodic sharing, through publication and targeted outreach, of cybersecurity best practices that are developed based on ongoing analyses of cyber threat indicators, defensive measures, and information relating to cybersecurity threats or authorized uses under this subchapter, in the possession of the Federal Government, with attention to accessibility and implementation challenges faced by small business concerns (as defined in section 632 of title 15).

7The procedures developed under subsection (a) shall—

8(A) ensure the Federal Government has and maintains the capability to share cyber threat indicators and defensive measures in real time consistent with the protection of classified information;

9(B) incorporate, to the greatest extent practicable, existing processes and existing roles and responsibilities of Federal entities and non-Federal entities for information sharing by the Federal Government, including sector specific information sharing and analysis centers;

10(C) include procedures for notifying, in a timely manner, Federal entities and non-Federal entities that have received a cyber threat indicator or defensive measure from a Federal entity under this subchapter that is known or determined to be in error or in contravention of the requirements of this subchapter or another provision of Federal law or policy of such error or contravention;

11(D) include requirements for Federal entities sharing cyber threat indicators or defensive measures to implement and utilize security controls to protect against unauthorized access to or acquisition of such cyber threat indicators or defensive measures;

12(E) include procedures that require a Federal entity, prior to the sharing of a cyber threat indicator—

13(i) to review such cyber threat indicator to assess whether such cyber threat indicator contains any information not directly related to a cybersecurity threat that such Federal entity knows at the time of sharing to be personal information of a specific individual or information that identifies a specific individual and remove such information; or

14(ii) to implement and utilize a technical capability configured to remove any information not directly related to a cybersecurity threat that the Federal entity knows at the time of sharing to be personal information of a specific individual or information that identifies a specific individual; and

15(F) include procedures for notifying, in a timely manner, any United States person whose personal information is known or determined to have been shared by a Federal entity in violation of this subchapter.

16In developing the procedures required under this section, the Director of National Intelligence, the Secretary of Homeland Security, the Secretary of Defense, and the Attorney General shall consult with appropriate Federal entities, including the Small Business Administration and the National Laboratories (as defined in section 15801 of title 42), to ensure that effective protocols are implemented that will facilitate and promote the sharing of cyber threat indicators by the Federal Government in a timely manner.

17Not later than 60 days after December 18, 2015, the Director of National Intelligence, in consultation with the heads of the appropriate Federal entities, shall submit to Congress the procedures required by subsection (a).

1503.

Authorizations for preventing, detecting, analyzing, and mitigating cybersecurity threats

1Notwithstanding any other provision of law, a private entity may, for cybersecurity purposes, monitor—

2(A) an information system of such private entity;

3(B) an information system of another non-Federal entity, upon the authorization and written consent of such other entity;

4(C) an information system of a Federal entity, upon the authorization and written consent of an authorized representative of the Federal entity; and

5(D) information that is stored on, processed by, or transiting an information system monitored by the private entity under this paragraph.

6Nothing in this subsection shall be construed—

7(A) to authorize the monitoring of an information system, or the use of any information obtained through such monitoring, other than as provided in this subchapter; or

8(B) to limit otherwise lawful activity.

9Notwithstanding any other provision of law, a private entity may, for cybersecurity purposes, operate a defensive measure that is applied to—

10(A) an information system of such private entity in order to protect the rights or property of the private entity;

11(B) an information system of another non-Federal entity upon written consent of such entity for operation of such defensive measure to protect the rights or property of such entity; and

12(C) an information system of a Federal entity upon written consent of an authorized representative of such Federal entity for operation of such defensive measure to protect the rights or property of the Federal Government.

13Nothing in this subsection shall be construed—

14(A) to authorize the use of a defensive measure other than as provided in this subsection; or

15(B) to limit otherwise lawful activity.

16Except as provided in paragraph (2) and notwithstanding any other provision of law, a non-Federal entity may, for a cybersecurity purpose and consistent with the protection of classified information, share with, or receive from, any other non-Federal entity or the Federal Government a cyber threat indicator or defensive measure.

17A non-Federal entity receiving a cyber threat indicator or defensive measure from another non-Federal entity or a Federal entity shall comply with otherwise lawful restrictions placed on the sharing or use of such cyber threat indicator or defensive measure by the sharing non-Federal entity or Federal entity.

18Nothing in this subsection shall be construed—

19(A) to authorize the sharing or receiving of a cyber threat indicator or defensive measure other than as provided in this subsection; or

20(B) to limit otherwise lawful activity.

21A non-Federal entity monitoring an information system, operating a defensive measure, or providing or receiving a cyber threat indicator or defensive measure under this section shall implement and utilize a security control to protect against unauthorized access to or acquisition of such cyber threat indicator or defensive measure.

22A non-Federal entity sharing a cyber threat indicator pursuant to this subchapter shall, prior to such sharing—

23(A) review such cyber threat indicator to assess whether such cyber threat indicator contains any information not directly related to a cybersecurity threat that the non-Federal entity knows at the time of sharing to be personal information of a specific individual or information that identifies a specific individual and remove such information; or

24(B) implement and utilize a technical capability configured to remove any information not directly related to a cybersecurity threat that the non-Federal entity knows at the time of sharing to be personal information of a specific individual or information that identifies a specific individual.

25Consistent with this subchapter, a cyber threat indicator or defensive measure shared or received under this section may, for cybersecurity purposes—

26(i) be used by a non-Federal entity to monitor or operate a defensive measure that is applied to—

27(I) an information system of the non-Federal entity; or

28(II) an information system of another non-Federal entity or a Federal entity upon the written consent of that other non-Federal entity or that Federal entity; and

29(ii) be otherwise used, retained, and further shared by a non-Federal entity subject to—

30(I) an otherwise lawful restriction placed by the sharing non-Federal entity or Federal entity on such cyber threat indicator or defensive measure; or

31(II) an otherwise applicable provision of law.

32Nothing in this paragraph shall be construed to authorize the use of a cyber threat indicator or defensive measure other than as provided in this section.

33A State, tribal, or local government that receives a cyber threat indicator or defensive measure under this subchapter may use such cyber threat indicator or defensive measure for the purposes described in section 1504(d)(5)(A) of this title.

34A cyber threat indicator or defensive measure shared by or with a State, tribal, or local government, including a component of a State, tribal, or local government that is a private entity, under this section shall be—

35(i) deemed voluntarily shared information; and

36(ii) exempt from disclosure under any provision of State, tribal, or local freedom of information law, open government law, open meetings law, open records law, sunshine law, or similar law requiring disclosure of information or records.

37Except as provided in clause (ii), a cyber threat indicator or defensive measure shared with a State, tribal, or local government under this subchapter shall not be used by any State, tribal, or local government to regulate, including an enforcement action, the lawful activity of any non-Federal entity or any activity taken by a non-Federal entity pursuant to mandatory standards, including an activity relating to monitoring, operating a defensive measure, or sharing of a cyber threat indicator.

38A cyber threat indicator or defensive measure shared as described in clause (i) may, consistent with a State, tribal, or local government regulatory authority specifically relating to the prevention or mitigation of cybersecurity threats to information systems, inform the development or implementation of a regulation relating to such information systems.

