We need new ways to protect the computer-connected systems that keep lights on and banks open... When critical infrastructure is attacked or essential data is stolen, companies need a clear way to report it to civilian authorities... it’s essential that privacy is protected.
Create stronger cybersecurity protections and reporting channels for critical infrastructure while protecting personal privacy.
Occurrences
Evidence
Congress.gov records S.754 as passed by the Senate on October 27, 2015, 74-21, and summarizes federal/private cyber threat sharing, required removal of unrelated personal information, and a DHS strategy for cyber incidents affecting critical infrastructure.
The Senate roll call for S.754 lists the vote result as Bill Passed, 74-21; Booker (D-NJ) is listed as Nay.
Public Law 114-113 includes Division N, Cybersecurity Act of 2015, authorizing cyber threat monitoring, defensive measures, and sharing with the federal government for cybersecurity purposes.
Section 105 required DHS to build a process to receive cyber threat indicators and defensive measures from non-federal entities through email, web forms, or automated real-time processes.
The law required processes for protecting personal information from unauthorized use or disclosure and for retaining, using, and disseminating cyber threat indicators under privacy guidelines.
The Senate agreed to the House amendments to H.R.2029 by 65-33 on December 18, 2015; Booker (D-NJ) is listed as Yea.
The law required DHS to assess plans for multiple simultaneous cyber incidents affecting critical infrastructure and report on cybersecurity vulnerabilities at high-risk U.S. ports.
Congress.gov records H.R.2471 as becoming Public Law 117-103 on March 15, 2022, after the Senate agreed to the House amendment by vote 68-31.
The Senate roll call on concurring in the House amendment to H.R.2471 lists Booker (D-NJ) as Yea; the motion was agreed to, 68-31.
Division Y requires covered entities to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours.
CIRCIA requires reported information to be handled under processes protecting personal information from unauthorized use or disclosure and provides FOIA, privilege, and liability protections for reports.
Assessments
The promised federal outcome was substantially enacted during Booker's first full Senate term after the 2014 campaign. Public Law 114-113, Division N, the Cybersecurity Act of 2015, created federal channels for non-federal entities to submit cyber threat indicators and defensive measures, included critical-infrastructure cyber incident planning and port vulnerability provisions, and required privacy procedures for protecting personal information. Booker voted for the final omnibus bill that enacted it. His nay vote on the standalone S.754 vehicle makes his role mixed, but the final enacted law he supported delivered the core promise. Later CIRCIA provisions in 2022 further strengthened mandatory critical-infrastructure reporting, but same-term delivery had already occurred.