Pub. L. 117-103, div. Y, sec. 107 (as amended)

CONGRESSIONAL REPORTING.

Year: 2025Length: 876 wordsOfficial source
SEC. 107. CONGRESSIONAL REPORTING. (a) Report on Stakeholder Engagement.—Not later than 30 days after the date on which the Director issues the final rule under section 2242(b) of the Homeland Security Act of 2002, as added by section 103 of this division, the Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report that describes how the Director engaged stakeholders in the development of the final rule. (b) Report on Opportunities to Strengthen Security Research.—Not later than 1 year after the date of enactment of this Act, the Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report describing how the National Cybersecurity and Communications Integration Center established under section 2209 of the Homeland Security Act of 2002 (6 U.S.C. 659) has carried out activities under section 2241(a)(9) of the Homeland Security Act of 2002, as added by section 103 of this division, by proactively identifying opportunities to use cyber incident data to inform and enable cybersecurity research within the academic and private sector. (c) Report on Ransomware Vulnerability Warning Pilot Program.—Not later than 1 year after the date of enactment of this Act, and annually thereafter for the duration of the pilot program established under section 105, the Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report, which may include a classified annex, on the effectiveness of the pilot program, which shall include a discussion of the following: (1) The effectiveness of the notifications under section 105(c) in mitigating security vulnerabilities and the threat of ransomware. (2) Identification of the most common vulnerabilities utilized in ransomware. (3) The number of notifications issued during the preceding year. (4) To the extent practicable, the number of vulnerable devices or systems mitigated under the pilot program by the Agency during the preceding year. (d) Report on Harmonization of Reporting Regulations.— (1) In general.—Not later than 180 days after the date on which the Secretary of Homeland Security convenes the Cyber Incident Reporting Council described in section 2246 of the Homeland Security Act of 2002, as added by section 103 of this division, the Secretary of Homeland Security shall submit to the appropriate congressional committees a report that includes— (A) a list of duplicative Federal cyber incident reporting requirements on covered entities; (B) a description of any challenges in harmonizing the duplicative reporting requirements; (C) any actions the Director intends to take to facilitate harmonizing the duplicative reporting requirements; and (D) any proposed legislative changes necessary to address the duplicative reporting. (2) Rule of construction.—Nothing in paragraph (1) shall be construed to provide any additional regulatory authority to any Federal agency. (e) GAO Reports.— (1) Implementation of this division.—Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the implementation of this division and the amendments made by this division. (2) Exemptions to reporting.—Not later than 1 year after the date on which the Director issues the final rule required under section 2242(b) of the Homeland Security Act of 2002, as added by section 103 of this division, the Comptroller General of the United States shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the exemptions to reporting under paragraphs (2) and (5) of section 2242(a) of the Homeland Security Act of 2002, as added by section 103 of this division, which shall include— (A) to the extent practicable, an evaluation of the quantity of cyber incidents not reported to the Federal Government; (B) an evaluation of the impact on impacted entities, homeland security, and the national economy due to cyber incidents, ransomware attacks, and ransom payments, including a discussion on the scope of impact of cyber incidents that were not reported to the Federal Government; (C) an evaluation of the burden, financial and otherwise, on entities required to report cyber incidents under this division, including an analysis of entities that meet the definition of a small business concern under section 3 of the Small Business Act (15 U.S.C. 632); and (D) a description of the consequences and effects of limiting covered cyber incident and ransom payment reporting to only covered entities. (f) Report on Effectiveness of Enforcement Mechanisms.—Not later than 1 year after the date on which the Director issues the final rule required under section 2242(b) of the Homeland Security Act of 2002, as added by section 103 of this division, the Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the effectiveness of the enforcement mechanisms within section 2244 of the Homeland Security Act of 2002, as added by section 103 of this division.
Pub. L. 117-103, div. Y, sec. 107 (as amended): CONGRESSIONAL REPORTING. | Justis AI