39Except as provided in section 1507(e) of this title, it shall not be considered a violation of any provision of antitrust laws for 2 or more private entities to exchange or provide a cyber threat indicator or defensive measure, or assistance relating to the prevention, investigation, or mitigation of a cybersecurity threat, for cybersecurity purposes under this subchapter.

40Paragraph (1) shall apply only to information that is exchanged or assistance provided in order to assist with—

41(A) facilitating the prevention, investigation, or mitigation of a cybersecurity threat to an information system or information that is stored on, processed by, or transiting an information system; or

42(B) communicating or disclosing a cyber threat indicator to help prevent, investigate, or mitigate the effect of a cybersecurity threat to an information system or information that is stored on, processed by, or transiting an information system.

43The sharing of a cyber threat indicator or defensive measure with a non-Federal entity under this subchapter shall not create a right or benefit to similar information by such non-Federal entity or any other non-Federal entity.

1504.

Sharing of cyber threat indicators and defensive measures with the Federal Government

1Not later than 60 days after December 18, 2015, the Attorney General and the Secretary of Homeland Security shall, in consultation with the heads of the appropriate Federal entities, jointly develop and submit to Congress interim policies and procedures relating to the receipt of cyber threat indicators and defensive measures by the Federal Government.

2Not later than 180 days after December 18, 2015, the Attorney General and the Secretary of Homeland Security shall, in consultation with the heads of the appropriate Federal entities, jointly issue and make publicly available final policies and procedures relating to the receipt of cyber threat indicators and defensive measures by the Federal Government.

3Consistent with the guidelines required by subsection (b), the policies and procedures developed or issued under this subsection shall—

4(A) ensure that cyber threat indicators shared with the Federal Government by any non-Federal entity pursuant to section 1503(c) of this title through the real-time process described in subsection (c) of this section—

5(i) are shared in an automated manner with all of the appropriate Federal entities;

6(ii) are only subject to a delay, modification, or other action due to controls established for such real-time process that could impede real-time receipt by all of the appropriate Federal entities when the delay, modification, or other action is due to controls—

7(I) agreed upon unanimously by all of the heads of the appropriate Federal entities;

8(II) carried out before any of the appropriate Federal entities retains or uses the cyber threat indicators or defensive measures; and

9(III) uniformly applied such that each of the appropriate Federal entities is subject to the same delay, modification, or other action; and

10(iii) may be provided to other Federal entities;

11(B) ensure that cyber threat indicators shared with the Federal Government by any non-Federal entity pursuant to section 1503 of this title in a manner other than the real-time process described in subsection (c) of this section—

12(i) are shared as quickly as operationally practicable with all of the appropriate Federal entities;

13(ii) are not subject to any unnecessary delay, interference, or any other action that could impede receipt by all of the appropriate Federal entities; and

14(iii) may be provided to other Federal entities; and

15(C) ensure there are—

16(i) audit capabilities; and

17(ii) appropriate sanctions in place for officers, employees, or agents of a Federal entity who knowingly and willfully conduct activities under this subchapter in an unauthorized manner.

18Not later than 60 days after December 18, 2015, the Attorney General and the Secretary of Homeland Security shall jointly develop and make publicly available guidance to assist entities and promote sharing of cyber threat indicators with Federal entities under this subchapter.

19The guidelines developed and made publicly available under subparagraph (A) shall include guidance on the following:

20(i) Identification of types of information that would qualify as a cyber threat indicator under this subchapter that would be unlikely to include information that—

21(I) is not directly related to a cybersecurity threat; and

22(II) is personal information of a specific individual or information that identifies a specific individual.

23(ii) Identification of types of information protected under otherwise applicable privacy laws that are unlikely to be directly related to a cybersecurity threat.

24(iii) Such other matters as the Attorney General and the Secretary of Homeland Security consider appropriate for entities sharing cyber threat indicators with Federal entities under this subchapter.

25Not later than 60 days after December 18, 2015, the Attorney General and the Secretary of Homeland Security shall, in consultation with heads of the appropriate Federal entities and in consultation with officers designated under section 2000ee–1 of title 42, jointly develop, submit to Congress, and make available to the public interim guidelines relating to privacy and civil liberties which shall govern the receipt, retention, use, and dissemination of cyber threat indicators by a Federal entity obtained in connection with activities authorized in this subchapter.

26Not later than 180 days after December 18, 2015, the Attorney General and the Secretary of Homeland Security shall, in coordination with heads of the appropriate Federal entities and in consultation with officers designated under section 2000ee–1 of title 42 and such private entities with industry expertise as the Attorney General and the Secretary consider relevant, jointly issue and make publicly available final guidelines relating to privacy and civil liberties which shall govern the receipt, retention, use, and dissemination of cyber threat indicators by a Federal entity obtained in connection with activities authorized in this subchapter.

27The Attorney General and the Secretary of Homeland Security shall, in coordination with heads of the appropriate Federal entities and in consultation with officers and private entities described in subparagraph (A), periodically, but not less frequently than once every 2 years, jointly review the guidelines issued under subparagraph (A).

28The guidelines required by paragraphs (1) and (2) shall, consistent with the need to protect information systems from cybersecurity threats and mitigate cybersecurity threats—

29(A) limit the effect on privacy and civil liberties of activities by the Federal Government under this subchapter;

30(B) limit the receipt, retention, use, and dissemination of cyber threat indicators containing personal information of specific individuals or information that identifies specific individuals, including by establishing—

31(i) a process for the timely destruction of such information that is known not to be directly related to uses authorized under this subchapter; and

32(ii) specific limitations on the length of any period in which a cyber threat indicator may be retained;

33(C) include requirements to safeguard cyber threat indicators containing personal information of specific individuals or information that identifies specific individuals from unauthorized access or acquisition, including appropriate sanctions for activities by officers, employees, or agents of the Federal Government in contravention of such guidelines;

34(D) consistent with this subchapter, any other applicable provisions of law, and the fair information practice principles set forth in appendix A of the document entitled "National Strategy for Trusted Identities in Cyberspace" and published by the President in April 2011, govern the retention, use, and dissemination by the Federal Government of cyber threat indicators shared with the Federal Government under this subchapter, including the extent, if any, to which such cyber threat indicators may be used by the Federal Government;

35(E) include procedures for notifying entities and Federal entities if information received pursuant to this section is known or determined by a Federal entity receiving such information not to constitute a cyber threat indicator;

36(F) protect the confidentiality of cyber threat indicators containing personal information of specific individuals or information that identifies specific individuals to the greatest extent practicable and require recipients to be informed that such indicators may only be used for purposes authorized under this subchapter; and

37(G) include steps that may be needed so that dissemination of cyber threat indicators is consistent with the protection of classified and other sensitive national security information.

