<section xmlns="http://xml.house.gov/schemas/uslm/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" style="-uslm-lc:I80" id="idf77a1256-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121"><num value="121">§ 121.</num><heading> Information and Analysis and Infrastructure Protection</heading><subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idf77a1257-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/a"><num value="a" class="bold">(a)</num><heading class="bold"> Intelligence and analysis and infrastructure protection</heading><content><p style="-uslm-lc:I11" class="indent0">There shall be in the Department an Office of Intelligence and Analysis and an Office of Infrastructure Protection.</p>
</content>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idf77a1258-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/b"><num value="b" class="bold">(b)</num><heading class="bold"> Under Secretary for Intelligence and Analysis and Assistant Secretary for Infrastructure Protection</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idf77a1259-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/b/1"><num value="1" class="bold">(1)</num><heading class="bold"> Office of Intelligence and Analysis</heading><content><p style="-uslm-lc:I12" class="indent1">The Office of Intelligence and Analysis shall be headed by an Under Secretary for Intelligence and Analysis, who shall be appointed by the President, by and with the advice and consent of the Senate.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idf77a125a-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/b/2"><num value="2" class="bold">(2)</num><heading class="bold"> Chief Intelligence Officer</heading><content><p style="-uslm-lc:I12" class="indent1">The Under Secretary for Intelligence and Analysis shall serve as the Chief Intelligence Officer of the Department.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idf77a125b-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/b/3"><num value="3" class="bold">(3)</num><heading class="bold"> Office of Infrastructure Protection</heading><content><p style="-uslm-lc:I12" class="indent1">The Office of Infrastructure Protection shall be headed by an Assistant Secretary for Infrastructure Protection, who shall be appointed by the President.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idf77a396c-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/c"><num value="c" class="bold">(c)</num><heading class="bold"> Discharge of responsibilities</heading><content><p style="-uslm-lc:I11" class="indent0">The Secretary shall ensure that the responsibilities of the Department relating to information analysis and infrastructure protection, including those described in subsection (d), are carried out through the Under Secretary for Intelligence and Analysis or the Assistant Secretary for Infrastructure Protection, as appropriate.</p>
</content>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idf77a396d-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d"><num value="d" class="bold">(d)</num><heading class="bold"> Responsibilities of Secretary relating to intelligence and analysis and infrastructure protection</heading><chapeau>The responsibilities of the Secretary relating to intelligence and analysis and infrastructure protection shall be as follows:</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="idf77a396e-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/1"><num value="1">(1)</num><chapeau> To access, receive, and analyze law enforcement information, intelligence information, and other information from agencies of the Federal Government, State and local government agencies (including law enforcement agencies), and private sector entities, and to integrate such information, in support of the mission responsibilities of the Department and the functions of the National Counterterrorism Center established under section 119 of the National Security Act of 1947 [<ref href="/us/usc/t50/s3056">50 U.S.C. 3056</ref>], in order to—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idf77a396f-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/1/A"><num value="A">(A)</num><content> identify and assess the nature and scope of terrorist threats to the homeland;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77a3970-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/1/B"><num value="B">(B)</num><content> detect and identify threats of terrorism against the United States; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77a3971-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/1/C"><num value="C">(C)</num><content> understand such threats in light of actual and potential vulnerabilities of the homeland.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a3972-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/2"><num value="2">(2)</num><content> To carry out comprehensive assessments of the vulnerabilities of the key resources and critical infrastructure of the United States, including the performance of risk assessments to determine the risks posed by particular types of terrorist attacks within the United States (including an assessment of the probability of success of such attacks and the feasibility and potential efficacy of various countermeasures to such attacks).</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a3973-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/3"><num value="3">(3)</num><chapeau> To integrate relevant information, analysis, and vulnerability assessments (regardless of whether such information, analysis or assessments are provided by or produced by the Department) in order to—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idf77a3974-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/3/A"><num value="A">(A)</num><content> identify priorities for protective and support measures regarding terrorist and other threats to homeland security by the Department, other agencies of the Federal Government, State, and local government agencies and authorities, the private sector, and other entities; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77a3975-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/3/B"><num value="B">(B)</num><content> prepare finished intelligence and information products in both classified and unclassified formats, as appropriate, whenever reasonably expected to be of benefit to a State, local, or tribal government (including a State, local, or tribal law enforcement agency) or a private sector entity.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a6086-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/4"><num value="4">(4)</num><content> To ensure, pursuant to <ref href="/us/usc/t6/s122">section 122 of this title</ref>, the timely and efficient access by the Department to all information necessary to discharge the responsibilities under this section, including obtaining such information from other agencies of the Federal Government.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a6087-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/5"><num value="5">(5)</num><content> To develop a comprehensive national plan for securing the key resources and critical infrastructure of the United States, including power production, generation, and distribution systems, information technology and telecommunications systems (including satellites), electronic financial and property record storage and transmission systems, emergency preparedness communications systems, and the physical and technological assets that support such systems.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a6088-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/6"><num value="6">(6)</num><content> To recommend measures necessary to protect the key resources and critical infrastructure of the United States in coordination with other agencies of the Federal Government and in cooperation with State and local government agencies and authorities, the private sector, and other entities.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a6089-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/7"><num value="7">(7)</num><content> To review, analyze, and make recommendations for improvements to the policies and procedures governing the sharing of information within the scope of the information sharing environment established under <ref href="/us/usc/t6/s485">section 485 of this title</ref>, including homeland security information, terrorism information, and weapons of mass destruction information, and any policies, guidelines, procedures, instructions, or standards established under that section.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a608a-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/8"><num value="8">(8)</num><content> To disseminate, as appropriate, information analyzed by the Department within the Department, to other agencies of the Federal Government with responsibilities relating to homeland security, and to agencies of State and local governments and private sector entities with such responsibilities in order to assist in the deterrence, prevention, preemption of, or response to, terrorist attacks against the United States.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a608b-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/9"><num value="9">(9)</num><content> To consult with the Director of National Intelligence and other appropriate intelligence, law enforcement, or other elements of the Federal Government to establish collection priorities and strategies for information, including law enforcement-related information, relating to threats of terrorism against the United States through such means as the representation of the Department in discussions regarding requirements and priorities in the collection of such information.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a879c-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/10"><num value="10">(10)</num><content> To consult with State and local governments and private sector entities to ensure appropriate exchanges of information, including law enforcement-related information, relating to threats of terrorism against the United States.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a879d-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/11"><num value="11">(11)</num><chapeau> To ensure that—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idf77a879e-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/11/A"><num value="A">(A)</num><content> any material received pursuant to this chapter is protected from unauthorized disclosure and handled and used only for the performance of official duties; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77a879f-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/11/B"><num value="B">(B)</num><content> any intelligence information under this chapter is shared, retained, and disseminated consistent with the authority of the Director of National Intelligence to protect intelligence sources and methods under the National Security Act of 1947 [<ref href="/us/usc/t50/s3001">50 U.S.C. 3001</ref> et seq.] and related procedures and, as appropriate, similar authorities of the Attorney General concerning sensitive law enforcement information.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a87a0-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/12"><num value="12">(12)</num><content> To request additional information from other agencies of the Federal Government, State and local government agencies, and the private sector relating to threats of terrorism in the United States, or relating to other areas of responsibility assigned by the Secretary, including the entry into cooperative agreements through the Secretary to obtain such information.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a87a1-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/13"><num value="13">(13)</num><content> To establish and utilize, in conjunction with the chief information officer of the Department, a secure communications and information technology infrastructure, including data-mining and other advanced analytical tools, in order to access, receive, and analyze data and information in furtherance of the responsibilities under this section, and to disseminate information acquired and analyzed by the Department, as appropriate.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77a87a2-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/14"><num value="14">(14)</num><chapeau> To ensure, in conjunction with the chief information officer of the Department, that any information databases and analytical tools developed or utilized by the Department—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idf77a87a3-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/14/A"><num value="A">(A)</num><content> are compatible with one another and with relevant information databases of other agencies of the Federal Government; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77a87a4-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/14/B"><num value="B">(B)</num><content> treat information in such databases in a manner that complies with applicable Federal law on privacy.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77aaeb5-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/15"><num value="15">(15)</num><content> To coordinate training and other support to the elements and personnel of the Department, other agencies of the Federal Government, and State and local governments that provide information to the Department, or are consumers of information provided by the Department, in order to facilitate the identification and sharing of information revealed in their ordinary duties and the optimal utilization of information received from the Department.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77aaeb6-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/16"><num value="16">(16)</num><content> To coordinate with elements of the intelligence community and with Federal, State, and local law enforcement agencies, and the private sector, as appropriate.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77aaeb7-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/17"><num value="17">(17)</num><content> To provide intelligence and information analysis and support to other elements of the Department.