Sec. 1637. Biennial exercises on responding to cyber attacks against critical infrastructure
379 words·~2 min read·
/bill/114/hr/1735/pap/section-1637·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not less frequently than once every two years until the date that is six years after the date of the enactment of this Act, the Secretary of Defense shall, in coordination with the Secretary of Homeland Security, the Director of National Intelligence, the Director of the Federal Bureau of Investigation, and the heads of the critical infrastructure sector-specific agencies designated under Presidential Policy Directive-21 (entitled Critical Infrastructure Security Resilience and dated February 12, 2013) and in consultation with governors of the States and the owners and operators of critical infrastructure, organize and execute one or more exercises based on scenarios in which— critical infrastructure of the United States is attacked through cyberspace; and the President directs the Secretary to— defend the United States; and provide support to civil authorities in responding to and recovering from cyber attacks.
The purposes of the exercises required by subsection
(a)are as follows: To improve cooperation and coordination between various parts of the Government and industry so that the Government and industry can more effectively and efficiently respond to cyber attacks. To exercise command and control, coordination, communications, and information sharing capabilities under the stressing conditions of an ongoing cyber attack. To identify gaps and problems that require new enhanced training, capabilities, procedures, or authorities. To identify— interdependencies; strengths that should be leveraged; and weaknesses that need to be mitigated. In conducting the exercises required by subsection (a), the Secretary shall ensure that there is an appropriate degree of variation from exercise to exercise of the following: The size, scope, duration, and sophistication of the cyber attacks. The degree of warning and knowledge that is available to the Department of Defense about the attack and the means used in the attack and the degree of delegation of authority from the President to react, including with pre-planned responses. The effectiveness of the National Mission Force of the United States Cyber Command in preempting and defeating the attack. The effectiveness of the attacks on critical infrastructure in general and particularly in specific industry sectors. The effectiveness of resilience and recovery mechanisms. The Secretary shall coordinate with those with whom the Secretary is required to coordinate under subsection
(a)to develop equitable cost sharing agreements to defray the expenses of the exercises required by subsection (a).