38Not later than 90 days after December 18, 2015, the Secretary of Homeland Security, in coordination with the heads of the appropriate Federal entities, shall develop and implement a capability and process within the Department of Homeland Security that—

39(A) shall accept from any non-Federal entity in real time cyber threat indicators and defensive measures, pursuant to this section;

40(B) shall, upon submittal of the certification under paragraph (2) that such capability and process fully and effectively operates as described in such paragraph, be the process by which the Federal Government receives cyber threat indicators and defensive measures under this subchapter that are shared by a non-Federal entity with the Federal Government through electronic mail or media, an interactive form on an Internet website, or a real time, automated process between information systems except—

41(i) consistent with section 1503 of this title, communications between a Federal entity and a non-Federal entity regarding a previously shared cyber threat indicator to describe the relevant cybersecurity threat or develop a defensive measure based on such cyber threat indicator; and

42(ii) communications by a regulated non-Federal entity with such entity's Federal regulatory authority regarding a cybersecurity threat;

43(C) ensures that all of the appropriate Federal entities receive in an automated manner such cyber threat indicators and defensive measures shared through the real-time process within the Department of Homeland Security;

44(D) is in compliance with the policies, procedures, and guidelines required by this section; and

45(E) does not limit or prohibit otherwise lawful disclosures of communications, records, or other information, including—

46(i) reporting of known or suspected criminal activity, by a non-Federal entity to any other non-Federal entity or a Federal entity, including cyber threat indicators or defensive measures shared with a Federal entity in furtherance of opening a Federal law enforcement investigation;

47(ii) voluntary or legally compelled participation in a Federal investigation; and

48(iii) providing cyber threat indicators or defensive measures as part of a statutory or authorized contractual requirement.

49Not later than 90 days after December 18, 2015, the Secretary of Homeland Security shall, in consultation with the heads of the appropriate Federal entities, submit to Congress a certification as to whether the capability and process required by paragraph (1) fully and effectively operates—

50(i) as the process by which the Federal Government receives from any non-Federal entity a cyber threat indicator or defensive measure under this subchapter; and

51(ii) in accordance with the interim policies, procedures, and guidelines developed under this subchapter.

52At any time after certification is submitted under subparagraph (A), the President may designate an appropriate Federal entity, other than the Department of Defense (including the National Security Agency), to develop and implement a capability and process as described in paragraph (1) in addition to the capability and process developed under such paragraph by the Secretary of Homeland Security, if, not fewer than 30 days before making such designation, the President submits to Congress a certification and explanation that—

53(I) such designation is necessary to ensure that full, effective, and secure operation of a capability and process for the Federal Government to receive from any non-Federal entity cyber threat indicators or defensive measures under this subchapter;

54(II) the designated appropriate Federal entity will receive and share cyber threat indicators and defensive measures in accordance with the policies, procedures, and guidelines developed under this subchapter, including subsection (a)(3)(A); and

55(III) such designation is consistent with the mission of such appropriate Federal entity and improves the ability of the Federal Government to receive, share, and use cyber threat indicators and defensive measures as authorized under this subchapter.

56If the President designates an appropriate Federal entity to develop and implement a capability and process under clause (i), the provisions of this subchapter that apply to the capability and process required by paragraph (1) shall also be construed to apply to the capability and process developed and implemented under clause (i).

57The Secretary of Homeland Security shall ensure there is public notice of, and access to, the capability and process developed and implemented under paragraph (1) so that—

58(A) any non-Federal entity may share cyber threat indicators and defensive measures through such process with the Federal Government; and

59(B) all of the appropriate Federal entities receive such cyber threat indicators and defensive measures in real time with receipt through the process within the Department of Homeland Security consistent with the policies and procedures issued under subsection (a).

60The process developed and implemented under paragraph (1) shall ensure that other Federal entities receive in a timely manner any cyber threat indicators and defensive measures shared with the Federal Government through such process.

61The provision of cyber threat indicators and defensive measures to the Federal Government under this subchapter shall not constitute a waiver of any applicable privilege or protection provided by law, including trade secret protection.

62Consistent with section 1503(c)(2) of this title and any other applicable provision of law, a cyber threat indicator or defensive measure provided by a non-Federal entity to the Federal Government under this subchapter shall be considered the commercial, financial, and proprietary information of such non-Federal entity when so designated by the originating non-Federal entity or a third party acting in accordance with the written authorization of the originating non-Federal entity.

63A cyber threat indicator or defensive measure shared with the Federal Government under this subchapter shall be—

64(A) deemed voluntarily shared information and exempt from disclosure under section 552 of title 5 and any State, tribal, or local provision of law requiring disclosure of information or records; and

65(B) withheld, without discretion, from the public under section 552(b)(3)(B) of title 5 and any State, tribal, or local provision of law requiring disclosure of information or records.

66The provision of a cyber threat indicator or defensive measure to the Federal Government under this subchapter shall not be subject to a rule of any Federal agency or department or any judicial doctrine regarding ex parte communications with a decision-making official.

67Cyber threat indicators and defensive measures provided to the Federal Government under this subchapter may be disclosed to, retained by, and used by, consistent with otherwise applicable provisions of Federal law, any Federal agency or department, component, officer, employee, or agent of the Federal Government solely for—

68(i) a cybersecurity purpose;

69(ii) the purpose of identifying—

70(I) a cybersecurity threat, including the source of such cybersecurity threat; or

71(II) a security vulnerability;

72(iii) the purpose of responding to, or otherwise preventing or mitigating, a specific threat of death, a specific threat of serious bodily harm, or a specific threat of serious economic harm, including a terrorist act or a use of a weapon of mass destruction;

73(iv) the purpose of responding to, investigating, prosecuting, or otherwise preventing or mitigating, a serious threat to a minor, including sexual exploitation and threats to physical safety; or

74(v) the purpose of preventing, investigating, disrupting, or prosecuting an offense arising out of a threat described in clause (iii) or any of the offenses listed in—

75(I) sections 1028 through 1030 of title 18 (relating to fraud and identity theft);

76(II) chapter 37 of such title (relating to espionage and censorship); and

77(III) chapter 90 of such title (relating to protection of trade secrets).

78Cyber threat indicators and defensive measures provided to the Federal Government under this subchapter shall not be disclosed to, retained by, or used by any Federal agency or department for any use not permitted under subparagraph (A).

79Cyber threat indicators and defensive measures provided to the Federal Government under this subchapter shall be retained, used, and disseminated by the Federal Government—

80(i) in accordance with the policies, procedures, and guidelines required by subsections (a) and (b);

81(ii) in a manner that protects from unauthorized use or disclosure any cyber threat indicators that may contain—

82(I) personal information of a specific individual; or

83(II) information that identifies a specific individual; and

84(iii) in a manner that protects the confidentiality of cyber threat indicators containing—

85(I) personal information of a specific individual; or

86(II) information that identifies a specific individual.

87Except as provided in clause (ii), cyber threat indicators and defensive measures provided to the Federal Government under this subchapter shall not be used by any Federal, State, tribal, or local government to regulate, including an enforcement action, the lawful activities of any non-Federal entity or any activities taken by a non-Federal entity pursuant to mandatory standards, including activities relating to monitoring, operating defensive measures, or sharing cyber threat indicators.