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77aaeb8-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/18"><num value="18">(18)</num><content> To coordinate and enhance integration among the intelligence components of the Department, including through strategic oversight of the intelligence activities of such components.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77aaeb9-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/19"><num value="19">(19)</num><content> To establish the intelligence collection, processing, analysis, and dissemination priorities, policies, processes, standards, guidelines, and procedures for the intelligence components of the Department, consistent with any directions from the President and, as applicable, the Director of National Intelligence.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77aaeba-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/20"><num value="20">(20)</num><content> To establish a structure and process to support the missions and goals of the intelligence components of the Department.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77aaebb-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/21"><num value="21">(21)</num><chapeau> To ensure that, whenever possible, the Department—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idf77aaebc-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/21/A"><num value="A">(A)</num><content> produces and disseminates unclassified reports and analytic products based on open-source information; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77aaebd-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/21/B"><num value="B">(B)</num><content> produces and disseminates such reports and analytic products contemporaneously with reports or analytic products concerning the same or similar information that the Department produced and disseminated in a classified format.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77aaebe-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/22"><num value="22">(22)</num><content> To establish within the Office of Intelligence and Analysis an internal continuity of operations plan.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77aaebf-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/23"><num value="23">(23)</num><chapeau> Based on intelligence priorities set by the President, and guidance from the Secretary and, as appropriate, the Director of National Intelligence—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idf77aaec0-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/23/A"><num value="A">(A)</num><content> to provide to the heads of each intelligence component of the Department guidance for developing the budget pertaining to the activities of such component; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77ad4d1-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/23/B"><num value="B">(B)</num><content> to present to the Secretary a recommendation for a consolidated budget for the intelligence components of the Department, together with any comments from the heads of such components.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77ad4d2-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/24"><num value="24">(24)</num><content> To perform such other duties relating to such responsibilities as the Secretary may provide.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77ad4d3-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/25"><num value="25">(25)</num><chapeau> To prepare and submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security in the House of Representatives, and to other appropriate congressional committees having jurisdiction over the critical infrastructure or key resources, for each sector identified in the National Infrastructure Protection Plan, a report on the comprehensive assessments carried out by the Secretary of the critical infrastructure and key resources of the United States, evaluating threat, vulnerability, and consequence, as required under this subsection. Each such report—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idf77ad4d4-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/25/A"><num value="A">(A)</num><content> shall contain, if applicable, actions or countermeasures recommended or taken by the Secretary or the head of another Federal agency to address issues identified in the assessments;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77ad4d5-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/25/B"><num value="B">(B)</num><content> shall be required for fiscal year 2007 and each subsequent fiscal year and shall be submitted not later than 35 days after the last day of the fiscal year covered by the report; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77ad4d6-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/25/C"><num value="C">(C)</num><content> may be classified.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77ad4d7-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26"><num value="26">(26)</num><subparagraph style="-uslm-lc:I12" class="indent1" id="idf77ad4d8-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26/A"><num value="A">(A)</num><chapeau> Not later than six months after <date date="2016-12-23">December 23, 2016</date>, to conduct an intelligence-based review and comparison of the risks and consequences of EMP and GMD facing critical infrastructure, and submit to the Committee on Homeland Security and the Permanent Select Committee on Intelligence of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Select Committee on Intelligence of the Senate—</chapeau><clause style="-uslm-lc:I13" class="indent2" id="idf77ad4d9-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26/A/i"><num value="i">(i)</num><content> a recommended strategy to protect and prepare the critical infrastructure of the homeland against threats of EMP and GMD; and</content>
</clause>
<clause style="-uslm-lc:I13" class="indent2" id="idf77afbea-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26/A/ii"><num value="ii">(ii)</num><content> not less frequently than every two years thereafter for the next six years, updates of the recommended strategy.</content>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I12" class="indent1" id="idf77afbeb-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26/B"><num value="B">(B)</num><chapeau> The recommended strategy under subparagraph (A) shall—</chapeau><clause style="-uslm-lc:I13" class="indent2" id="idf77afbec-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26/B/i"><num value="i">(i)</num><content> be based on findings of the research and development conducted under <ref href="/us/usc/t6/s195f">section 195f of this title</ref>; <ref class="footnoteRef" idref="fn002002">1</ref><note type="footnote" id="fn002002"><num>1</num> See References in Text note below.</note></content>
</clause>
<clause style="-uslm-lc:I13" class="indent2" id="idf77afbed-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26/B/ii"><num value="ii">(ii)</num><content> be developed in consultation with the relevant Federal sector-specific agencies (as defined under Presidential Policy Directive-21) for critical infrastructure;</content>
</clause>
<clause style="-uslm-lc:I13" class="indent2" id="idf77afbee-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26/B/iii"><num value="iii">(iii)</num><content> be developed in consultation with the relevant sector coordinating councils for critical infrastructure;</content>
</clause>
<clause style="-uslm-lc:I13" class="indent2" id="idf77afbef-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26/B/iv"><num value="iv">(iv)</num><content> be informed, to the extent practicable, by the findings of the intelligence-based review and comparison of the risks and consequences of EMP and GMD facing critical infrastructure conducted under subparagraph (A); and</content>
</clause>
<clause style="-uslm-lc:I13" class="indent2" id="idf77afbf0-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26/B/v"><num value="v">(v)</num><content> be submitted in unclassified form, but may include a classified annex.</content>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I12" class="indent1" id="idf77afbf1-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/d/26/C"><num value="C">(C)</num><content> The Secretary may, if appropriate, incorporate the recommended strategy into a broader recommendation developed by the Department to help protect and prepare critical infrastructure from terrorism, cyber attacks, and other threats if, as incorporated, the recommended strategy complies with subparagraph (B).</content>
</subparagraph>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idf77afbf2-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/e"><num value="e" class="bold">(e)</num><heading class="bold"> Staff</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idf77afbf3-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/e/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I12" class="indent1">The Secretary shall provide the Office of Intelligence and Analysis and the Office of Infrastructure Protection with a staff of analysts having appropriate expertise and experience to assist such offices in discharging responsibilities under this section.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idf77b2304-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/e/2"><num value="2" class="bold">(2)</num><heading class="bold"> Private sector analysts</heading><content><p style="-uslm-lc:I12" class="indent1">Analysts under this subsection may include analysts from the private sector.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idf77b2305-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/e/3"><num value="3" class="bold">(3)</num><heading class="bold"> Security clearances</heading><content><p style="-uslm-lc:I12" class="indent1">Analysts under this subsection shall possess security clearances appropriate for their work under this section.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idf77b2306-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f"><num value="f" class="bold">(f)</num><heading class="bold"> Detail of personnel</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idf77b2307-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I12" class="indent1">In order to assist the Office of Intelligence and Analysis and the Office of Infrastructure Protection in discharging responsibilities under this section, personnel of the agencies referred to in paragraph (2) may be detailed to the Department for the performance of analytic functions and related duties.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idf77b2308-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/2"><num value="2" class="bold">(2)</num><heading class="bold"> Covered agencies</heading><chapeau>The agencies referred to in this paragraph are as follows:</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idf77b2309-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/2/A"><num value="A">(A)</num><content> The Department of State.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77b230a-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/2/B"><num value="B">(B)</num><content> The Central Intelligence Agency.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77b230b-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/2/C"><num value="C">(C)</num><content> The Federal Bureau of Investigation.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77b230c-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/2/D"><num value="D">(D)</num><content> The National Security Agency.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77b230d-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/2/E"><num value="E">(E)</num><content> The National Geospatial-Intelligence Agency.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77b230e-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/2/F"><num value="F">(F)</num><content> The Defense Intelligence Agency.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idf77b230f-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/2/G"><num value="G">(G)</num><content> Any other agency of the Federal Government that the President considers appropriate.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idf77b2310-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/3"><num value="3" class="bold">(3)</num><heading class="bold"> Cooperative agreements</heading><content><p style="-uslm-lc:I12" class="indent1">The Secretary and the head of the agency concerned may enter into cooperative agreements for the purpose of detailing personnel under this subsection.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idf77b2311-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/f/4"><num value="4" class="bold">(4)</num><heading class="bold"> Basis</heading><content><p style="-uslm-lc:I12" class="indent1">The detail of personnel under this subsection may be on a reimbursable or non-reimbursable basis.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idf77b2312-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/g"><num value="g" class="bold">(g)</num><heading class="bold"> Functions transferred</heading><chapeau>In accordance with subchapter XII, there shall be transferred to the Secretary, for assignment to the Office of Intelligence and Analysis and the Office of Infrastructure Protection under this section, the functions, personnel, assets, and liabilities of the following:</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="idf77b2313-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/g/1"><num value="1">(1)</num><content> The National Infrastructure Protection Center of the Federal Bureau of Investigation (other than the Computer Investigations and Operations Section), including the functions of the Attorney General relating thereto.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77b4a24-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/g/2"><num value="2">(2)</num><content> The National Communications System of the Department of Defense, including the functions of the Secretary of Defense relating thereto.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77b4a25-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/g/3"><num value="3">(3)</num><content> The Critical Infrastructure Assurance Office of the Department of Commerce, including the functions of the Secretary of Commerce relating thereto.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77b4a26-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/g/4"><num value="4">(4)</num><content> The National Infrastructure Simulation and Analysis Center of the Department of Energy and the energy security and assurance program and activities of the Department, including the functions of the Secretary of Energy relating thereto.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idf77b4a27-4154-11e7-bab8-e125cf475dd2" identifier="/us/usc/t6/s121/g/5"><num value="5">(5)</num><content> The Federal Computer Incident Response Center of the General Services Administration, including the functions of the Administrator of General Services relating thereto.</content>
