1 | 1 | | II |
---|
2 | 2 | | 119THCONGRESS |
---|
3 | 3 | | 1 |
---|
4 | 4 | | STSESSION S. 754 |
---|
5 | 5 | | To direct the Secretary of Agriculture to periodically assess cybersecurity |
---|
6 | 6 | | threats to, and vulnerabilities in, the agriculture and food critical infra- |
---|
7 | 7 | | structure sector and to provide recommendations to enhance their secu- |
---|
8 | 8 | | rity and resilience, to require the Secretary of Agriculture to conduct |
---|
9 | 9 | | an annual cross-sector simulation exercise relating to a food-related emer- |
---|
10 | 10 | | gency or disruption, and for other purposes. |
---|
11 | 11 | | IN THE SENATE OF THE UNITED STATES |
---|
12 | 12 | | FEBRUARY26, 2025 |
---|
13 | 13 | | Mr. C |
---|
14 | 14 | | OTTON(for himself, Ms. SLOTKIN, Mr. RICKETTS, Mr. TILLIS, Ms. |
---|
15 | 15 | | L |
---|
16 | 16 | | UMMIS, Mr. BUDD, and Mrs. BRITT) introduced the following bill; which |
---|
17 | 17 | | was read twice and referred to the Committee on Agriculture, Nutrition, |
---|
18 | 18 | | and Forestry |
---|
19 | 19 | | A BILL |
---|
20 | 20 | | To direct the Secretary of Agriculture to periodically assess |
---|
21 | 21 | | cybersecurity threats to, and vulnerabilities in, the agri- |
---|
22 | 22 | | culture and food critical infrastructure sector and to |
---|
23 | 23 | | provide recommendations to enhance their security and |
---|
24 | 24 | | resilience, to require the Secretary of Agriculture to con- |
---|
25 | 25 | | duct an annual cross-sector simulation exercise relating |
---|
26 | 26 | | to a food-related emergency or disruption, and for other |
---|
27 | 27 | | purposes. |
---|
28 | 28 | | Be it enacted by the Senate and House of Representa-1 |
---|
29 | 29 | | tives of the United States of America in Congress assembled, 2 |
---|
30 | 30 | | VerDate Sep 11 2014 23:18 Mar 13, 2025 Jkt 059200 PO 00000 Frm 00001 Fmt 6652 Sfmt 6201 E:\BILLS\S754.IS S754 |
---|
31 | 31 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 2 |
---|
32 | 32 | | •S 754 IS |
---|
33 | 33 | | SECTION 1. SHORT TITLE. 1 |
---|
34 | 34 | | This Act may be cited as the ‘‘Farm and Food Cyber-2 |
---|
35 | 35 | | security Act of 2025’’. 3 |
---|
36 | 36 | | SEC. 2. DEFINITIONS. 4 |
---|
37 | 37 | | In this Act: 5 |
---|
38 | 38 | | (1) A |
---|
39 | 39 | | GRICULTURE AND FOOD CRITICAL INFRA -6 |
---|
40 | 40 | | STRUCTURE SECTOR .—The term ‘‘agriculture and 7 |
---|
41 | 41 | | food critical infrastructure sector’’ means— 8 |
---|
42 | 42 | | (A) any activity relating to the production, 9 |
---|
43 | 43 | | processing, distribution, storage, transportation, 10 |
---|
44 | 44 | | consumption, or disposal of agricultural or food 11 |
---|
45 | 45 | | products; and 12 |
---|
46 | 46 | | (B) any entity involved in an activity de-13 |
---|
47 | 47 | | scribed in subparagraph (A), including a farm-14 |
---|
48 | 48 | | er, rancher, processor, manufacturer, dis-15 |
---|
49 | 49 | | tributor, retailer, consumer, and regulator. 16 |
---|
50 | 50 | | (2) C |
---|
51 | 51 | | YBERSECURITY THREAT ; DEFENSIVE 17 |
---|
52 | 52 | | MEASURE; INCIDENT; SECURITY VULNERABILITY .— 18 |
---|
53 | 53 | | The terms ‘‘cybersecurity threat’’, ‘‘defensive meas-19 |
---|
54 | 54 | | ure’’, ‘‘incident’’, and ‘‘security vulnerability’’ have 20 |
---|
55 | 55 | | the meanings given those terms in section 2200 of 21 |
---|
56 | 56 | | the Homeland Security Act of 2002 (6 U.S.C. 650). 22 |
---|
57 | 57 | | (3) S |
---|
58 | 58 | | ECRETARY.—The term ‘‘Secretary’’ means 23 |
---|
59 | 59 | | the Secretary of Agriculture. 24 |
---|