88Cyber threat indicators and defensive measures provided to the Federal Government under this subchapter may, consistent with Federal or State regulatory authority specifically relating to the prevention or mitigation of cybersecurity threats to information systems, inform the development or implementation of regulations relating to such information systems.

89Clause (i) shall not apply to procedures developed and implemented under this subchapter.

1505.

Protection from liability

1No cause of action shall lie or be maintained in any court against any private entity, and such action shall be promptly dismissed, for the monitoring of an information system and information under section 1503(a) of this title that is conducted in accordance with this subchapter.

2No cause of action shall lie or be maintained in any court against any private entity, and such action shall be promptly dismissed, for the sharing or receipt of a cyber threat indicator or defensive measure under section 1503(c) of this title if—

3(1) such sharing or receipt is conducted in accordance with this subchapter; and

4(2) in a case in which a cyber threat indicator or defensive measure is shared with the Federal Government, the cyber threat indicator or defensive measure is shared in a manner that is consistent with section 1504(c)(1)(B) of this title and the sharing or receipt, as the case may be, occurs after the earlier of—

5(A) the date on which the interim policies and procedures are submitted to Congress under section 1504(a)(1) of this title and guidelines are submitted to Congress under section 1504(b)(1) of this title; or

6(B) the date that is 60 days after December 18, 2015.

7Nothing in this subchapter shall be construed—

8(1) to create—

9(A) a duty to share a cyber threat indicator or defensive measure; or

10(B) a duty to warn or act based on the receipt of a cyber threat indicator or defensive measure; or

11(2) to undermine or limit the availability of otherwise applicable common law or statutory defenses.

1506.

Oversight of government activities

1Not later than 1 year after December 18, 2015, the heads of the appropriate Federal entities shall jointly submit to Congress a detailed report concerning the implementation of this subchapter.

2The report required by paragraph (1) may include such recommendations as the heads of the appropriate Federal entities may have for improvements or modifications to the authorities, policies, procedures, and guidelines under this subchapter and shall include the following:

3(A) An evaluation of the effectiveness of real-time information sharing through the capability and process developed under section 1504(c) of this title, including any impediments to such real-time sharing.

4(B) An assessment of whether cyber threat indicators or defensive measures have been properly classified and an accounting of the number of security clearances authorized by the Federal Government for the purpose of sharing cyber threat indicators or defensive measures with the private sector.

5(C) The number of cyber threat indicators or defensive measures received through the capability and process developed under section 1504(c) of this title.

6(D) A list of Federal entities that have received cyber threat indicators or defensive measures under this subchapter.

7Not later than 2 years after December 18, 2015 and not less frequently than once every 2 years thereafter, the inspectors general of the appropriate Federal entities, in consultation with the Inspector General of the Intelligence Community and the Council of Inspectors General on Financial Oversight, shall jointly submit to Congress an interagency report on the actions of the executive branch of the Federal Government to carry out this subchapter during the most recent 2-year period.

8Each report submitted under paragraph (1) shall include, for the period covered by the report, the following:

9(A) An assessment of the sufficiency of the policies, procedures, and guidelines relating to the sharing of cyber threat indicators within the Federal Government, including those policies, procedures, and guidelines relating to the removal of information not directly related to a cybersecurity threat that is personal information of a specific individual or information that identifies a specific individual.

10(B) An assessment of whether cyber threat indicators or defensive measures have been properly classified and an accounting of the number of security clearances authorized by the Federal Government for the purpose of sharing cyber threat indicators or defensive measures with the private sector.

11(C) A review of the actions taken by the Federal Government based on cyber threat indicators or defensive measures shared with the Federal Government under this subchapter, including a review of the following:

12(i) The appropriateness of subsequent uses and disseminations of cyber threat indicators or defensive measures.

13(ii) Whether cyber threat indicators or defensive measures were shared in a timely and adequate manner with appropriate entities, or, if appropriate, were made publicly available.

14(D) An assessment of the cyber threat indicators or defensive measures shared with the appropriate Federal entities under this subchapter, including the following:

15(i) The number of cyber threat indicators or defensive measures shared through the capability and process developed under section 1504(c) of this title.

16(ii) An assessment of any information not directly related to a cybersecurity threat that is personal information of a specific individual or information identifying a specific individual and was shared by a non-Federal government 1 entity with the Federal government 1 in contravention of this subchapter, or was shared within the Federal Government in contravention of the guidelines required by this subchapter, including a description of any significant violation of this subchapter.

17(iii) The number of times, according to the Attorney General, that information shared under this subchapter was used by a Federal entity to prosecute an offense listed in section 1504(d)(5)(A) of this title.

18(iv) A quantitative and qualitative assessment of the effect of the sharing of cyber threat indicators or defensive measures with the Federal Government on privacy and civil liberties of specific individuals, including the number of notices that were issued with respect to a failure to remove information not directly related to a cybersecurity threat that was personal information of a specific individual or information that identified a specific individual in accordance with the procedures required by section 1504(b)(3)(E) of this title.

19(v) The adequacy of any steps taken by the Federal Government to reduce any adverse effect from activities carried out under this subchapter on the privacy and civil liberties of United States persons.

20(E) An assessment of the sharing of cyber threat indicators or defensive measures among Federal entities to identify inappropriate barriers to sharing information.

21Each report submitted under this subsection may include such recommendations as the inspectors general may have for improvements or modifications to the authorities and processes under this subchapter.

22Not later than 3 years after December 18, 2015, the Comptroller General of the United States shall submit to Congress a report on the actions taken by the Federal Government to remove personal information from cyber threat indicators or defensive measures pursuant to this subchapter. Such report shall include an assessment of the sufficiency of the policies, procedures, and guidelines established under this subchapter in addressing concerns relating to privacy and civil liberties.

23Each report required under this section shall be submitted in an unclassified form, but may include a classified annex.

24The unclassified portions of the reports required under this section shall be made available to the public.

1507.

Construction and preemption

1Nothing in this subchapter shall be construed—

2(1) to limit or prohibit otherwise lawful disclosures of communications, records, or other information, including reporting of known or suspected criminal activity, by a non-Federal entity to any other non-Federal entity or the Federal Government under this subchapter; or

3(2) to limit or prohibit otherwise lawful use of such disclosures by any Federal entity, even when such otherwise lawful disclosures duplicate or replicate disclosures made under this subchapter.

4Nothing in this subchapter shall be construed to prohibit or limit the disclosure of information protected under section 2302(b)(8) of title 5 (governing disclosures of illegality, waste, fraud, abuse, or public health or safety threats), section 7211 of title 5 (governing disclosures to Congress), section 1034 of title 10 (governing disclosure to Congress by members of the military), section 3234 of title 50 (governing disclosure by employees of elements of the intelligence community), or any similar provision of Federal or State law.

5Nothing in this subchapter shall be construed—

6(1) as creating any immunity against, or otherwise affecting, any action brought by the Federal Government, or any agency or department thereof, to enforce any law, executive order, or procedure governing the appropriate handling, disclosure, or use of classified information;

7(2) to affect the conduct of authorized law enforcement or intelligence activities; or

8(3) to modify the authority of a department or agency of the Federal Government to protect classified information and sources and methods and the national security of the United States.