</paragraph>
</subsection>
<sourceCredit id="idf77b4a28-4154-11e7-bab8-e125cf475dd2">(<ref href="/us/pl/107/296/tII">Pub. L. 107–296, title II</ref>, § 201, <date date="2002-11-25">Nov. 25, 2002</date>, <ref href="/us/stat/116/2145">116 Stat. 2145</ref>; <ref href="/us/pl/110/53/tV">Pub. L. 110–53, title V</ref>, §§ 501(a)(2)(A), (b), 531(a), title X, § 1002(a), <date date="2007-08-03">Aug. 3, 2007</date>, <ref href="/us/stat/121/309">121 Stat. 309</ref>, 332, 374; <ref href="/us/pl/110/417">Pub. L. 110–417</ref>, [div. A], title IX, § 931(b)(5), <date date="2008-10-14">Oct. 14, 2008</date>, <ref href="/us/stat/122/4575">122 Stat. 4575</ref>; <ref href="/us/pl/111/84/dA/tX">Pub. L. 111–84, div. A, title X</ref>, § 1073(c)(9), <date date="2009-10-28">Oct. 28, 2009</date>, <ref href="/us/stat/123/2475">123 Stat. 2475</ref>; <ref href="/us/pl/111/258">Pub. L. 111–258</ref>, § 5(b)(1), <date date="2010-10-07">Oct. 7, 2010</date>, <ref href="/us/stat/124/2650">124 Stat. 2650</ref>; <ref href="/us/pl/114/328/dA/tXIX">Pub. L. 114–328, div. A, title XIX</ref>, § 1913(a)(2), <date date="2016-12-23">Dec. 23, 2016</date>, <ref href="/us/stat/130/2685">130 Stat. 2685</ref>.)</sourceCredit>
<notes type="uscNote" id="idf77b4a29-4154-11e7-bab8-e125cf475dd2">
<note style="-uslm-lc:I75" topic="referencesInText" id="idf77b4a2a-4154-11e7-bab8-e125cf475dd2">
<heading class="centered smallCaps">References in Text</heading><p style="-uslm-lc:I21" class="indent0">This chapter, referred to in subsec. (d)(11), was in the original “this Act”, meaning <ref href="/us/pl/107/296">Pub. L. 107–296</ref>, <date date="2002-11-25">Nov. 25, 2002</date>, <ref href="/us/stat/116/2135">116 Stat. 2135</ref>, known as the Homeland Security Act of 2002, which is classified principally to this chapter. For complete classification of this Act to the Code, see Short Title note set out under <ref href="/us/usc/t6/s101">section 101 of this title</ref> and Tables.</p>
<p style="-uslm-lc:I21" class="indent0">The National Security Act of 1947, referred to in subsec. (d)(11)(B), is <ref href="/us/act/1947-07-26/ch343">act July 26, 1947, ch. 343</ref>, <ref href="/us/stat/61/495">61 Stat. 495</ref>, which was formerly classified principally to chapter 15 (§ 401 et seq.) of Title 50, War and National Defense, prior to editorial reclassification in Title 50, and is now classified principally to chapter 44 (§ 3001 et seq.) of Title 50. For complete classification of this Act to the Code, see Tables.</p>
<p style="-uslm-lc:I21" class="indent0"><ref href="/us/usc/t6/s195f">Section 195f of this title</ref>, referred to in subsec. (d)(26)(B)(i), was in the original “section 319”, meaning <ref href="/us/pl/107/296/s319">section 319 of Pub. L. 107–296</ref>, the Homeland Security Act of 2002, and has been translated as meaning the section 319 of the Act as added by <ref href="/us/pl/114/328/s1913/a/3">section 1913(a)(3) of Pub. L. 114–328</ref> and relating to EMP and GMD mitigation research and development, and not the section 319 of the Act as added by <ref href="/us/pl/114/328/s1906/a">section 1906(a) of Pub. L. 114–328</ref>, to reflect the probable intent of Congress.</p>
</note>
<note style="-uslm-lc:I76" topic="codification" id="idf77b713b-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Codification</heading>
<p style="-uslm-lc:I21" class="indent0">Section is comprised of <ref href="/us/pl/107/296/s201">section 201 of Pub. L. 107–296</ref>. Subsec. (h) of <ref href="/us/pl/107/296/s201">section 201 of Pub. L. 107–296</ref> amended <ref href="/us/usc/t50/s3003">section 3003 of Title 50</ref>, War and National Defense.</p>
</note>
<note style="-uslm-lc:I74" topic="amendments" id="idf77b713c-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Amendments</heading><p style="-uslm-lc:I21" class="indent0">2016—Subsec. (d)(26). <ref href="/us/pl/114/328">Pub. L. 114–328</ref> added par. (26).</p>
<p style="-uslm-lc:I21" class="indent0">2010—Subsec. (d)(3). <ref href="/us/pl/111/258">Pub. L. 111–258</ref> amended par. (3) generally. Prior to amendment, par. (3) read as follows: “To integrate relevant information, analyses, and vulnerability assessments (whether such information, analyses, or assessments are provided or produced by the Department or others) in order to identify priorities for protective and support measures by the Department, other agencies of the Federal Government, State and local government agencies and authorities, the private sector, and other entities.”</p>
<p style="-uslm-lc:I21" class="indent0">2009—Subsec. (f)(2)(E). <ref href="/us/pl/111/84">Pub. L. 111–84</ref> made technical amendment to directory language of <ref href="/us/pl/110/417">Pub. L. 110–417</ref>. See 2008 amendment note below.</p>
<p style="-uslm-lc:I21" class="indent0">2008—Subsec. (f)(2)(E). <ref href="/us/pl/110/417">Pub. L. 110–417</ref>, § 931(b)(5), as amended by <ref href="/us/pl/111/84">Pub. L. 111–84</ref>, substituted “National Geospatial-Intelligence Agency” for “National Imagery and Mapping Agency”.</p>
<p style="-uslm-lc:I21" class="indent0">2007—<ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(1), substituted “Information and” for “Directorate for Information” in section catchline.</p>
<p style="-uslm-lc:I21" class="indent0">Subsecs. (a) to (c). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(2), added subsecs. (a) to (c) and struck out former subsecs. (a) to (c) which related to, in subsec. (a), establishment and responsibilities of Directorate for Information Analysis and Infrastructure Protection, in subsec. (b), positions of Assistant Secretary for Information Analysis and Assistant Secretary for Infrastructure Protection, and, in subsec. (c), Secretary’s duty to ensure that responsibilities regarding information analysis and infrastructure protection would be carried out through the Under Secretary for Information Analysis and Infrastructure Protection.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(3), substituted “Secretary relating to intelligence and analysis and infrastructure protection” for “Under Secretary” in heading and “The responsibilities of the Secretary relating to intelligence and analysis and infrastructure protection” for “Subject to the direction and control of the Secretary, the responsibilities of the Under Secretary for Information Analysis and Infrastructure Protection” in introductory provisions.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(1). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 501(b)(1), inserted “, in support of the mission responsibilities of the Department and the functions of the National Counterterrorism Center established under section 119 of the National Security Act of 1947 (<ref href="/us/usc/t50/s404">50 U.S.C. 404</ref><i>o</i>),” after “to integrate such information” in introductory provisions.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(7). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 501(b)(2), added par. (7) and struck out former par. (7) which read as follows: “To review, analyze, and make recommendations for improvements in the policies and procedures governing the sharing of law enforcement information, intelligence information, intelligence-related information, and other information relating to homeland security within the Federal Government and between the Federal Government and State and local government agencies and authorities.”</p>
<p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 501(a)(2)(A), redesignated par. (8) as (7) and struck out former par. (7) which read as follows: “To administer the Homeland Security Advisory System, including—</p>
<p style="-uslm-lc:I22" class="indent1">“(A) exercising primary responsibility for public advisories related to threats to homeland security; and</p>
<p style="-uslm-lc:I22" class="indent1">“(B) in coordination with other agencies of the Federal Government, providing specific warning information, and advice about appropriate protective measures and countermeasures, to State and local government agencies and authorities, the private sector, other entities, and the public.”</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(8). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 501(a)(2)(A)(ii), redesignated par. (9) as (8). Former par. (8) redesignated (7).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(9). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(3)(C), substituted “Director of National Intelligence” for “Director of Central Intelligence”.</p>
<p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 501(a)(2)(A)(ii), redesignated par. (10) as (9). Former par. (9) redesignated (8).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(10). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 501(a)(2)(A)(ii), redesignated par. (11) as (10). Former par. (10) redesignated (9).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(11). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 501(a)(2)(A)(ii), redesignated par. (12) as (11). Former par. (11) redesignated (10).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(11)(B). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(3)(D), substituted “Director of National Intelligence” for “Director of Central Intelligence”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(12) to (17). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 501(a)(2)(A)(ii), redesignated pars. (13) to (18) as (12) to (17), respectively. Former par. (12) redesignated (11).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(18). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(3)(E), (F), added par. (18) and redesignated former par. (18) as (24).</p>
<p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 501(a)(2)(A)(ii), redesignated par. (19) as (18). Former par. (18) redesignated (17).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(19). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(3)(F), added par. (19).</p>
<p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 501(a)(2)(A)(ii), redesignated par. (19) as (18).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(20) to (23). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(3)(F), added pars. (20) to (23).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(24). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(3)(E), redesignated par. (18) as (24).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(25). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 1002(a), added par. (25).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (e)(1). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(4), substituted “provide the Office of Intelligence and Analysis and the Office of Infrastructure Protection” for “provide the Directorate” and “assist such offices in discharging” for “assist the Directorate in discharging”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (f)(1). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(5), substituted “Office of Intelligence and Analysis and the Office of Infrastructure Protection” for “Directorate”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (g). <ref href="/us/pl/110/53">Pub. L. 110–53</ref>, § 531(a)(6), substituted “Office of Intelligence and Analysis and the Office of Infrastructure Protection” for “Under Secretary for Information Analysis and Infrastructure Protection” in introductory provisions.</p>
</note>
<note style="-uslm-lc:I74" topic="effectiveDateOfAmendment" id="idf77b984d-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Effective Date of 2009 Amendment</heading><p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/111/84/dA/tX">Pub. L. 111–84, div. A, title X</ref>, § 1073(c), <date date="2009-10-28">Oct. 28, 2009</date>, <ref href="/us/stat/123/2474">123 Stat. 2474</ref>, provided that the amendment by section 1073(c)(9) is effective as of <date date="2008-10-14">Oct. 14, 2008</date>, and as if included in <ref href="/us/pl/110/417">Pub. L. 110–417</ref> as enacted.</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idf77b984e-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Regulations</heading><p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/109/295/tV">Pub. L. 109–295, title V</ref>, § 550, <date date="2006-10-04">Oct. 4, 2006</date>, <ref href="/us/stat/120/1388">120 Stat. 1388</ref>, as amended by <ref href="/us/pl/110/161/dE/tV">Pub. L. 110–161, div. E, title V</ref>, § 534, <date date="2007-12-26">Dec. 26, 2007</date>, <ref href="/us/stat/121/2075">121 Stat. 2075</ref>; <ref href="/us/pl/111/83/tV">Pub. L. 111–83, title V</ref>, § 550, <date date="2009-10-28">Oct. 28, 2009</date>, <ref href="/us/stat/123/2177">123 Stat. 2177</ref>; <ref href="/us/pl/112/10/dB/tVI">Pub. L. 112–10, div. B, title VI</ref>, § 1650, <date date="2011-04-15">Apr. 15, 2011</date>, <ref href="/us/stat/125/146">125 Stat. 146</ref>; <ref href="/us/pl/112/74/dD/tV">Pub. L. 112–74, div. D, title V</ref>, § 540, <date date="2011-12-23">Dec. 23, 2011</date>, <ref href="/us/stat/125/976">125 Stat. 976</ref>; <ref href="/us/pl/113/6/dD/tV">Pub. L. 113–6, div. D, title V</ref>, § 537, <date date="2013-03-26">Mar. 26, 2013</date>, <ref href="/us/stat/127/373">127 Stat. 373</ref>; <ref href="/us/pl/113/76/dF/tV">Pub. L. 113–76, div. F, title V</ref>, § 536, <date date="2014-01-17">Jan. 17, 2014</date>, <ref href="/us/stat/128/275">128 Stat. 275</ref>, required interim final regulations establishing risk-based performance standards for security of chemical facilities and requiring vulnerability assessments and the development and implementation of site security plans for chemical facilities, prior to repeal by <ref href="/us/pl/113/254">Pub. L. 113–254</ref>, § 4(b), <date date="2014-12-18">Dec. 18, 2014</date>, <ref href="/us/stat/128/2919">128 Stat. 2919</ref>. See <ref href="/us/usc/t6/s627">section 627 of this title</ref>.</p>
