Sec. 6. Ransomware threat mitigation activities
363 words·~2 min read·
/bill/117/s/2875/rs/section-6·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than 180 days after the date of enactment of this section, the National Cyber Director shall establish and chair the Joint Ransomware Task Force to coordinate an ongoing, nationwide campaign against ransomware attacks, and identify and pursue opportunities for international cooperation. The Joint Ransomware Task Force shall consist of participants from Federal agencies, as determined appropriate by the National Cyber Director in consultation with the Secretary of Homeland Security.
The Joint Ransomware Task Force, utilizing only existing authorities of each participating agency, shall coordinate across the Federal Government the following activities: Prioritization of intelligence-driven operations to disrupt specific ransomware actors. Consult with relevant private sector, State, local, Tribal, and territorial governments and international stakeholders to identify needs and establish mechanisms for providing input into the Task Force. Identifying, in consultation with relevant entities, a list of highest threat ransomware entities updated on an ongoing basis, in order to facilitate— prioritization for Federal action by appropriate Federal agencies; and identify metrics for success of said actions.
Disrupting ransomware criminal actors, associated infrastructure, and their finances. Facilitating coordination and collaboration between Federal entities and relevant entities, including the private sector, to improve Federal actions against ransomware threats. Collection, sharing, and analysis of ransomware trends to inform Federal actions. Creation of after-action reports and other lessons learned from Federal actions that identify successes and failures to improve subsequent actions.
Any other activities determined appropriate by the task force to mitigate the threat of ransomware attacks against Federal and non-Federal entities. Not later than 180 days after the date of enactment of this Act, the National Cyber Director, in coordination with the Secretary of Homeland Security and the Attorney General, shall submit to the Committee on Homeland Security and Governmental Affairs and the Committee on the Judiciary of the Senate and the Committee on Homeland Security, the Committee on the Judiciary, and the Committee on Oversight and Reform of the House of Representatives a report that describes defensive measures that private-sector actors can take when countering ransomware attacks and what laws need to be clarified to enable that action.
Nothing in this section shall be construed as providing any additional authority to any Federal agency.