9Nothing in this subchapter shall be construed to affect any requirement under any other provision of law for a non-Federal entity to provide information to the Federal Government.

10Nothing in this subchapter shall be construed to permit price-fixing, allocating a market between competitors, monopolizing or attempting to monopolize a market, boycotting, or exchanges of price or cost information, customer lists, or information regarding future competitive planning.

11Nothing in this subchapter shall be construed—

12(1) to limit or modify an existing information sharing relationship;

13(2) to prohibit a new information sharing relationship;

14(3) to require a new information sharing relationship between any non-Federal entity and a Federal entity or another non-Federal entity; or

15(4) to require the use of the capability and process within the Department of Homeland Security developed under section 1504(c) of this title.

16Nothing in this subchapter shall be construed—

17(1) to amend, repeal, or supersede any current or future contractual agreement, terms of service agreement, or other contractual relationship between any non-Federal entities, or between any non-Federal entity and a Federal entity; or

18(2) to abrogate trade secret or intellectual property rights of any non-Federal entity or Federal entity.

19Nothing in this subchapter shall be construed to permit a Federal entity—

20(1) to require a non-Federal entity to provide information to a Federal entity or another non-Federal entity;

21(2) to condition the sharing of cyber threat indicators with a non-Federal entity on such entity's provision of cyber threat indicators to a Federal entity or another non-Federal entity; or

22(3) to condition the award of any Federal grant, contract, or purchase on the provision of a cyber threat indicator to a Federal entity or another non-Federal entity.

23Nothing in this subchapter shall be construed to subject any entity to liability for choosing not to engage in the voluntary activities authorized in this subchapter.

24Nothing in this subchapter shall be construed to authorize, or to modify any existing authority of, a department or agency of the Federal Government to retain or use any information shared under this subchapter for any use other than permitted in this subchapter.

25This subchapter supersedes any statute or other provision of law of a State or political subdivision of a State that restricts or otherwise expressly regulates an activity authorized under this subchapter.

26Nothing in this subchapter shall be construed to supersede any statute or other provision of law of a State or political subdivision of a State concerning the use of authorized law enforcement practices and procedures.

27Nothing in this subchapter shall be construed—

28(1) to authorize the promulgation of any regulations not specifically authorized to be issued under this subchapter;

29(2) to establish or limit any regulatory authority not specifically established or limited under this subchapter; or

30(3) to authorize regulatory actions that would duplicate or conflict with regulatory requirements, mandatory standards, or related processes under another provision of Federal law.

31Nothing in this subchapter shall be construed to limit the authority of the Secretary of Defense under section 394 of title 10.

32Nothing in this subchapter shall be construed to prevent the disclosure of a cyber threat indicator or defensive measure shared under this subchapter in a case of criminal prosecution, when an applicable provision of Federal, State, tribal, or local law requires disclosure in such case.

1508.

Report on cybersecurity threats

1Not later than 180 days after December 18, 2015, the Director of National Intelligence, in coordination with the heads of other appropriate elements of the intelligence community, shall submit to the Select Committee on Intelligence of the Senate and the Permanent Select Committee on Intelligence of the House of Representatives a report on cybersecurity threats, including cyber attacks, theft, and data breaches.

2The report required by subsection (a) shall include the following:

3(1) An assessment of the current intelligence sharing and cooperation relationships of the United States with other countries regarding cybersecurity threats, including cyber attacks, theft, and data breaches, directed against the United States and which threaten the United States national security interests and economy and intellectual property, specifically identifying the relative utility of such relationships, which elements of the intelligence community participate in such relationships, and whether and how such relationships could be improved.

4(2) A list and an assessment of the countries and nonstate actors that are the primary threats of carrying out a cybersecurity threat, including a cyber attack, theft, or data breach, against the United States and which threaten the United States national security, economy, and intellectual property.

5(3) A description of the extent to which the capabilities of the United States Government to respond to or prevent cybersecurity threats, including cyber attacks, theft, or data breaches, directed against the United States private sector are degraded by a delay in the prompt notification by private entities of such threats or cyber attacks, theft, and data breaches.

6(4) An assessment of additional technologies or capabilities that would enhance the ability of the United States to prevent and to respond to cybersecurity threats, including cyber attacks, theft, and data breaches.

7(5) An assessment of any technologies or practices utilized by the private sector that could be rapidly fielded to assist the intelligence community in preventing and responding to cybersecurity threats.

8The report required by subsection (a) shall be made available in classified and unclassified forms.

9In this section, the term "intelligence community" has the meaning given that term in section 3003 of title 50.

1509.

Exception to limitation on authority of Secretary of Defense to disseminate certain information

1Notwithstanding subsection (c)(3) of section 393 of title 10, the Secretary of Defense may authorize the sharing of cyber threat indicators and defensive measures pursuant to the policies, procedures, and guidelines developed or issued under this subchapter.

1510.

Effective period

1Except as provided in subsection (b), this subchapter and the amendments made by this subchapter shall be effective during the period beginning on December 18, 2015 and ending on September 30, 2025.

2With respect to any action authorized by this subchapter or information obtained pursuant to an action authorized by this subchapter, which occurred before the date on which the provisions referred to in subsection (a) cease to have effect, the provisions of this subchapter shall continue in effect.

1521.

Definitions

1In this subchapter:

2The term "agency" has the meaning given the term in section 3502 of title 44.

3The term "agency information system" has the meaning given the term in section 660 of this title.

4The term "appropriate congressional committees" means—

5(A) the Committee on Homeland Security and Governmental Affairs of the Senate; and

6(B) the Committee on Homeland Security of the House of Representatives.

7The terms "cybersecurity risk" and "information system" have the meanings given those terms in section 650 of this title.

8The term "Director" means the Director of the Office of Management and Budget.

9The term "intelligence community" has the meaning given the term in section 3003(4) of title 50.

10The term "national security system" has the meaning given the term in section 11103 of title 40.

11The term "Secretary" means the Secretary of Homeland Security.

1522.

Advanced internal defenses

1The Secretary shall include, in the efforts of the Department to continuously diagnose and mitigate cybersecurity risks, advanced network security tools to improve visibility of network activity, including through the use of commercial and free or open source tools, and to detect and mitigate intrusions and anomalous activity.

2The Director shall develop and the Secretary shall implement a plan to ensure that each agency utilizes advanced network security tools, including those described in paragraph (1), to detect and mitigate intrusions and anomalous activity.

3The Director and the Secretary, in consultation with appropriate agencies, shall—

4(1) review and update Government-wide policies and programs to ensure appropriate prioritization and use of network security monitoring tools within agency networks; and

5(2) brief appropriate congressional committees on such prioritization and use.

6The Secretary, in collaboration with the Director, shall review and update the metrics used to measure security under section 3554 of title 44 to include measures of intrusion and incident detection and response times.