<p style="-uslm-lc:I21" class="indent0">[<ref href="/us/pl/113/254">Pub. L. 113–254</ref>, § 4(b), <date date="2014-12-18">Dec. 18, 2014</date>, <ref href="/us/stat/128/2919">128 Stat. 2919</ref>, provided that the repeal of <ref href="/us/pl/109/295/s550">section 550 of Pub. L. 109–295</ref>, formerly set out above, is effective as of the effective date of <ref href="/us/pl/113/254">Pub. L. 113–254</ref>, which is the date that is 30 days after <date date="2014-12-18">Dec. 18, 2014</date>. See <ref href="/us/pl/113/254/s4/a">section 4(a) of Pub. L. 113–254</ref>, set out as an Effective and Termination Dates note under <ref href="/us/usc/t6/s621">section 621 of this title</ref>.]</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idf77bbf5f-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Deadline for Initial Recommended Strategy</heading><p><ref href="/us/pl/114/328/dA/tXIX">Pub. L. 114–328, div. A, title XIX</ref>, § 1913(c), <date date="2016-12-23">Dec. 23, 2016</date>, <ref href="/us/stat/130/2687">130 Stat. 2687</ref>, provided that: <quotedContent origin="/us/pl/114/328/dA/tXIX">“Not later than one year after the date of the enactment of this section [<date date="2016-12-23">Dec. 23, 2016</date>], the Secretary of Homeland Security shall submit the recommended strategy required under paragraph (26) of section 201(d) of the Homeland Security Act of 2002 (<ref href="/us/usc/t6/s121/d">6 U.S.C. 121(d)</ref>), as added by this section.”</quotedContent>
</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idf77bbf60-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Enhanced Grid Security</heading><p><ref href="/us/pl/114/94/dF">Pub. L. 114–94, div. F</ref>, § 61003(c), <date date="2015-12-04">Dec. 4, 2015</date>, <ref href="/us/stat/129/1778">129 Stat. 1778</ref>, provided that:<quotedContent origin="/us/pl/114/94/dF">
<paragraph style="-uslm-lc:I21" class="indent0"><num value="1">“(1)</num><heading> <inline class="small-caps">Definitions</inline>.—</heading><chapeau>In this subsection:</chapeau><subparagraph style="-uslm-lc:I22" class="indent1"><num value="A">“(A)</num><heading> <inline class="small-caps">Critical electric infrastructure; critical electric infrastructure information</inline>.—</heading><content>The terms ‘critical electric infrastructure’ and ‘critical electric infrastructure information’ have the meanings given those terms in section 215A of the Federal Power Act [<ref href="/us/usc/t16/s824">16 U.S.C. 824</ref><i>o</i>–1].</content>
</subparagraph>
<subparagraph style="-uslm-lc:I22" class="indent1"><num value="B">“(B)</num><heading> <inline class="small-caps">Sector-specific agency</inline>.—</heading><content>The term ‘Sector-Specific Agency’ has the meaning given that term in the Presidential Policy Directive entitled ‘Critical Infrastructure Security and Resilience’, numbered 21, and dated <date date="2013-02-12">February 12, 2013</date>.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I21" class="indent0"><num value="2">“(2)</num><heading> Sector-specific agency for cybersecurity for the energy sector.—</heading><subparagraph style="-uslm-lc:I22" class="indent1"><num value="A">“(A)</num><heading> <inline class="small-caps">In general</inline>.—</heading><content>The Department of Energy shall be the lead Sector-Specific Agency for cybersecurity for the energy sector.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I22" class="indent1"><num value="B">“(B)</num><heading> <inline class="small-caps">Duties</inline>.—</heading><chapeau>As head of the designated Sector-Specific Agency for cybersecurity, the duties of the Secretary of Energy shall include—</chapeau><clause style="-uslm-lc:I23" class="indent2"><num value="i">“(i)</num><content> coordinating with the Department of Homeland Security and other relevant Federal departments and agencies;</content>
</clause>
<clause style="-uslm-lc:I23" class="indent2"><num value="ii">“(ii)</num><chapeau> collaborating with—</chapeau><subclause style="-uslm-lc:I24" class="indent3"><num value="I">“(I)</num><content> critical electric infrastructure owners and operators; and</content>
</subclause>
<subclause style="-uslm-lc:I24" class="indent3"><num value="II">“(II)</num><chapeau> as appropriate—</chapeau><item style="-uslm-lc:I36" class="indent4 firstIndent-4"><num value="aa">     “(aa)</num><content> independent regulatory agencies; and</content>
</item>
<item style="-uslm-lc:I36" class="indent4 firstIndent-4"><num value="bb">     “(bb)</num><content> State, local, tribal, and territorial entities;</content>
</item>
<item style="-uslm-lc:I36" class="indent4 firstIndent-4"><num value="cc">     “(cc)</num><content> serving as a day-to-day Federal interface for the dynamic prioritization and coordination of sector-specific activities;</content>
</item>
<item style="-uslm-lc:I36" class="indent4 firstIndent-4"><num value="dd">     “(dd)</num><content> carrying out incident management responsibilities consistent with applicable law (including regulations) and other appropriate policies or directives;</content>
</item>
<item style="-uslm-lc:I36" class="indent4 firstIndent-4"><num value="ee">     “(ee)</num><content> providing, supporting, or facilitating technical assistance and consultations for the energy sector to identify vulnerabilities and help mitigate incidents, as appropriate; and</content>
</item>
<item style="-uslm-lc:I36" class="indent4 firstIndent-4"><num value="ff">     “(ff)</num><content> supporting the reporting requirements of the Department of Homeland Security under applicable law by providing, on an annual basis, sector-specific critical electric infrastructure information.”</content>
</item>
</subclause>
</clause>
</subparagraph>
</paragraph>
</quotedContent>
</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idf77be671-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Cybersecurity Collaboration Between the Department of Defense and the Department of Homeland Security</heading><p><ref href="/us/pl/112/81/dA/tX">Pub. L. 112–81, div. A, title X</ref>, § 1090, <date date="2011-12-31">Dec. 31, 2011</date>, <ref href="/us/stat/125/1603">125 Stat. 1603</ref>, provided that:<quotedContent origin="/us/pl/112/81/dA/tX">
<subsection style="-uslm-lc:I21" class="indent0"><num value="a">“(a)</num><heading> Interdepartmental Collaboration.—</heading><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">In general</inline>.—</heading><chapeau>The Secretary of Defense and the Secretary of Homeland Security shall provide personnel, equipment, and facilities in order to increase interdepartmental collaboration with respect to—</chapeau><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><content> strategic planning for the cybersecurity of the United States;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><content> mutual support for cybersecurity capabilities development; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="C">“(C)</num><content> synchronization of current operational cybersecurity mission activities.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">Efficiencies</inline>.—</heading><chapeau>The collaboration provided for under paragraph (1) shall be designed—</chapeau><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><content> to improve the efficiency and effectiveness of requirements formulation and requests for products, services, and technical assistance for, and coordination and performance assessment of, cybersecurity missions executed across a variety of Department of Defense and Department of Homeland Security elements; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><content> to leverage the expertise of each individual Department and to avoid duplicating, replicating, or aggregating unnecessarily the diverse line organizations across technology developments, operations, and customer support that collectively execute the cybersecurity mission of each Department.</content>
</subparagraph>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="b">“(b)</num><heading> Responsibilities.—</heading><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">Department of homeland security</inline>.—</heading><content>The Secretary of Homeland Security shall identify and assign, in coordination with the Department of Defense, a Director of Cybersecurity Coordination within the Department of Homeland Security to undertake collaborative activities with the Department of Defense.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">Department of defense</inline>.—</heading><content>The Secretary of Defense shall identify and assign, in coordination with the Department of Homeland Security, one or more officials within the Department of Defense to coordinate, oversee, and execute collaborative activities and the provision of cybersecurity support to the Department of Homeland Security.”</content>
</paragraph>
</subsection>
</quotedContent>
</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idf77be672-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Cybersecurity Oversight</heading><p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/111/259/tIII">Pub. L. 111–259, title III</ref>, § 336, <date date="2010-10-07">Oct. 7, 2010</date>, <ref href="/us/stat/124/2689">124 Stat. 2689</ref>, which related to cybersecurity oversight and provided for notification of cybersecurity programs, program and information sharing reports, provisions for the detailing of personnel, and provisions for further planning to recruit, retain, and train a highly-qualified workforce to secure the networks of the intelligence community, terminated on <date date="2013-12-31">Dec. 31, 2013</date>.</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idf77c0d83-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Treatment of Incumbent Under Secretary for Intelligence and Analysis</heading><p><ref href="/us/pl/110/53/tV">Pub. L. 110–53, title V</ref>, § 531(c), <date date="2007-08-03">Aug. 3, 2007</date>, <ref href="/us/stat/121/335">121 Stat. 335</ref>, provided that: <quotedContent origin="/us/pl/110/53/tV">“The individual administratively performing the duties of the Under Secretary for Intelligence and Analysis as of the date of the enactment of this Act [<date date="2007-08-03">Aug. 3, 2007</date>] may continue to perform such duties after the date on which the President nominates an individual to serve as the Under Secretary pursuant to section 201 of the Homeland Security Act of 2002 [<ref href="/us/usc/t6/s121">6 U.S.C. 121</ref>], as amended by this section, and until the individual so appointed assumes the duties of the position.”</quotedContent>
</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idf77c0d84-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Reports To Be Submitted to Certain Committees</heading><p><ref href="/us/pl/110/53/tXXIV">Pub. L. 110–53, title XXIV</ref>, § 2403, <date date="2007-08-03">Aug. 3, 2007</date>, <ref href="/us/stat/121/547">121 Stat. 547</ref>, provided that: <quotedContent origin="/us/pl/110/53/tXXIV">
<inline>“The Committee on Commerce, Science, and Transportation of the Senate shall receive the reports required by the following provisions of law in the same manner and to the same extent that the reports are to be received by the Committee on Homeland Security and Governmental Affairs of the Senate:</inline>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> Section 1016(j)(1) of the Intelligence Reform and Terrorist [Terrorism] Prevention Act of 2004 (<ref href="/us/usc/t6/s485/j/1">6 U.S.C. 485(j)(1)</ref>).</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> Section 511(d) of this Act [<ref href="/us/stat/121/323">121 Stat. 323</ref>].</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><content> [Former] [s]ubsection (a)(3)(D) of section 2022 of the Homeland Security Act of 2002 [former <ref href="/us/usc/t6/s612/a/3/D">6 U.S.C. 612(a)(3)(D)</ref>], as added by section 101 of this Act.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="4">“(4)</num><content> Section 7215(d) of the Intelligence Reform and Terrorism Prevention Act of 2004 (<ref href="/us/usc/t6/s123/d">6 U.S.C. 123(d)</ref>).</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="5">“(5)</num><content> Section 7209(b)(1)(C) of the Intelligence Reform and Terrorism Prevention Act of 2004 [<ref href="/us/pl/108/458">Pub. L. 108–458</ref>] (<ref href="/us/usc/t8/s1185">8 U.S.C. 1185</ref> note).</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="6">“(6)</num><content> Section 804(c) of this Act [<ref href="/us/usc/t42/s2000ee–3/c">42 U.S.C. 2000ee–3(c)</ref>].</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="7">“(7)</num><content> Section 901(b) of this Act [<ref href="/us/stat/121/370">121 Stat. 370</ref>].</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="8">“(8)</num><content> Section 1002(a) of this Act [amending this section].</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="9">“(9)</num><content> Title III of this Act [enacting sections 579 and 580 of this title and amending sections 194 and 572 of this title].”</content>
</paragraph>
</quotedContent>
</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idf77c0d85-4154-11e7-bab8-e125cf475dd2"><heading class="centered smallCaps">Security Management Systems Demonstration Project</heading><p><ref href="/us/pl/110/53/tXXIV">Pub. L. 110–53, title XXIV</ref>, § 2404, <date date="2007-08-03">Aug. 3, 2007</date>, <ref href="/us/stat/121/548">121 Stat. 548</ref>, provided that:<quotedContent origin="/us/pl/110/53/tXXIV">
<subsection style="-uslm-lc:I21" class="indent0"><num value="a">“(a)</num><heading> <inline class="small-caps">Demonstration Project Required</inline>.—</heading><chapeau>Not later than 120 days after the date of enactment of this Act [<date date="2007-08-03">Aug. 3, 2007</date>], the Secretary of Homeland Security shall—</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><chapeau> establish a demonstration project to conduct demonstrations of security management systems that—</chapeau><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><content> shall use a management system standards approach; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><content> may be integrated into quality, safety, environmental and other internationally adopted management systems; and</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> enter into one or more agreements with a private sector entity to conduct such demonstrations of security management systems.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="b">“(b)</num><heading> <inline class="small-caps">Security Management System Defined</inline>.—</heading><content>In this section, the term ‘security management system’ means a set of guidelines that address the security assessment needs of critical infrastructure and key resources that are consistent with a set of generally accepted management standards ratified and adopted by a standards making body.”</content>