60 | 60 | | VerDate Sep 11 2014 23:18 Mar 13, 2025 Jkt 059200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\S754.IS S754 |
---|
61 | 61 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 3 |
---|
62 | 62 | | •S 754 IS |
---|
63 | 63 | | (4) SECTOR-SPECIFICISAC.—The term ‘‘sec-1 |
---|
64 | 64 | | tor-specific ISAC’’ means the Food and Agriculture- 2 |
---|
65 | 65 | | Information Sharing and Analysis Center. 3 |
---|
66 | 66 | | SEC. 3. ASSESSMENT OF CYBERSECURITY THREATS AND 4 |
---|
67 | 67 | | SECURITY VULNERABILITIES IN THE AGRI-5 |
---|
68 | 68 | | CULTURE AND FOOD CRITICAL INFRASTRUC-6 |
---|
69 | 69 | | TURE SECTOR. 7 |
---|
70 | 70 | | (a) R |
---|
71 | 71 | | ISKASSESSMENT.—The Secretary, in coordina-8 |
---|
72 | 72 | | tion with the Cybersecurity and Infrastructure Security 9 |
---|
73 | 73 | | Agency, shall conduct a risk assessment, on a biennial 10 |
---|
74 | 74 | | basis, on the cybersecurity threats to, and security 11 |
---|
75 | 75 | | vulnerabilities in, the agriculture and food critical infra-12 |
---|
76 | 76 | | structure sector, including— 13 |
---|
77 | 77 | | (1) the nature and extent of cyberattacks and 14 |
---|
78 | 78 | | incidents that affect the agriculture and food critical 15 |
---|
79 | 79 | | infrastructure sector; 16 |
---|
80 | 80 | | (2) the potential impacts of a cyberattack or in-17 |
---|
81 | 81 | | cident on the safety, security, and availability of 18 |
---|
82 | 82 | | food products, as well as on the economy, public 19 |
---|
83 | 83 | | health, and national security of the United States; 20 |
---|
84 | 84 | | (3) the current capability and readiness of the 21 |
---|
85 | 85 | | Federal Government, State and local governments, 22 |
---|
86 | 86 | | and private sector entities to prevent, detect, miti-23 |
---|
87 | 87 | | gate, respond to, and recover from cyberattacks and 24 |
---|
88 | 88 | | incidents described in paragraph (2); 25 |
---|
89 | 89 | | VerDate Sep 11 2014 23:18 Mar 13, 2025 Jkt 059200 PO 00000 Frm 00003 Fmt 6652 Sfmt 6201 E:\BILLS\S754.IS S754 |
---|
90 | 90 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 4 |
---|
91 | 91 | | •S 754 IS |
---|
92 | 92 | | (4) the existing policies, standards, guidelines, 1 |
---|
93 | 93 | | best practices, and initiatives applicable to the agri-2 |
---|
94 | 94 | | culture and food critical infrastructure sector to en-3 |
---|
95 | 95 | | hance defensive measures in that sector; 4 |
---|
96 | 96 | | (5) the gaps, challenges, barriers, or opportuni-5 |
---|
97 | 97 | | ties for improving defensive measures in the agri-6 |
---|
98 | 98 | | culture and food critical infrastructure sector; and 7 |
---|
99 | 99 | | (6) any recommendations for Federal legislative 8 |
---|
100 | 100 | | or administrative actions to address the cybersecu-9 |
---|
101 | 101 | | rity threats to, and security vulnerabilities in, the 10 |
---|
102 | 102 | | agriculture and food critical infrastructure sector, 11 |
---|
103 | 103 | | including intrusive, duplicative, or conflicting regu-12 |
---|
104 | 104 | | latory requirements that may divert attention and 13 |
---|
105 | 105 | | resources from operational risk management to a 14 |
---|
106 | 106 | | compliance regime that impedes security efforts. 15 |
---|
107 | 107 | | (b) P |
---|
108 | 108 | | RIVATESECTORPARTICIPATION.—In con-16 |
---|
109 | 109 | | ducting a risk assessment under subsection (a), the Sec-17 |
---|
110 | 110 | | retary shall consult with appropriate entities in the private 18 |
---|
111 | 111 | | sector, including— 19 |
---|
112 | 112 | | (1) the sector-specific ISAC; and 20 |
---|