7The Director, in consultation with the Secretary, shall increase transparency to the public on agency cybersecurity posture, including by increasing the number of metrics available on Federal Government performance websites and, to the greatest extent practicable, displaying metrics for department components, small agencies, and micro-agencies.

8The requirements under this section shall not apply to the Department of Defense, a national security system, or an element of the intelligence community.

1523.

Federal cybersecurity requirements

1Consistent with section 3553 of title 44, the Secretary, in consultation with the Director, shall exercise the authority to issue binding operational directives to assist the Director in ensuring timely agency adoption of and compliance with policies and standards promulgated under section 11331 of title 40 1 for securing agency information systems.

2Consistent with policies, standards, guidelines, and directives on information security under subchapter II of chapter 35 of title 44 and the standards and guidelines promulgated under section 11331 of title 40 and except as provided in paragraph (2), not later than 1 year after December 18, 2015, the head of each agency shall—

3(A) identify sensitive and mission critical data stored by the agency consistent with the inventory required under the first subsection (c) (relating to the inventory of major information systems) and the second subsection (c) (relating to the inventory of information systems) of section 3505 of title 44;

4(B) assess access controls to the data described in subparagraph (A), the need for readily accessible storage of the data, and individuals' need to access the data;

5(C) encrypt or otherwise render indecipherable to unauthorized users the data described in subparagraph (A) that is stored on or transiting agency information systems;

6(D) implement a single sign-on trusted identity platform for individuals accessing each public website of the agency that requires user authentication, as developed by the Administrator of General Services in collaboration with the Secretary; and

7(E) implement identity management consistent with section 7464 of title 15, including multi-factor authentication, for—

8(i) remote access to an agency information system; and

9(ii) each user account with elevated privileges on an agency information system.

10The requirements under paragraph (1) shall not apply to an agency information system for which—

11(A) the head of the agency has personally certified to the Director with particularity that—

12(i) operational requirements articulated in the certification and related to the agency information system would make it excessively burdensome to implement the cybersecurity requirement;

13(ii) the cybersecurity requirement is not necessary to secure the agency information system or agency information stored on or transiting it; and

14(iii) the agency has taken all necessary steps to secure the agency information system and agency information stored on or transiting it; and

15(B) the head of the agency or the designee of the head of the agency has submitted the certification described in subparagraph (A) to the appropriate congressional committees and the agency's authorizing committees.

16Nothing in this section shall be construed to alter the authority of the Secretary, the Director, or the Director of the National Institute of Standards and Technology in implementing subchapter II of chapter 35 of title 44. Nothing in this section shall be construed to affect the National Institute of Standards and Technology standards process or the requirement under section 3553(a)(4) of such title or to discourage continued improvements and advancements in the technology, standards, policies, and guidelines used to promote Federal information security.

17The requirements under this section shall not apply to the Department of Defense, a national security system, or an element of the intelligence community.

1524.

Assessment; reports

1In this section:

2The term "agency information" has the meaning given the term in section 2213 of the Homeland Security Act of 2002 [6 U.S.C. 663].

3The terms "cyber threat indicator" and "defensive measure" have the meanings given those terms in section 650 of this title.

4The term "intrusion assessments" means actions taken under the intrusion assessment plan to identify and remove intruders in agency information systems.

5The term "intrusion assessment plan" means the plan required under section 2210(b)(1) of the Homeland Security Act of 2002 [6 U.S.C. 660(b)(1)].

6The term "intrusion detection and prevention capabilities" means the capabilities required under section 2213(b) of the Homeland Security Act of 2002 [6 U.S.C. 663(b)].

7Not later than 3 years after December 18, 2015, the Comptroller General of the United States shall conduct a study and publish a report on the effectiveness of the approach and strategy of the Federal Government to securing agency information systems, including the intrusion detection and prevention capabilities and the intrusion assessment plan.

8Not later than 6 months after December 18, 2015, and annually thereafter, the Secretary shall submit to the appropriate congressional committees a report on the status of implementation of the intrusion detection and prevention capabilities, including—

9(i) a description of privacy controls;

10(ii) a description of the technologies and capabilities utilized to detect cybersecurity risks in network traffic, including the extent to which those technologies and capabilities include existing commercial and noncommercial technologies;

11(iii) a description of the technologies and capabilities utilized to prevent network traffic associated with cybersecurity risks from transiting or traveling to or from agency information systems, including the extent to which those technologies and capabilities include existing commercial and noncommercial technologies;

12(iv) a list of the types of indicators or other identifiers or techniques used to detect cybersecurity risks in network traffic transiting or traveling to or from agency information systems on each iteration of the intrusion detection and prevention capabilities and the number of each such type of indicator, identifier, and technique;

13(v) the number of instances in which the intrusion detection and prevention capabilities detected a cybersecurity risk in network traffic transiting or traveling to or from agency information systems and the number of times the intrusion detection and prevention capabilities blocked network traffic associated with cybersecurity risk; and

14(vi) a description of the pilot established under section 2213(c)(5) of the Homeland Security Act of 2002 [6 U.S.C. 663(c)(5)], including the number of new technologies tested and the number of participating agencies.

15Not later than 18 months after December 18, 2015, and annually thereafter, the Director shall submit to Congress, as part of the report required under section 3553(c) of title 44, an analysis of agency application of the intrusion detection and prevention capabilities, including—

16(i) a list of each agency and the degree to which each agency has applied the intrusion detection and prevention capabilities to an agency information system; and

17(ii) a list by agency of—

18(I) the number of instances in which the intrusion detection and prevention capabilities detected a cybersecurity risk in network traffic transiting or traveling to or from an agency information system and the types of indicators, identifiers, and techniques used to detect such cybersecurity risks; and

19(II) the number of instances in which the intrusion detection and prevention capabilities prevented network traffic associated with a cybersecurity risk from transiting or traveling to or from an agency information system and the types of indicators, identifiers, and techniques used to detect such agency information systems.

20Not earlier than 18 months after December 18, 2015, and not later than 2 years after December 18, 2015, the Federal Chief Information Officer shall review and submit to the appropriate congressional committees a report assessing the intrusion detection and intrusion prevention capabilities, including—

21(i) the effectiveness of the system in detecting, disrupting, and preventing cyber-threat actors, including advanced persistent threats, from accessing agency information and agency information systems;

22(ii) whether the intrusion detection and prevention capabilities, continuous diagnostics and mitigation, and other systems deployed under subtitle D 1 of title II of the Homeland Security Act of 2002 (6 U.S.C. 231 et seq.) are effective in securing Federal information systems;

23(iii) the costs and benefits of the intrusion detection and prevention capabilities, including as compared to commercial technologies and tools and including the value of classified cyber threat indicators; and

24(iv) the capability of agencies to protect sensitive cyber threat indicators and defensive measures if they were shared through unclassified mechanisms for use in commercial technologies and tools.