</subsection>
</quotedContent>
</p>
</note>
<note style="-uslm-lc:I86" topic="executiveOrder" id="idf77c3496-4154-11e7-bab8-e125cf475dd2">
<heading class="centered smallCaps">Ex. Ord. No. 13231. Critical Infrastructure Protection in the Information Age</heading>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13231, <date date="2001-10-16">Oct. 16, 2001</date>, 66 F.R. 53063, as amended by Ex. Ord. No. 13284, § 2, <date date="2003-01-23">Jan. 23, 2003</date>, 68 F.R. 4075; Ex. Ord. No. 13286, § 7, <date date="2003-02-28">Feb. 28, 2003</date>, 68 F.R. 10620; Ex. Ord. No. 13385, § 5, <date date="2005-09-29">Sept. 29, 2005</date>, 70 F.R. 57990; Ex. Ord. No. 13652, § 6, <date date="2013-09-30">Sept. 30, 2013</date>, 78 F.R. 61818, provided:</p>
<p style="-uslm-lc:I21" class="indent0">By the authority vested in me as President by the Constitution and the laws of the United States of America, and in order to ensure protection of information systems for critical infrastructure, including emergency preparedness communications and the physical assets that support such systems, in the information age, it is hereby ordered as follows:</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Section</inline> 1. <i>Policy</i>. The information technology revolution has changed the way business is transacted, government operates, and national defense is conducted. Those three functions now depend on an interdependent network of critical information infrastructures. It is the policy of the United States to protect against disruption of the operation of information systems for critical infrastructure and thereby help to protect the people, economy, essential human and government services, and national security of the United States, and to ensure that any disruptions that occur are infrequent, of minimal duration, and manageable, and cause the least damage possible. The implementation of this policy shall include a voluntary public-private partnership, involving corporate and nongovernmental organizations.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 2. <i>Continuing Authorities</i>. This order does not alter the existing authorities or roles of United States Government departments and agencies. Authorities set forth in 44 U.S.C. chapter 35, and other applicable law, provide senior officials with responsibility for the security of Federal Government information systems.</p>
<p style="-uslm-lc:I21" class="indent0">(a) Executive Branch Information Systems Security. The Director of the Office of Management and Budget (OMB) has the responsibility to develop and oversee the implementation of government-wide policies, principles, standards, and guidelines for the security of information systems that support the executive branch departments and agencies, except those noted in section 2(b) of this order. The Director of OMB shall advise the President and the appropriate department or agency head when there is a critical deficiency in the security practices within the purview of this section in an executive branch department or agency.</p>
<p style="-uslm-lc:I21" class="indent0">(b) National Security Information Systems. The Secretary of Defense and the Director of Central Intelligence (DCI) shall have responsibility to oversee, develop, and ensure implementation of policies, principles, standards, and guidelines for the security of information systems that support the operations under their respective control. In consultation with the Assistant to the President for National Security Affairs and the affected departments and agencies, the Secretary of Defense and the DCI shall develop policies, principles, standards, and guidelines for the security of national security information systems that support the operations of other executive branch departments and agencies with national security information.</p>
<p style="-uslm-lc:I22" class="indent1">(i) Policies, principles, standards, and guidelines developed under this subsection may require more stringent protection than those developed in accordance with section 2(a) of this order.</p>
<p style="-uslm-lc:I22" class="indent1">(ii) The Assistant to the President for National Security Affairs shall advise the President and the appropriate department or agency when there is a critical deficiency in the security practices of a department or agency within the purview of this section.</p>
<p style="-uslm-lc:I22" class="indent1">(iii) National Security Systems. The National Security Telecommunications and Information Systems Security Committee, as established by and consistent with NSD–42 and chaired by the Department of Defense, shall be designated as the “Committee on National Security Systems.”</p>
<p style="-uslm-lc:I21" class="indent0">(c) Additional Responsibilities. The heads of executive branch departments and agencies are responsible and accountable for providing and maintaining adequate levels of security for information systems, including emergency preparedness communications systems, for programs under their control. Heads of such departments and agencies shall ensure the development and, within available appropriations, funding of programs that adequately address these mission systems, especially those critical systems that support the national security and other essential government programs. Additionally, security should enable, and not unnecessarily impede, department and agency business operations.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 3. <i>The National Infrastructure Advisory Council</i>. The National Infrastructure Advisory Council (NIAC), established on <date date="2001-10-16">October 16, 2001</date>, shall provide the President, through the Secretary of Homeland Security, with advice on the security and resilience of the critical infrastructure sectors and their functional systems, physical assets, and cyber networks.</p>
<p style="-uslm-lc:I21" class="indent0">(a) <i>Membership</i>. The NIAC shall be composed of not more than 30 members appointed by the President, taking appropriate account of the benefits of having members:</p>
<p style="-uslm-lc:I21" class="indent0">(i) from the private sector, including individuals with experience in banking and finance, transportation, energy, water, communications, health care services, food and agriculture, government facilities, emergency services organizations, institutions of higher education, environmental and climate resilience, and State, local, and tribal governments;</p>
<p style="-uslm-lc:I21" class="indent0">(ii) with senior executive leadership responsibilities for the availability and reliability, including security and resilience, of critical infrastructure sectors;</p>
<p style="-uslm-lc:I21" class="indent0">(iii) with expertise relevant to the functions of the NIAC; and</p>
<p style="-uslm-lc:I21" class="indent0">(iv) with experience equivalent to that of a chief executive of an organization.</p>
<p style="-uslm-lc:I21" class="indent0">Unless otherwise determined by the President, no full-time officer or employee of the executive branch shall be appointed to serve as a member of the NIAC. The President shall designate from among the members of the NIAC a Chair and a Vice Chair, who shall perform the functions of the Chair if the Chair is absent or disabled, or in the instance of a vacancy in the Chair.</p>
<p style="-uslm-lc:I21" class="indent0">(b) <i>Functions of the NIAC</i>. The NIAC shall meet periodically to:</p>
<p style="-uslm-lc:I21" class="indent0">(i) enhance the partnership of the public and private sectors in securing and enhancing the security and resilience of critical infrastructure and their supporting functional systems, physical assets, and cyber networks, and provide reports on this issue to the President, through the Secretary of Homeland Security, as appropriate;</p>
<p style="-uslm-lc:I21" class="indent0">(ii) propose and develop ways to encourage private industry to perform periodic risk assessments and implement risk-reduction programs;</p>
<p style="-uslm-lc:I21" class="indent0">(iii) monitor the development and operations of critical infrastructure sector coordinating councils and their information-sharing mechanisms and provide recommendations to the President, through the Secretary of Homeland Security, on how these organizations can best foster improved cooperation among the sectors, the Department of Homeland Security, and other Federal Government entities;</p>
<p style="-uslm-lc:I21" class="indent0">(iv) report to the President through the Secretary of Homeland Security, who shall ensure appropriate coordination with the Assistant to the President for Homeland Security and Counterterrorism, the Assistant to the President for Economic Policy, and the Assistant to the President for National Security Affairs under the terms of this order; and</p>
<p style="-uslm-lc:I21" class="indent0">(v) advise sector-specific agencies with critical infrastructure responsibilities to include issues pertaining to sector and government coordinating councils and their information sharing mechanisms.</p>
<p style="-uslm-lc:I21" class="indent0">In implementing this order, the NIAC shall not advise or otherwise act on matters pertaining to National Security and Emergency Preparedness (NS/EP) Communications and, with respect to any matters to which the NIAC is authorized by this order to provide advice or otherwise act on that may depend on or affect NS/EP Communications, shall coordinate with the National Security and Telecommunications Advisory Committee established by Executive Order 12382 of <date date="1982-09-13">September 13, 1982</date>, as amended.</p>
<p style="-uslm-lc:I21" class="indent0">(c) Administration of the NIAC.</p>
<p style="-uslm-lc:I22" class="indent1">(i) The NIAC may hold hearings, conduct inquiries, and establish subcommittees, as appropriate.</p>
<p style="-uslm-lc:I22" class="indent1">(ii) Upon request of the Chair, and to the extent permitted by law, the heads of the executive departments and agencies shall provide the NIAC with information and advice relating to its functions.</p>
<p style="-uslm-lc:I22" class="indent1">(iii) Senior Federal Government officials may participate in the meetings of the NIAC, as appropriate.</p>
<p style="-uslm-lc:I22" class="indent1">(iv) Members shall serve without compensation for their work on the NIAC. However, members may be reimbursed for travel expenses, including per diem in lieu of subsistence, as authorized by law for persons serving intermittently in Federal Government service (<ref href="/us/usc/t5/s5701–570">5 U.S.C. 5701–570</ref>7).</p>
<p style="-uslm-lc:I22" class="indent1">(v) To the extent permitted by law and subject to the availability of appropriations, the Department of Homeland Security shall provide the NIAC with administrative services, staff, and other support services, and such funds as may be necessary for the performance of the NIAC’s functions.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 4. <i>Judicial Review</i>. This order does not create any right or benefit, substantive or procedural, enforceable at law or in equity, against the United States, its departments, agencies, or other entities, its officers or employees, or any other person.</p>
</note>
<note style="-uslm-lc:I86" topic="miscellaneous" id="idf77c82b7-4154-11e7-bab8-e125cf475dd2">
<heading class="centered smallCaps">Extension of Term of National Infrastructure Advisory Council</heading>
<p style="-uslm-lc:I21" class="indent0">Term of National Infrastructure Advisory Council extended until <date date="2017-09-30">Sept. 30, 2017</date>, by Ex. Ord. No. 13708, <date date="2015-09-30">Sept. 30, 2015</date>, 80 F.R. 60271, set out as a note under section 14 of the Federal Advisory Committee Act in the Appendix to Title 5, Government Organization and Employees.</p>
<p style="-uslm-lc:I21" class="indent0">Previous extensions of term of National Infrastructure Advisory Council were contained in the following prior Executive Orders:</p>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13652, <date date="2013-09-30">Sept. 30, 2013</date>, 78 F.R. 61817, extended term until <date date="2015-09-30">Sept. 30, 2015</date>.</p>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13585, <date date="2011-09-30">Sept. 30, 2011</date>, 76 F.R. 62281, extended term until <date date="2013-09-30">Sept. 30, 2013</date>.</p>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13511, <date date="2009-09-29">Sept. 29, 2009</date>, 74 F.R. 50909, extended term until <date date="2011-09-30">Sept. 30, 2011</date>.</p>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13446, <date date="2007-09-28">Sept. 28, 2007</date>, 72 F.R. 56175, extended term until <date date="2009-09-30">Sept. 30, 2009</date>.</p>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13385, <date date="2005-09-29">Sept. 29, 2005</date>, 70 F.R. 57989, extended term until <date date="2007-09-30">Sept. 30, 2007</date>.</p>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13316, <date date="2003-09-17">Sept. 17, 2003</date>, 68 F.R. 55255, extended term until <date date="2005-09-30">Sept. 30, 2005</date>.</p>
</note>
<note style="-uslm-lc:I86" topic="executiveOrder" id="idf77ca9c8-4154-11e7-bab8-e125cf475dd2">
<heading class="centered smallCaps">Ex. Ord. No. 13284. Amendment of Executive Orders, and Other Actions, in Connection With the Establishment of the Department of Homeland Security</heading>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13284, <date date="2003-01-23">Jan. 23, 2003</date>, 68 F.R. 4075, provided:</p>
