H. R. 2029—721
SEC. 206. REPORT ON REDUCING CYBERSECURITY RISKS IN DHS DATA
CENTERS.
Not later than 1 year after the date of the enactment of this
Act, the Secretary shall submit to the appropriate congressional
committees a report on the feasibility of the Department creating
an environment for the reduction in cybersecurity risks in Department data centers, including by increasing compartmentalization
between systems, and providing a mix of security controls between
such compartments.
SEC. 207. ASSESSMENT.
Not later than 2 years after the date of enactment of this
Act, the Comptroller General of the United States shall submit
to the appropriate congressional committees a report that includes—
(1) an assessment of the implementation by the Secretary
of this title and the amendments made by this title; and
(2) to the extent practicable, findings regarding increases
in the sharing of cyber threat indicators, defensive measures,
and information relating to cybersecurity risks and incidents
at the center established under section 227 of the Homeland
Security Act of 2002, as redesignated by section 223(a) of this
division, and throughout the United States.
SEC. 208. MULTIPLE SIMULTANEOUS CYBER INCIDENTS AT CRITICAL
INFRASTRUCTURE.
Not later than 1 year after the date of enactment of this
Act, the Under Secretary appointed under section 103(a)(1)(H) of
the Homeland Security Act of 2002 (6 U.S.C. 113(a)(1)(H)) shall
provide information to the appropriate congressional committees
on the feasibility of producing a risk-informed plan to address
the risk of multiple simultaneous cyber incidents affecting critical
infrastructure, including cyber incidents that may have a cascading
effect on other critical infrastructure.
SEC. 209. REPORT ON CYBERSECURITY VULNERABILITIES OF UNITED
STATES PORTS.
Not later than 180 days after the date of enactment of this
Act, the Secretary shall submit to the appropriate congressional
committees, the Committee on Commerce, Science and Transportation of the Senate, and the Committee on Transportation and
Infrastructure of the House of Representatives a report on cybersecurity vulnerabilities for the 10 United States ports that the Secretary determines are at greatest risk of a cybersecurity incident
and provide recommendations to mitigate such vulnerabilities.
SEC. 210. PROHIBITION ON NEW REGULATORY AUTHORITY.
Nothing in this subtitle or the amendments made by this subtitle may be construed to grant the Secretary any authority to
promulgate regulations or set standards relating to the cybersecurity of non-Federal entities, not including State, local, and tribal
governments, that was not in effect on the day before the date
of enactment of this Act.
SEC. 211. TERMINATION OF REPORTING REQUIREMENTS.
Any reporting requirements in this subtitle shall terminate
on the date that is 7 years after the date of enactment of this
Act.