Sec. 316. Strategy to secure email
260 words·~1 min read·
/bill/116/hr/8309/ih/section-316A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than December 31, 2021, the Secretary of Homeland Security shall develop and submit to Congress a strategy, including recommendations, to implement across all United States-based email providers Domain-based Message Authentication, Reporting, and Conformance standard at scale. The strategy required under subsection
(a)shall include the following: A recommendation for the minimum size threshold for United States-based email providers for applicability of Domain-based Message Authentication, Reporting, and Conformance. A description of the security and privacy benefits of implementing the Domain-based Message Authentication, Reporting, and Conformance standard at scale, including recommendations for national security exemptions, as appropriate, as well as the burdens of such implementation and an identification of the entities on which such burdens would most likely fall. An identification of key United States and international stakeholders associated with such implementation. An identification of any barriers to such implementing, including a cost-benefit analysis where feasible. An initial estimate of the total cost to the Federal Government and implementing entities in the private sector of such implementing, including recommendations for defraying such costs, if applicable. In developing the strategies and recommendations under subsection (a), the Secretary of Homeland Security may, as appropriate, consult with representatives from the information technology sector. The Federal Advisory Committee Act (5 U.S.C. App.) shall not apply to this section or to any action to implement this section. In this section, the term Domain-based Message Authentication, Reporting, and Conformance means an email authentication, policy, and reporting protocol that verifies the authenticity of the sender of an email and blocks and reports to the sender fraudulent accounts.