<p>By the authority vested in me as President by the Constitution and the laws of the United States of America, including the Homeland Security Act of 2002 (<ref href="/us/pl/107/296">Public Law 107–296</ref>) [see Tables for classification], and the National Security Act of 1947, as amended (<ref href="/us/usc/t50/s401">50 U.S.C. 401</ref> <i>et seq</i>.) [now <ref href="/us/usc/t50/s3001">50 U.S.C. 3001</ref> et seq.], and in order to reflect responsibilities vested in the Secretary of Homeland Security and take other actions in connection with the establishment of the Department of Homeland Security, it is hereby ordered as follows:</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Section</inline> 1. [Amended Ex. Ord. No. 13234.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 2. [Amended Ex. Ord. No. 13231, set out above.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 3. Executive Order 13228 of <date date="2001-10-08">October 8, 2001</date> (“Establishing the Office of Homeland Security and the Homeland Security Council”) [<ref href="/us/usc/t50/s3021">50 U.S.C. 3021</ref> note], is amended by inserting “the Secretary of Homeland Security,” after “the Secretary of Transportation,” in section 5(b). Further, during the period from <date date="2003-01-24">January 24, 2003</date>, until <date date="2003-03-01">March 1, 2003</date>, the Secretary of Homeland Security shall have the responsibility for coordinating the domestic response efforts otherwise assigned to the Assistant to the President for Homeland Security pursuant to section 3(g) of Executive Order 13228.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 4. [Amended Ex. Ord. No. 13224, listed in a table under <ref href="/us/usc/t50/s1701">section 1701 of Title 50</ref>, War and National Defense.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 5. [Amended Ex. Ord. No. 13151, set out as a note under <ref href="/us/usc/t42/s5195">section 5195 of Title 42</ref>, The Public Health and Welfare.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 6. [Amended Ex. Ord. No. 13122, set out as a note under <ref href="/us/usc/t42/s3121">section 3121 of Title 42</ref>, The Public Health and Welfare.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 7. [Amended Ex. Ord. No. 13048, set out as a note under <ref href="/us/usc/t31/s501">section 501 of Title 31</ref>, Money and Finance.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 8. [Amended Ex. Ord. No. 12992, set out as a note under <ref href="/us/usc/t21/s1708">section 1708 of Title 21</ref>, Food and Drugs.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 9. [Amended Ex. Ord. No. 12881, set out as a note under <ref href="/us/usc/t42/s6601">section 6601 of Title 42</ref>, The Public Health and Welfare.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 10. [Amended Ex. Ord. No. 12859, set out as a note preceding <ref href="/us/usc/t3/s101">section 101 of Title 3</ref>, The President.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 11. [Amended Ex. Ord. No. 12590, set out as a note under former <ref href="/us/usc/t21/s1201">section 1201 of Title 21</ref>, Food and Drugs.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 12. [Amended Ex. Ord. No. 12260, set out as a note under <ref href="/us/usc/t19/s2511">section 2511 of Title 19</ref>, Customs Duties.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 13. [Amended Ex. Ord. No. 11958, set out as a note under <ref href="/us/usc/t22/s2751">section 2751 of Title 22</ref>, Foreign Relations and Intercourse.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 14. [Amended Ex. Ord. No. 11423, set out as a note under <ref href="/us/usc/t3/s301">section 301 of Title 3</ref>, The President.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 15. [Amended Ex. Ord. No. 10865, set out as a note under <ref href="/us/usc/t50/s3161">section 3161 of Title 50</ref>, War and National Defense.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 16. [Amended Ex. Ord. No. 13011, set out as a note under <ref href="/us/usc/t40/s11101">section 11101 of Title 40</ref>, Public Buildings, Property, and Works.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 17. Those elements of the Department of Homeland Security that are supervised by the Department’s Under Secretary for Information Analysis and Infrastructure Protection through the Department’s Assistant Secretary for Information Analysis, with the exception of those functions that involve no analysis of foreign intelligence information, are designated as elements of the Intelligence Community under section 201(h) of the Homeland Security Act of 2002 [<ref href="/us/pl/107/296">Pub. L. 107–296</ref>, amending <ref href="/us/usc/t50/s3003">50 U.S.C. 3003</ref>] and section 3(4) of the National Security Act of 1947, as amended (<ref href="/us/usc/t50/s401a">50 U.S.C. 401a</ref>[(4)]) [now <ref href="/us/usc/t50/s3003/4">50 U.S.C. 3003(4)</ref>].</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 18. [Amended Ex. Ord. No. 12333, set out as a note under <ref href="/us/usc/t50/s3001">section 3001 of title 50</ref>, War and National Defense.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 19. <i>Functions of Certain Officials in the Department of Homeland Security.</i></p>
<p style="-uslm-lc:I21" class="indent0">The Secretary of Homeland Security, the Deputy Secretary of Homeland Security, the Under Secretary for Information Analysis and Infrastructure Protection, Department of Homeland Security, and the Assistant Secretary for Information Analysis, Department of Homeland Security, each shall be considered a “Senior Official of the Intelligence Community” for purposes of Executive Order 12333 [<ref href="/us/usc/t50/s3001">50 U.S.C. 3001</ref> note], and all other relevant authorities, and shall:</p>
<p style="-uslm-lc:I21" class="indent0">(a) recognize and give effect to all current clearances for access to classified information held by those who become employees of the Department of Homeland Security by operation of law pursuant to the Homeland Security Act of 2002 or by Presidential appointment;</p>
<p style="-uslm-lc:I21" class="indent0">(b) recognize and give effect to all current clearances for access to classified information held by those in the private sector with whom employees of the Department of Homeland Security may seek to interact in the discharge of their homeland security-related responsibilities;</p>
<p style="-uslm-lc:I21" class="indent0">(c) make all clearance and access determinations pursuant to Executive Order 12968 of <date date="1995-08-02">August 2, 1995</date> [<ref href="/us/usc/t50/s3161">50 U.S.C. 3161</ref> note], or any successor Executive Order, as to employees of, and applicants for employment in, the Department of Homeland Security who do not then hold a current clearance for access to classified information; and</p>
<p style="-uslm-lc:I21" class="indent0">(d) ensure all clearance and access determinations for those in the private sector with whom employees of the Department of Homeland Security may seek to interact in the discharge of their homeland security-related responsibilities are made in accordance with Executive Order 12829 of <date date="1993-01-06">January 6, 1993</date> [<ref href="/us/usc/t50/s3161">50 U.S.C. 3161</ref> note].</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 20. Pursuant to the provisions of section 1.4 of [former] Executive Order 12958 of <date date="1995-04-17">April 17, 1995</date> (“Classified National Security Information”), I hereby authorize the Secretary of Homeland Security to classify information originally as “Top Secret.” Any delegation of this authority shall be in accordance with section 1.4 of that order or any successor Executive Orders.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 21. This order shall become effective on <date date="2003-01-24">January 24, 2003</date>.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 22. This order does not create any right or benefit, substantive or procedural, enforceable at law or equity, against the United States, its departments, agencies, or other entities, its officers or employees, or any other person.</p>
<signature>
<name>George W. Bush.</name>
</signature>
</note>
<note style="-uslm-lc:I86" topic="executiveOrder" id="idf77cf7e9-4154-11e7-bab8-e125cf475dd2">
<heading class="centered smallCaps">Ex. Ord. No. 13636. Improving Critical Infrastructure Cybersecurity</heading>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13636, <date date="2013-02-12">Feb. 12, 2013</date>, 78 F.R. 11739, provided:</p>
<p style="-uslm-lc:I21" class="indent0">By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered as follows:</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Section</inline> 1. <i>Policy</i>. Repeated cyber intrusions into critical infrastructure demonstrate the need for improved cybersecurity. The cyber threat to critical infrastructure continues to grow and represents one of the most serious national security challenges we must confront. The national and economic security of the United States depends on the reliable functioning of the Nation’s critical infrastructure in the face of such threats. It is the policy of the United States to enhance the security and resilience of the Nation’s critical infrastructure and to maintain a cyber environment that encourages efficiency, innovation, and economic prosperity while promoting safety, security, business confidentiality, privacy, and civil liberties. We can achieve these goals through a partnership with the owners and operators of critical infrastructure to improve cybersecurity information sharing and collaboratively develop and implement risk-based standards.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 2. <i>Critical Infrastructure</i>. As used in this order, the term critical infrastructure means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 3. <i>Policy Coordination</i>. Policy coordination, guidance, dispute resolution, and periodic in-progress reviews for the functions and programs described and assigned herein shall be provided through the interagency process established in Presidential Policy Directive–1 of <date date="2009-02-13">February 13, 2009</date> (Organization of the National Security Council System), or any successor.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 4. <i>Cybersecurity Information Sharing</i>. (a) It is the policy of the United States Government to increase the volume, timeliness, and quality of cyber threat information shared with U.S. private sector entities so that these entities may better protect and defend themselves against cyber threats. Within 120 days of the date of this order, the Attorney General, the Secretary of Homeland Security (the “Secretary”), and the Director of National Intelligence shall each issue instructions consistent with their authorities and with the requirements of section 12(c) of this order to ensure the timely production of unclassified reports of cyber threats to the U.S. homeland that identify a specific targeted entity. The instructions shall address the need to protect intelligence and law enforcement sources, methods, operations, and investigations.</p>
<p style="-uslm-lc:I21" class="indent0">(b) The Secretary and the Attorney General, in coordination with the Director of National Intelligence, shall establish a process that rapidly disseminates the reports produced pursuant to section 4(a) of this order to the targeted entity. Such process shall also, consistent with the need to protect national security information, include the dissemination of classified reports to critical infrastructure entities authorized to receive them. The Secretary and the Attorney General, in coordination with the Director of National Intelligence, shall establish a system for tracking the production, dissemination, and disposition of these reports.</p>
<p style="-uslm-lc:I21" class="indent0">(c) To assist the owners and operators of critical infrastructure in protecting their systems from unauthorized access, exploitation, or harm, the Secretary, consistent with <ref href="/us/usc/t6/s143">6 U.S.C. 143</ref> and in collaboration with the Secretary of Defense, shall, within 120 days of the date of this order, establish procedures to expand the Enhanced Cybersecurity Services program to all critical infrastructure sectors. This voluntary information sharing program will provide classified cyber threat and technical information from the Government to eligible critical infrastructure companies or commercial service providers that offer security services to critical infrastructure.</p>
<p style="-uslm-lc:I21" class="indent0">(d) The Secretary, as the Executive Agent for the Classified National Security Information Program created under Executive Order 13549 of <date date="2010-08-18">August 18, 2010</date> (Classified National Security Information Program for State, Local, Tribal, and Private Sector Entities), shall expedite the processing of security clearances to appropriate personnel employed by critical infrastructure owners and operators, prioritizing the critical infrastructure identified in section 9 of this order.</p>
<p style="-uslm-lc:I21" class="indent0">(e) In order to maximize the utility of cyber threat information sharing with the private sector, the Secretary shall expand the use of programs that bring private sector subject-matter experts into Federal service on a temporary basis. These subject matter experts should provide advice regarding the content, structure, and types of information most useful to critical infrastructure owners and operators in reducing and mitigating cyber risks.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 5. <i>Privacy and Civil Liberties Protections</i>. (a) Agencies shall coordinate their activities under this order with their senior agency officials for privacy and civil liberties and ensure that privacy and civil liberties protections are incorporated into such activities. Such protections shall be based upon the Fair Information Practice Principles and other privacy and civil liberties policies, principles, and frameworks as they apply to each agency’s activities.</p>
<p style="-uslm-lc:I21" class="indent0">(b) The Chief Privacy Officer and the Officer for Civil Rights and Civil Liberties of the Department of Homeland Security (DHS) shall assess the privacy and civil liberties risks of the functions and programs undertaken by DHS as called for in this order and shall recommend to the Secretary ways to minimize or mitigate such risks, in a publicly available report, to be released within 1 year of the date of this order. Senior agency privacy and civil liberties officials for other agencies engaged in activities under this order shall conduct assessments of their agency activities and provide those assessments to DHS for consideration and inclusion in the report. The report shall be reviewed on an annual basis and revised as necessary. The report may contain a classified annex if necessary. Assessments shall include evaluation of activities against the Fair Information Practice Principles and other applicable privacy and civil liberties policies, principles, and frameworks. Agencies shall consider the assessments and recommendations of the report in implementing privacy and civil liberties protections for agency activities.</p>
