H. R. 2029—721 SEC. 206. REPORT ON REDUCING CYBERSECURITY RISKS IN DHS DATA CENTERS. Not later than 1 year after the date of the enactment of this Act, the Secretary shall submit to the appropriate congressional committees a report on the feasibility of the Department creating an environment for the reduction in cybersecurity risks in Department data centers, including by increasing compartmentalization between systems, and providing a mix of security controls between such compartments. SEC. 207. ASSESSMENT. Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall submit to the appropriate congressional committees a report that includes— (1) an assessment of the implementation by the Secretary of this title and the amendments made by this title; and (2) to the extent practicable, findings regarding increases in the sharing of cyber threat indicators, defensive measures, and information relating to cybersecurity risks and incidents at the center established under section 227 of the Homeland Security Act of 2002, as redesignated by section 223(a) of this division, and throughout the United States. SEC. 208. MULTIPLE SIMULTANEOUS CYBER INCIDENTS AT CRITICAL INFRASTRUCTURE. Not later than 1 year after the date of enactment of this Act, the Under Secretary appointed under section 103(a)(1)(H) of the Homeland Security Act of 2002 (6 U.S.C. 113(a)(1)(H)) shall provide information to the appropriate congressional committees on the feasibility of producing a risk-informed plan to address the risk of multiple simultaneous cyber incidents affecting critical infrastructure, including cyber incidents that may have a cascading effect on other critical infrastructure. SEC. 209. REPORT ON CYBERSECURITY VULNERABILITIES OF UNITED STATES PORTS. Not later than 180 days after the date of enactment of this Act, the Secretary shall submit to the appropriate congressional committees, the Committee on Commerce, Science and Transportation of the Senate, and the Committee on Transportation and Infrastructure of the House of Representatives a report on cybersecurity vulnerabilities for the 10 United States ports that the Secretary determines are at greatest risk of a cybersecurity incident and provide recommendations to mitigate such vulnerabilities. SEC. 210. PROHIBITION ON NEW REGULATORY AUTHORITY. Nothing in this subtitle or the amendments made by this subtitle may be construed to grant the Secretary any authority to promulgate regulations or set standards relating to the cybersecurity of non-Federal entities, not including State, local, and tribal governments, that was not in effect on the day before the date of enactment of this Act. SEC. 211. TERMINATION OF REPORTING REQUIREMENTS. Any reporting requirements in this subtitle shall terminate on the date that is 7 years after the date of enactment of this Act.

Select target paragraph3