113 | 113 | | (2) the appropriate sector coordinating council. 21 |
---|
114 | 114 | | (c) B |
---|
115 | 115 | | IENNIALREPORT.—Not later than 1 year after 22 |
---|
116 | 116 | | the date of enactment of this Act, and every 2 years there-23 |
---|
117 | 117 | | after, the Secretary shall submit a report on each risk as-24 |
---|
118 | 118 | | sessment conducted under subsection (a) to— 25 |
---|
119 | 119 | | VerDate Sep 11 2014 23:18 Mar 13, 2025 Jkt 059200 PO 00000 Frm 00004 Fmt 6652 Sfmt 6201 E:\BILLS\S754.IS S754 |
---|
120 | 120 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 5 |
---|
121 | 121 | | •S 754 IS |
---|
122 | 122 | | (1) the Committee on Agriculture, Nutrition, 1 |
---|
123 | 123 | | and Forestry of the Senate; 2 |
---|
124 | 124 | | (2) the Committee on Homeland Security and 3 |
---|
125 | 125 | | Governmental Affairs of the Senate; 4 |
---|
126 | 126 | | (3) the Committee on Agriculture of the House 5 |
---|
127 | 127 | | of Representatives; and 6 |
---|
128 | 128 | | (4) the Committee on Homeland Security of the 7 |
---|
129 | 129 | | House of Representatives. 8 |
---|
130 | 130 | | SEC. 4. FOOD SECURITY AND CYBER RESILIENCE SIMULA-9 |
---|
131 | 131 | | TION EXERCISE. 10 |
---|
132 | 132 | | (a) E |
---|
133 | 133 | | STABLISHMENT.—The Secretary, in coordina-11 |
---|
134 | 134 | | tion with the Secretary of Homeland Security, the Sec-12 |
---|
135 | 135 | | retary of Health and Human Services, the Director of Na-13 |
---|
136 | 136 | | tional Intelligence, and the heads of other relevant Federal 14 |
---|
137 | 137 | | agencies, shall conduct, over a 5-year period, an annual 15 |
---|
138 | 138 | | cross-sector crisis simulation exercise relating to a food- 16 |
---|
139 | 139 | | related emergency or disruption (referred to in this section 17 |
---|
140 | 140 | | as an ‘‘exercise’’). 18 |
---|
141 | 141 | | (b) P |
---|
142 | 142 | | URPOSES.—The purposes of each exercise are— 19 |
---|
143 | 143 | | (1) to assess the preparedness and response ca-20 |
---|
144 | 144 | | pabilities of Federal, State, Tribal, local, and terri-21 |
---|
145 | 145 | | torial governments and private sector entities in the 22 |
---|
146 | 146 | | event of a food-related emergency or disruption; 23 |
---|
147 | 147 | | VerDate Sep 11 2014 23:18 Mar 13, 2025 Jkt 059200 PO 00000 Frm 00005 Fmt 6652 Sfmt 6201 E:\BILLS\S754.IS S754 |
---|
148 | 148 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 6 |
---|
149 | 149 | | •S 754 IS |
---|
150 | 150 | | (2) to identify and address gaps and 1 |
---|
151 | 151 | | vulnerabilities in the food supply chain and critical 2 |
---|
152 | 152 | | infrastructure; 3 |
---|
153 | 153 | | (3) to enhance coordination and information 4 |
---|
154 | 154 | | sharing among stakeholders involved in food produc-5 |
---|
155 | 155 | | tion, processing, distribution, and consumption; 6 |
---|
156 | 156 | | (4) to evaluate the effectiveness and efficiency 7 |
---|
157 | 157 | | of existing policies, programs, and resources relating 8 |
---|
158 | 158 | | to food security and resilience; 9 |
---|
159 | 159 | | (5) to develop and disseminate best practices 10 |
---|
160 | 160 | | and recommendations for improving food security 11 |
---|
161 | 161 | | and resilience; and 12 |
---|
162 | 162 | | (6) to identify key stakeholders and categories 13 |
---|
163 | 163 | | that were missing from the exercise to ensure the in-14 |
---|
164 | 164 | | clusion of those stakeholders and categories in fu-15 |
---|
165 | 165 | | ture exercises. 16 |
---|
166 | 166 | | (c) D |
---|
167 | 167 | | ESIGN.—Each exercise shall— 17 |
---|