<p style="-uslm-lc:I21" class="indent0">(c) In producing the report required under subsection (b) of this section, the Chief Privacy Officer and the Officer for Civil Rights and Civil Liberties of DHS shall consult with the Privacy and Civil Liberties Oversight Board and coordinate with the Office of Management and Budget (OMB).</p>
<p style="-uslm-lc:I21" class="indent0">(d) Information submitted voluntarily in accordance with <ref href="/us/usc/t6/s133">6 U.S.C. 133</ref> by private entities under this order shall be protected from disclosure to the fullest extent permitted by law.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 6. <i>Consultative Process</i>. The Secretary shall establish a consultative process to coordinate improvements to the cybersecurity of critical infrastructure. As part of the consultative process, the Secretary shall engage and consider the advice, on matters set forth in this order, of the Critical Infrastructure Partnership Advisory Council; Sector Coordinating Councils; critical infrastructure owners and operators; Sector-Specific Agencies; other relevant agencies; independent regulatory agencies; State, local, territorial, and tribal governments; universities; and outside experts.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 7. <i>Baseline Framework to Reduce Cyber Risk to Critical Infrastructure</i>. (a) The Secretary of Commerce shall direct the Director of the National Institute of Standards and Technology (the “Director”) to lead the development of a framework to reduce cyber risks to critical infrastructure (the “Cybersecurity Framework”). The Cybersecurity Framework shall include a set of standards, methodologies, procedures, and processes that align policy, business, and technological approaches to address cyber risks. The Cybersecurity Framework shall incorporate voluntary consensus standards and industry best practices to the fullest extent possible. The Cybersecurity Framework shall be consistent with voluntary international standards when such international standards will advance the objectives of this order, and shall meet the requirements of the National Institute of Standards and Technology Act, as amended (<ref href="/us/usc/t15/s271">15 U.S.C. 271</ref> et seq.), the National Technology Transfer and Advancement Act of 1995 (<ref href="/us/pl/104/113">Public Law 104–113</ref>), and OMB Circular A–119, as revised.</p>
<p style="-uslm-lc:I21" class="indent0">(b) The Cybersecurity Framework shall provide a prioritized, flexible, repeatable, performance-based, and cost-effective approach, including information security measures and controls, to help owners and operators of critical infrastructure identify, assess, and manage cyber risk. The Cybersecurity Framework shall focus on identifying cross-sector security standards and guidelines applicable to critical infrastructure. The Cybersecurity Framework will also identify areas for improvement that should be addressed through future collaboration with particular sectors and standards-developing organizations. To enable technical innovation and account for organizational differences, the Cybersecurity Framework will provide guidance that is technology neutral and that enables critical infrastructure sectors to benefit from a competitive market for products and services that meet the standards, methodologies, procedures, and processes developed to address cyber risks. The Cybersecurity Framework shall include guidance for measuring the performance of an entity in implementing the Cybersecurity Framework.</p>
<p style="-uslm-lc:I21" class="indent0">(c) The Cybersecurity Framework shall include methodologies to identify and mitigate impacts of the Cybersecurity Framework and associated information security measures or controls on business confidentiality, and to protect individual privacy and civil liberties.</p>
<p style="-uslm-lc:I21" class="indent0">(d) In developing the Cybersecurity Framework, the Director shall engage in an open public review and comment process. The Director shall also consult with the Secretary, the National Security Agency, Sector-Specific Agencies and other interested agencies including OMB, owners and operators of critical infrastructure, and other stakeholders through the consultative process established in section 6 of this order. The Secretary, the Director of National Intelligence, and the heads of other relevant agencies shall provide threat and vulnerability information and technical expertise to inform the development of the Cybersecurity Framework. The Secretary shall provide performance goals for the Cybersecurity Framework informed by work under section 9 of this order.</p>
<p style="-uslm-lc:I21" class="indent0">(e) Within 240 days of the date of this order, the Director shall publish a preliminary version of the Cybersecurity Framework (the “preliminary Framework”). Within 1 year of the date of this order, and after coordination with the Secretary to ensure suitability under section 8 of this order, the Director shall publish a final version of the Cybersecurity Framework (the “final Framework”).</p>
<p style="-uslm-lc:I21" class="indent0">(f) Consistent with statutory responsibilities, the Director will ensure the Cybersecurity Framework and related guidance is reviewed and updated as necessary, taking into consideration technological changes, changes in cyber risks, operational feedback from owners and operators of critical infrastructure, experience from the implementation of section 8 of this order, and any other relevant factors.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 8. <i>Voluntary Critical Infrastructure Cybersecurity Program</i>. (a) The Secretary, in coordination with Sector-Specific Agencies, shall establish a voluntary program to support the adoption of the Cybersecurity Framework by owners and operators of critical infrastructure and any other interested entities (the “Program”).</p>
<p style="-uslm-lc:I21" class="indent0">(b) Sector-Specific Agencies, in consultation with the Secretary and other interested agencies, shall coordinate with the Sector Coordinating Councils to review the Cybersecurity Framework and, if necessary, develop implementation guidance or supplemental materials to address sector-specific risks and operating environments.</p>
<p style="-uslm-lc:I21" class="indent0">(c) Sector-Specific Agencies shall report annually to the President, through the Secretary, on the extent to which owners and operators notified under section 9 of this order are participating in the Program.</p>
<p style="-uslm-lc:I21" class="indent0">(d) The Secretary shall coordinate establishment of a set of incentives designed to promote participation in the Program. Within 120 days of the date of this order, the Secretary and the Secretaries of the Treasury and Commerce each shall make recommendations separately to the President, through the Assistant to the President for Homeland Security and Counterterrorism and the Assistant to the President for Economic Affairs, that shall include analysis of the benefits and relative effectiveness of such incentives, and whether the incentives would require legislation or can be provided under existing law and authorities to participants in the Program.</p>
<p style="-uslm-lc:I21" class="indent0">(e) Within 120 days of the date of this order, the Secretary of Defense and the Administrator of General Services, in consultation with the Secretary and the Federal Acquisition Regulatory Council, shall make recommendations to the President, through the Assistant to the President for Homeland Security and Counterterrorism and the Assistant to the President for Economic Affairs, on the feasibility, security benefits, and relative merits of incorporating security standards into acquisition planning and contract administration. The report shall address what steps can be taken to harmonize and make consistent existing procurement requirements related to cybersecurity.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 9. <i>Identification of Critical Infrastructure at Greatest Risk</i>. (a) Within 150 days of the date of this order, the Secretary shall use a risk-based approach to identify critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security. In identifying critical infrastructure for this purpose, the Secretary shall use the consultative process established in section 6 of this order and draw upon the expertise of Sector-Specific Agencies. The Secretary shall apply consistent, objective criteria in identifying such critical infrastructure. The Secretary shall not identify any commercial information technology products or consumer information technology services under this section. The Secretary shall review and update the list of identified critical infrastructure under this section on an annual basis, and provide such list to the President, through the Assistant to the President for Homeland Security and Counterterrorism and the Assistant to the President for Economic Affairs.</p>
<p style="-uslm-lc:I21" class="indent0">(b) Heads of Sector-Specific Agencies and other relevant agencies shall provide the Secretary with information necessary to carry out the responsibilities under this section. The Secretary shall develop a process for other relevant stakeholders to submit information to assist in making the identifications required in subsection (a) of this section.</p>
<p style="-uslm-lc:I21" class="indent0">(c) The Secretary, in coordination with Sector-Specific Agencies, shall confidentially notify owners and operators of critical infrastructure identified under subsection (a) of this section that they have been so identified, and ensure identified owners and operators are provided the basis for the determination. The Secretary shall establish a process through which owners and operators of critical infrastructure may submit relevant information and request reconsideration of identifications under subsection (a) of this section.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 10. <i>Adoption of Framework</i>. (a) Agencies with responsibility for regulating the security of critical infrastructure shall engage in a consultative process with DHS, OMB, and the National Security Staff to review the preliminary Cybersecurity Framework and determine if current cybersecurity regulatory requirements are sufficient given current and projected risks. In making such determination, these agencies shall consider the identification of critical infrastructure required under section 9 of this order. Within 90 days of the publication of the preliminary Framework, these agencies shall submit a report to the President, through the Assistant to the President for Homeland Security and Counterterrorism, the Director of OMB, and the Assistant to the President for Economic Affairs, that states whether or not the agency has clear authority to establish requirements based upon the Cybersecurity Framework to sufficiently address current and projected cyber risks to critical infrastructure, the existing authorities identified, and any additional authority required.</p>
<p style="-uslm-lc:I21" class="indent0">(b) If current regulatory requirements are deemed to be insufficient, within 90 days of publication of the final Framework, agencies identified in subsection (a) of this section shall propose prioritized, risk-based, efficient, and coordinated actions, consistent with Executive Order 12866 of <date date="1993-09-30">September 30, 1993</date> (Regulatory Planning and Review), Executive Order 13563 of <date date="2011-01-18">January 18, 2011</date> (Improving Regulation and Regulatory Review), and Executive Order 13609 of <date date="2012-05-01">May 1, 2012</date> (Promoting International Regulatory Cooperation), to mitigate cyber risk.</p>
<p style="-uslm-lc:I21" class="indent0">(c) Within 2 years after publication of the final Framework, consistent with Executive Order 13563 and Executive Order 13610 of <date date="2012-05-10">May 10, 2012</date> (Identifying and Reducing Regulatory Burdens), agencies identified in subsection (a) of this section shall, in consultation with owners and operators of critical infrastructure, report to OMB on any critical infrastructure subject to ineffective, conflicting, or excessively burdensome cybersecurity requirements. This report shall describe efforts made by agencies, and make recommendations for further actions, to minimize or eliminate such requirements.</p>
<p style="-uslm-lc:I21" class="indent0">(d) The Secretary shall coordinate the provision of technical assistance to agencies identified in subsection (a) of this section on the development of their cybersecurity workforce and programs.</p>
<p style="-uslm-lc:I21" class="indent0">(e) Independent regulatory agencies with responsibility for regulating the security of critical infrastructure are encouraged to engage in a consultative process with the Secretary, relevant Sector-Specific Agencies, and other affected parties to consider prioritized actions to mitigate cyber risks for critical infrastructure consistent with their authorities.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 11. <i>Definitions</i>. (a) “Agency” means any authority of the United States that is an “agency” under <ref href="/us/usc/t44/s3502/1">44 U.S.C. 3502(1)</ref>, other than those considered to be independent regulatory agencies, as defined in <ref href="/us/usc/t44/s3502/5">44 U.S.C. 3502(5)</ref>.</p>
<p style="-uslm-lc:I21" class="indent0">(b) “Critical Infrastructure Partnership Advisory Council” means the council established by DHS under <ref href="/us/usc/t6/s451">6 U.S.C. 451</ref> to facilitate effective interaction and coordination of critical infrastructure protection activities among the Federal Government; the private sector; and State, local, territorial, and tribal governments.</p>
<p style="-uslm-lc:I21" class="indent0">(c) “Fair Information Practice Principles” means the eight principles set forth in Appendix A of the National Strategy for Trusted Identities in Cyberspace.</p>