25The Director shall—

26(A) not later than 6 months after December 18, 2015, and 30 days after any update thereto, submit the intrusion assessment plan to the appropriate congressional committees;

27(B) not later than 1 year after December 18, 2015, and annually thereafter, submit to Congress, as part of the report required under section 3553(c) of title 44—

28(i) a description of the implementation of the intrusion assessment plan;

29(ii) the findings of the intrusion assessments conducted pursuant to the intrusion assessment plan;

30(iii) a description of the advanced network security tools included in the efforts to continuously diagnose and mitigate cybersecurity risks pursuant to section 1522(a)(1) of this title; and

31(iv) a list by agency of compliance with the requirements of section 1523(b) of this title; and

32(C) not later than 1 year after December 18, 2015, submit to the appropriate congressional committees—

33(i) a copy of the plan developed pursuant to section 1522(a)(2) of this title; and

34(ii) the improved metrics developed pursuant to section 1522(c) of this title.

35Each report required under this section shall be submitted in unclassified form, but may include a classified annex.

1525.

Termination

1The authority provided under section 663 of this title, and the reporting requirements under section 1524(c) of this title shall terminate on March 14, 2025.

2Nothing in subsection (a) shall be construed to affect the limitation of liability of a private entity for assistance provided to the Secretary under section 663(d)(2) 1 of this title, if such assistance was rendered before the termination date under subsection (a) or otherwise during a period in which the assistance was authorized.

1526.

Inventory of cryptographic systems; migration to post-quantum cryptography

1Not later than 180 days after December 21, 2022, the Director of OMB, in coordination with the National Cyber Director and in consultation with the Director of CISA, shall issue guidance on the migration of information technology to post-quantum cryptography, which shall include at a minimum—

2(A) a requirement for each agency to establish and maintain a current inventory of information technology in use by the agency that is vulnerable to decryption by quantum computers, prioritized using the criteria described in subparagraph (B);

3(B) criteria to allow agencies to prioritize their inventory efforts; and

4(C) a description of the information required to be reported pursuant to subsection (b).

5In the guidance established by paragraph (1), the Director of OMB shall include, in addition to the requirements described in that paragraph—

6(A) a description of information technology to be prioritized for migration to post-quantum cryptography; and

7(B) a process for evaluating progress on migrating information technology to post-quantum cryptography, which shall be automated to the greatest extent practicable.

8The Director of OMB shall update the guidance required under paragraph (1) as the Director of OMB determines necessary, in coordination with the National Cyber Director and in consultation with the Director of CISA.

9Not later than 1 year after December 21, 2022, and on an ongoing basis thereafter, the head of each agency shall provide to the Director of OMB, the Director of CISA, and the National Cyber Director—

10(1) the inventory described in subsection (a)(1); and

11(2) any other information required to be reported under subsection (a)(1)(C).

12Not later than 1 year after the date on which the Director of NIST has issued post-quantum cryptography standards, the Director of OMB shall issue guidance requiring each agency to—

13(1) prioritize information technology described under subsection (a)(2)(A) for migration to post-quantum cryptography; and

14(2) develop a plan to migrate information technology of the agency to post-quantum cryptography consistent with the prioritization under paragraph (1).

15The Director of OMB shall ensure that the prioritizations made under subsection (c)(1) are assessed and coordinated to ensure interoperability.

16Not later than 15 months after December 21, 2022, the Director of OMB, in coordination with the National Cyber Director and in consultation with the Director of CISA, shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives a report on the following:

17(A) A strategy to address the risk posed by the vulnerabilities of information technology of agencies to weakened encryption due to the potential and possible capability of a quantum computer to breach that encryption.

18(B) An estimate of the amount of funding needed by agencies to secure the information technology described in subsection (a)(1)(A) from the risk posed by an adversary of the United States using a quantum computer to breach the encryption of the information technology.

19(C) A description of Federal civilian executive branch coordination efforts led by the National Institute of Standards and Technology, including timelines, to develop standards for post-quantum cryptography, including any Federal Information Processing Standards developed under chapter 35 of title 44, as well as standards developed through voluntary, consensus standards bodies such as the International Organization for Standardization.

20Not later than 1 year after the date on which the Director of OMB issues guidance under subsection (c)(2), and thereafter until the date that is 5 years after the date on which post-quantum cryptographic standards are issued, the Director of OMB, in coordination with the National Cyber Director and in consultation with the Director of CISA, shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives, with the report submitted pursuant to section 3553(c) of title 44, a report on the progress of agencies in adopting post-quantum cryptography standards.

1531.

Apprehension and prosecution of international cyber criminals

1In this section, the term "international cyber criminal" means an individual—

2(1) who is believed to have committed a cybercrime or intellectual property crime against the interests of the United States or the citizens of the United States; and

3(2) for whom—

4(A) an arrest warrant has been issued by a judge in the United States; or

5(B) an international wanted notice (commonly referred to as a "Red Notice") has been circulated by Interpol.

6The Secretary of State, or designee, shall consult with the appropriate government official of each country from which extradition is not likely due to the lack of an extradition treaty with the United States or other reasons, in which one or more international cyber criminals are physically present, to determine what actions the government of such country has taken—

7(1) to apprehend and prosecute such criminals; and

8(2) to prevent such criminals from carrying out cybercrimes or intellectual property crimes against the interests of the United States or its citizens.

9The Secretary of State shall submit to the appropriate congressional committees an annual report that includes—

10(A) the number of international cyber criminals located in other countries, disaggregated by country, and indicating from which countries extradition is not likely due to the lack of an extradition treaty with the United States or other reasons;

11(B) the nature and number of significant discussions by an official of the Department of State on ways to thwart or prosecute international cyber criminals with an official of another country, including the name of each such country; and

12(C) for each international cyber criminal who was extradited to the United States during the most recently completed calendar year—

13(i) his or her name;

14(ii) the crimes for which he or she was charged;

15(iii) his or her previous country of residence; and

16(iv) the country from which he or she was extradited into the United States.

17The report required by this subsection shall be in unclassified form to the maximum extent possible, but may include a classified annex.

18For purposes of this subsection, the term "appropriate congressional committees" means—

19(A) the Committee on Foreign Relations, the Committee on Appropriations, the Committee on Homeland Security and Governmental Affairs, the Committee on Banking, Housing, and Urban Affairs, the Select Committee on Intelligence, and the Committee on the Judiciary of the Senate; and

20(B) the Committee on Foreign Affairs, the Committee on Appropriations, the Committee on Homeland Security, the Committee on Financial Services, the Permanent Select Committee on Intelligence, and the Committee on the Judiciary of the House of Representatives.

1532.

Enhancement of emergency services

1Not later than 90 days after December 18, 2015, the Secretary of Homeland Security, acting through the center established under section 659 of this title, in coordination with appropriate Federal entities and the Assistant Director for Emergency Communications, shall establish a process by which a Statewide Interoperability Coordinator may report data on any cybersecurity risk or incident involving any information system or network used by emergency response providers (as defined in section 101 of this title) within the State.

2Not later than 1 year after December 18, 2015, the Secretary of Homeland Security, acting through the Director of the National Cybersecurity and Communications Integration Center, in coordination with appropriate entities and the Assistant Director for Emergency Communications, and in consultation with the Secretary of Commerce, acting through the Director of the National Institute of Standards and Technology, shall conduct integration and analysis of the data reported under subsection (a) to develop information and recommendations on security and resilience measures for any information system or network used by State emergency response providers.

