Sec. 6. Vulnerability testing and technical assistance to increase cyberresilience
254 words·~1 min read·
/bill/115/hr/4120/ih/section-6A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
The Secretary shall— collaborate with electricity sector asset owners and operators in the private sector, leveraging the research facilities and expertise of the National Laboratories, to— utilize a range of methods, including voluntary vulnerability testing and red team-blue team exercises, to identify vulnerabilities in physical and cyber systems; develop cybersecurity risk assessment tools and provide confidential analyses and recommendations to participating stakeholders; work with stakeholders to develop methods to share anonymized and aggregated results in a format that enables the electricity sector, researchers, and the private sector to advance cybersecurity efforts, technologies, and tools; and leverage the unique strengths and expertise of the National Laboratories and Federal agencies; collaborate with relevant stakeholders to— identify information, research, staff training, and analysis tools needed to evaluate industrial control system cybersecurity issues and challenges in the electricity sector; and facilitate the sharing of information and the development of tools identified under subparagraph (A); collaborate with and support electricity sector trade organizations and their research agencies to improve the cybersecurity of industrial control systems used by members and stakeholders; and collaborate with tribal governments to— identify information, research, and analysis tools needed by tribal governments to increase the industrial control system cybersecurity of electricity assets within their jurisdiction; and facilitate the sharing of information and the development of tools needed to ensure the cybersecurity of tribal electricity assets and systems.
Information provided to Federal agencies for the purposes of carrying out subsection (a)(1)(C) shall be considered critical electric infrastructure information and provided the protections established in section 10.