168 | 168 | | (1) involve a realistic and plausible scenario 18 |
---|
169 | 169 | | that simulates a food-related emergency or disrup-19 |
---|
170 | 170 | | tion affecting multiple sectors and jurisdictions; 20 |
---|
171 | 171 | | (2) incorporate input from experts and stake-21 |
---|
172 | 172 | | holders from various disciplines and sectors, includ-22 |
---|
173 | 173 | | ing agriculture, public health, nutrition, emergency 23 |
---|
174 | 174 | | management, transportation, energy, water, commu-24 |
---|
175 | 175 | | nications, related equipment suppliers and manufac-25 |
---|
176 | 176 | | VerDate Sep 11 2014 23:18 Mar 13, 2025 Jkt 059200 PO 00000 Frm 00006 Fmt 6652 Sfmt 6201 E:\BILLS\S754.IS S754 |
---|
177 | 177 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 7 |
---|
178 | 178 | | •S 754 IS |
---|
179 | 179 | | turers, and cybersecurity, including related academia 1 |
---|
180 | 180 | | and private sector information security researchers 2 |
---|
181 | 181 | | and practitioners, including the sector-specific ISAC; 3 |
---|
182 | 182 | | (3) use a variety of methods and tools, such as 4 |
---|
183 | 183 | | tabletop exercises, workshops, seminars, games, 5 |
---|
184 | 184 | | drills, or full-scale exercises; and 6 |
---|
185 | 185 | | (4) include participants from Federal, State, 7 |
---|
186 | 186 | | Tribal, local, and territorial governments and private 8 |
---|
187 | 187 | | sector entities, including the sector-specific ISAC 9 |
---|
188 | 188 | | and appropriate sector coordinating councils, that 10 |
---|
189 | 189 | | have roles and responsibilities relating to food secu-11 |
---|
190 | 190 | | rity and resilience. 12 |
---|
191 | 191 | | (d) P |
---|
192 | 192 | | RIVATESECTORPARTICIPATION.—In con-13 |
---|
193 | 193 | | ducting an exercise, the Secretary shall consult with ap-14 |
---|
194 | 194 | | propriate entities in the private sector, including— 15 |
---|
195 | 195 | | (1) the sector-specific ISAC; and 16 |
---|
196 | 196 | | (2) the appropriate sector coordinating councils. 17 |
---|
197 | 197 | | (e) F |
---|
198 | 198 | | EEDBACK; REPORT.—After each exercise, the 18 |
---|
199 | 199 | | Secretary, in consultation with the heads of the Federal 19 |
---|
200 | 200 | | agencies described in subsection (a), shall— 20 |
---|
201 | 201 | | (1) provide feedback to, and an evaluation of, 21 |
---|
202 | 202 | | the participants in that exercise on their perform-22 |
---|
203 | 203 | | ance and outcomes; and 23 |
---|
204 | 204 | | (2) produce, and submit to Congress, a report 24 |
---|
205 | 205 | | that summarizes, with respect to that exercise, the 25 |
---|
206 | 206 | | VerDate Sep 11 2014 23:18 Mar 13, 2025 Jkt 059200 PO 00000 Frm 00007 Fmt 6652 Sfmt 6201 E:\BILLS\S754.IS S754 |
---|
207 | 207 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 8 |
---|
208 | 208 | | •S 754 IS |
---|
209 | 209 | | findings of that exercise, lessons learned from that 1 |
---|
210 | 210 | | exercise, and recommendations to enhance the cyber-2 |
---|
211 | 211 | | security and resilience of the agriculture and food 3 |
---|
212 | 212 | | critical infrastructure sector. 4 |
---|
213 | 213 | | (f) A |
---|
214 | 214 | | UTHORIZATION OF APPROPRIATIONS.—There is 5 |
---|
215 | 215 | | authorized to be appropriated to carry out this section 6 |
---|
216 | 216 | | $1,000,000 for each of fiscal years 2026 through 2030. 7 |
---|
217 | 217 | | Æ |
---|
218 | 218 | | VerDate Sep 11 2014 23:18 Mar 13, 2025 Jkt 059200 PO 00000 Frm 00008 Fmt 6652 Sfmt 6301 E:\BILLS\S754.IS S754 |
---|
219 | 219 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB |
---|