3Using the results of the integration and analysis conducted under subsection (b), and any other relevant information, the Director of the National Institute of Standards and Technology shall, on an ongoing basis, facilitate and support the development of methods for reducing cybersecurity risks to emergency response providers using the process described in section 272(e) of title 15.

4The Director of the National Institute of Standards and Technology shall submit to Congress a report on the result of the activities of the Director under paragraph (1), including any methods developed by the Director under such paragraph, and shall make such report publicly available on the website of the National Institute of Standards and Technology.

5Nothing in this section shall be construed to—

6(1) require a State to report data under subsection (a); or

7(2) require a non-Federal entity (as defined in section 1501 of this title) to—

8(A) adopt a recommended measure developed under subsection (b); or

9(B) follow the result of the activities carried out under subsection (c), including any methods developed under such subsection.

1533.

Improving cybersecurity in the health care industry

1In this section:

2The term "appropriate congressional committees" means—

3(A) the Committee on Health, Education, Labor, and Pensions, the Committee on Homeland Security and Governmental Affairs, and the Select Committee on Intelligence of the Senate; and

4(B) the Committee on Energy and Commerce, the Committee on Homeland Security, and the Permanent Select Committee on Intelligence of the House of Representatives.

5The term "business associate" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations (as in effect on the day before December 18, 2015).

6The term "covered entity" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations (as in effect on the day before December 18, 2015).

7The terms "cybersecurity threat", "cyber threat indicator", "defensive measure", "Federal entity", "non-Federal entity", and "private entity" have the meanings given such terms in section 1501 of this title.

8The terms "health care clearinghouse", "health care provider", and "health plan" have the meanings given such terms in section 160.103 of title 45, Code of Federal Regulations (as in effect on the day before December 18, 2015).

9The term "health care industry stakeholder" means any—

10(A) health plan, health care clearinghouse, or health care provider;

11(B) advocate for patients or consumers;

12(C) pharmacist;

13(D) developer or vendor of health information technology;

14(E) laboratory;

15(F) pharmaceutical or medical device manufacturer; or

16(G) additional stakeholder the Secretary determines necessary for purposes of subsection (b)(1), (c)(1), (c)(3), or (d)(1).

17The term "Secretary" means the Secretary of Health and Human Services.

18Not later than 1 year after December 18, 2015, the Secretary shall submit to the Committee on Health, Education, Labor, and Pensions of the Senate and the Committee on Energy and Commerce of the House of Representatives a report on the preparedness of the Department of Health and Human Services and health care industry stakeholders in responding to cybersecurity threats.

19With respect to the internal response of the Department of Health and Human Services to emerging cybersecurity threats, the report under paragraph (1) shall include—

20(A) a clear statement of the official within the Department of Health and Human Services to be responsible for leading and coordinating efforts of the Department regarding cybersecurity threats in the health care industry; and

21(B) a plan from each relevant operating division and subdivision of the Department of Health and Human Services on how such division or subdivision will address cybersecurity threats in the health care industry, including a clear delineation of how each such division or subdivision will divide responsibility among the personnel of such division or subdivision and communicate with other such divisions and subdivisions regarding efforts to address such threats.

22Not later than 90 days after December 18, 2015, the Secretary, in consultation with the Director of the National Institute of Standards and Technology and the Secretary of Homeland Security, shall convene health care industry stakeholders, cybersecurity experts, and any Federal agencies or entities the Secretary determines appropriate to establish a task force to—

23(A) analyze how industries, other than the health care industry, have implemented strategies and safeguards for addressing cybersecurity threats within their respective industries;

24(B) analyze challenges and barriers private entities (excluding any State, tribal, or local government) in the health care industry face securing themselves against cyber attacks;

25(C) review challenges that covered entities and business associates face in securing networked medical devices and other software or systems that connect to an electronic health record;

26(D) provide the Secretary with information to disseminate to health care industry stakeholders of all sizes for purposes of improving their preparedness for, and response to, cybersecurity threats affecting the health care industry;

27(E) establish a plan for implementing subchapter I of this chapter, so that the Federal Government and health care industry stakeholders may in real time, share actionable cyber threat indicators and defensive measures; and

28(F) report to the appropriate congressional committees on the findings and recommendations of the task force regarding carrying out subparagraphs (A) through (E).

29The task force established under this subsection shall terminate on the date that is 1 year after the date on which such task force is established.

30Not later than 60 days after the termination of the task force established under this subsection, the Secretary shall disseminate the information described in paragraph (1)(D) to health care industry stakeholders in accordance with such paragraph.

31The Secretary shall establish, through a collaborative process with the Secretary of Homeland Security, health care industry stakeholders, the Director of the National Institute of Standards and Technology, and any Federal entity or non-Federal entity the Secretary determines appropriate, a common set of voluntary, consensus-based, and industry-led guidelines, best practices, methodologies, procedures, and processes that—

32(A) serve as a resource for cost-effectively reducing cybersecurity risks for a range of health care organizations;

33(B) support voluntary adoption and implementation efforts to improve safeguards to address cybersecurity threats;

34(C) are consistent with—

35(i) the standards, guidelines, best practices, methodologies, procedures, and processes developed under section 272(c)(15) of title 15;

36(ii) the security and privacy regulations promulgated under section 264(c) of the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1320d–2 note); and

37(iii) the provisions of the Health Information Technology for Economic and Clinical Health Act (title XIII of division A, and title IV of division B, of Public Law 111–5), and the amendments made by such Act; and

38(D) are updated on a regular basis and applicable to a range of health care organizations.

39Nothing in this subsection shall be interpreted as granting the Secretary authority to—

40(A) provide for audits to ensure that health care organizations are in compliance with this subsection; or

41(B) mandate, direct, or condition the award of any Federal grant, contract, or purchase, on compliance with this subsection.

42Nothing in this section shall be construed to subject a health care industry stakeholder to liability for choosing not to engage in the voluntary activities authorized or guidelines developed under this subsection.

43In carrying out the activities under this section, the Secretary may incorporate activities that are ongoing as of the day before December 18, 2015 and that are consistent with the objectives of this section.

44Nothing in this section shall be construed to limit the antitrust exemption under section 1503(e) of this title or the protection from liability under section 1505 of this title.

1534.

Cybercrime

1Subject to the availability of appropriations, and in accordance with the comparable level of the General Schedule, the Attorney General and the Secretary of Homeland Security shall provide incentive pay, in an amount that is not more than 25 percent of the basic pay of the individual, to an individual appointed to a position in the Department of Justice (including the Federal Bureau of Investigation) or the Department of Homeland Security (including positions in Homeland Security Investigations), respectively, requiring significant cyber skills, including to aid in—

2(1) the protection of trafficking victims;

3(2) the prevention of trafficking in persons; or

4(3) the prosecution of technology-facilitated crimes against children by buyers or traffickers in persons.