<p style="-uslm-lc:I21" class="indent0">(d) “Independent regulatory agency” has the meaning given the term in <ref href="/us/usc/t44/s3502/5">44 U.S.C. 3502(5)</ref>.</p>
<p style="-uslm-lc:I21" class="indent0">(e) “Sector Coordinating Council” means a private sector coordinating council composed of representatives of owners and operators within a particular sector of critical infrastructure established by the National Infrastructure Protection Plan or any successor.</p>
<p style="-uslm-lc:I21" class="indent0">(f) “Sector-Specific Agency” has the meaning given the term in Presidential Policy Directive–21 of <date date="2013-02-12">February 12, 2013</date> (Critical Infrastructure Security and Resilience), or any successor.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 12. <i>General Provisions</i>. (a) This order shall be implemented consistent with applicable law and subject to the availability of appropriations. Nothing in this order shall be construed to provide an agency with authority for regulating the security of critical infrastructure in addition to or to a greater extent than the authority the agency has under existing law. Nothing in this order shall be construed to alter or limit any authority or responsibility of an agency under existing law.</p>
<p style="-uslm-lc:I21" class="indent0">(b) Nothing in this order shall be construed to impair or otherwise affect the functions of the Director of OMB relating to budgetary, administrative, or legislative proposals.</p>
<p style="-uslm-lc:I21" class="indent0">(c) All actions taken pursuant to this order shall be consistent with requirements and authorities to protect intelligence and law enforcement sources and methods. Nothing in this order shall be interpreted to supersede measures established under authority of law to protect the security and integrity of specific activities and associations that are in direct support of intelligence and law enforcement operations.</p>
<p style="-uslm-lc:I21" class="indent0">(d) This order shall be implemented consistent with U.S. international obligations.</p>
<p style="-uslm-lc:I21" class="indent0">(e) This order is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.</p>
<signature>
<name>Barack Obama.</name>
</signature>
<p style="-uslm-lc:I21" class="indent0">[Reference to the National Security Staff deemed to be a reference to the National Security Council Staff, see Ex. Ord. No. 13657, set out as a note under <ref href="/us/usc/t50/s3021">section 3021 of Title 50</ref>, War and National Defense.]</p>
</note>
<note style="-uslm-lc:I86" topic="executiveOrder" id="idf77dbb3a-4154-11e7-bab8-e125cf475dd2">
<heading class="centered smallCaps">Executive Order No. 13650</heading>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13650, <date date="2013-08-01">Aug. 1, 2013</date>, 78 F.R. 48029, was transferred to a note set out under <ref href="/us/usc/t6/s621">section 621 of this title</ref>.</p>
</note>
<note style="-uslm-lc:I86" topic="executiveOrder" id="idf77de24b-4154-11e7-bab8-e125cf475dd2">
<heading class="centered smallCaps">Ex. Ord. No. 13691. Promoting Private Sector Cybersecurity Information Sharing</heading>
<p style="-uslm-lc:I21" class="indent0">Ex. Ord. No. 13691, <date date="2015-02-13">Feb. 13, 2015</date>, 80 F.R. 9349, provided:</p>
<p style="-uslm-lc:I21" class="indent0">By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered as follows:</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Section</inline> 1. <i>Policy</i>. In order to address cyber threats to public health and safety, national security, and economic security of the United States, private companies, nonprofit organizations, executive departments and agencies (agencies), and other entities must be able to share information related to cybersecurity risks and incidents and collaborate to respond in as close to real time as possible.</p>
<p style="-uslm-lc:I21" class="indent0">Organizations engaged in the sharing of information related to cybersecurity risks and incidents play an invaluable role in the collective cybersecurity of the United States. The purpose of this order is to encourage the voluntary formation of such organizations, to establish mechanisms to continually improve the capabilities and functions of these organizations, and to better allow these organizations to partner with the Federal Government on a voluntary basis.</p>
<p style="-uslm-lc:I21" class="indent0">Such information sharing must be conducted in a manner that protects the privacy and civil liberties of individuals, that preserves business confidentiality, that safeguards the information being shared, and that protects the ability of the Government to detect, investigate, prevent, and respond to cyber threats to the public health and safety, national security, and economic security of the United States.</p>
<p style="-uslm-lc:I21" class="indent0">This order builds upon the foundation established by Executive Order 13636 of <date date="2013-02-12">February 12, 2013</date> (Improving Critical Infrastructure Cybersecurity), and Presidential Policy Directive–21 (PPD–21) of <date date="2013-02-12">February 12, 2013</date> (Critical Infrastructure Security and Resilience).</p>
<p style="-uslm-lc:I21" class="indent0">Policy coordination, guidance, dispute resolution, and periodic in-progress reviews for the functions and programs described and assigned herein shall be provided through the interagency process established in Presidential Policy Directive–l [sic] (PPD–l [PPD–1]) of <date date="2009-02-13">February 13, 2009</date> (Organization of the National Security Council System), or any successor.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 2. <i>Information Sharing and Analysis Organizations</i>. (a) The Secretary of Homeland Security (Secretary) shall strongly encourage the development and formation of Information Sharing and Analysis Organizations (ISAOs).</p>
<p style="-uslm-lc:I21" class="indent0">(b) ISAOs may be organized on the basis of sector, sub-sector, region, or any other affinity, including in response to particular emerging threats or vulnerabilities. ISAO membership may be drawn from the public or private sectors, or consist of a combination of public and private sector organizations. ISAOs may be formed as for-profit or nonprofit entities.</p>
<p style="-uslm-lc:I21" class="indent0">(c) The National Cybersecurity and Communications Integration Center (NCCIC), established under section 226(b) of the Homeland Security Act of 2002 (the “Act”), shall engage in continuous, collaborative, and inclusive coordination with ISAOs on the sharing of information related to cybersecurity risks and incidents, addressing such risks and incidents, and strengthening information security systems consistent with sections 212 and 226 of the Act.</p>
<p style="-uslm-lc:I21" class="indent0">(d) In promoting the formation of ISAOs, the Secretary shall consult with other Federal entities responsible for conducting cybersecurity activities, including Sector-Specific Agencies, independent regulatory agencies at their discretion, and national security and law enforcement agencies.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 3. <i>ISAO Standards Organization</i>. (a) The Secretary, in consultation with other Federal entities responsible for conducting cybersecurity and related activities, shall, through an open and competitive process, enter into an agreement with a nongovernmental organization to serve as the ISAO Standards Organization (SO), which shall identify a common set of voluntary standards or guidelines for the creation and functioning of ISAOs under this order. The standards shall further the goal of creating robust information sharing related to cybersecurity risks and incidents with ISAOs and among ISAOs to create deeper and broader networks of information sharing nationally, and to foster the development and adoption of automated mechanisms for the sharing of information. The standards will address the baseline capabilities that ISAOs under this order should possess and be able to demonstrate. These standards shall address, but not be limited to, contractual agreements, business processes, operating procedures, technical means, and privacy protections, such as minimization, for ISAO operation and ISAO member participation.</p>
<p style="-uslm-lc:I21" class="indent0">(b) To be selected, the SO must demonstrate the ability to engage and work across the broad community of organizations engaged in sharing information related to cybersecurity risks and incidents, including ISAOs, and associations and private companies engaged in information sharing in support of their customers.</p>
<p style="-uslm-lc:I21" class="indent0">(c) The agreement referenced in section 3(a) shall require that the SO engage in an open public review and comment process for the development of the standards referenced above, soliciting the viewpoints of existing entities engaged in sharing information related to cybersecurity risks and incidents, owners and operators of critical infrastructure, relevant agencies, and other public and private sector stakeholders.</p>
<p style="-uslm-lc:I21" class="indent0">(d) The Secretary shall support the development of these standards and, in carrying out the requirements set forth in this section, shall consult with the Office of Management and Budget, the National Institute of Standards and Technology in the Department of Commerce, Department of Justice, the Information Security Oversight Office in the National Archives and Records Administration, the Office of the Director of National Intelligence, Sector-Specific Agencies, and other interested Federal entities. All standards shall be consistent with voluntary international standards when such international standards will advance the objectives of this order, and shall meet the requirements of the National Technology Transfer and Advancement Act of 1995 (<ref href="/us/pl/104/113">Public Law 104–113</ref>), and OMB Circular A–119, as revised.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 4. <i>Critical Infrastructure Protection Program</i>. (a) Pursuant to sections 213 and 214(h) of the Critical Infrastructure Information Act of 2002, I hereby designate the NCCIC as a critical infrastructure protection program and delegate to it authority to enter into voluntary agreements with ISAOs in order to promote critical infrastructure security with respect to cybersecurity.</p>
<p style="-uslm-lc:I21" class="indent0">(b) Other Federal entities responsible for conducting cybersecurity and related activities to address threats to the public health and safety, national security, and economic security, consistent with the objectives of this order, may participate in activities under these agreements.</p>
<p style="-uslm-lc:I21" class="indent0">(c) The Secretary will determine the eligibility of ISAOs and their members for any necessary facility or personnel security clearances associated with voluntary agreements in accordance with Executive Order 13549 of <date date="2010-08-18">August 18, 2010</date> (Classified National Security Information Programs for State, Local, Tribal, and Private Sector Entities), and Executive Order 12829 of <date date="1993-01-06">January 6, 1993</date> (National Industrial Security Program), as amended, including as amended by this order.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 5. <i>Privacy and Civil Liberties Protections</i>. (a) Agencies shall coordinate their activities under this order with their senior agency officials for privacy and civil liberties and ensure that appropriate protections for privacy and civil liberties are incorporated into such activities. Such protections shall be based upon the Fair Information Practice Principles and other privacy and civil liberties policies, principles, and frameworks as they apply to each agency’s activities.</p>
<p style="-uslm-lc:I21" class="indent0">(b) Senior privacy and civil liberties officials for agencies engaged in activities under this order shall conduct assessments of their agency’s activities and provide those assessments to the Department of Homeland Security (DHS) Chief Privacy Officer and the DHS Office for Civil Rights and Civil Liberties for consideration and inclusion in the Privacy and Civil Liberties Assessment report required under Executive Order 13636.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 6. <i>National Industrial Security Program</i>. [Amended Ex. Ord. No. 12829, set out as a note under <ref href="/us/usc/t50/s3161">section 3161 of Title 50</ref>, War and National Defense.]</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 7. <i>Definitions</i>. (a) “Critical infrastructure information” has the meaning given the term in section 212(3) of the Critical Infrastructure Information Act of 2002.</p>
<p style="-uslm-lc:I21" class="indent0">(b) “Critical infrastructure protection program” has the meaning given the term in section 212(4) of the Critical Infrastructure Information Act of 2002.</p>
<p style="-uslm-lc:I21" class="indent0">(c) “Cybersecurity risk” has the meaning given the term in section 226(a)(1) of the Homeland Security Act of 2002 (as amended by the National Cybersecurity Protection Act of 2014).</p>
<p style="-uslm-lc:I21" class="indent0">(d) “Fair Information Practice Principles” means the eight principles set forth in Appendix A of the National Strategy for Trusted Identities in Cyberspace.</p>
<p style="-uslm-lc:I21" class="indent0">(e) “Incident” has the meaning given the term in section 226(a)(2) of the Homeland Security Act of 2002 (as amended by the National Cybersecurity Protection Act of 2014).</p>
<p style="-uslm-lc:I21" class="indent0">(f) “Information Sharing and Analysis Organization” has the meaning given the term in section 212(5) of the Critical Infrastrucure Information Act of 2002.</p>
<p style="-uslm-lc:I21" class="indent0">(g) “Sector-Specific Agency” has the meaning given the term in PPD–21, or any successor.</p>
<p style="-uslm-lc:I21" class="indent0"><inline class="small-caps">Sec</inline>. 8. <i>General Provisions</i>. (a) Nothing in this order shall be construed to impair or otherwise affect:</p>
<p style="-uslm-lc:I21" class="indent0">(i) the authority granted by law or Executive Order to an agency, or the head thereof; or</p>
<p style="-uslm-lc:I21" class="indent0">(ii) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals.</p>
<p style="-uslm-lc:I21" class="indent0">(b) This order shall be implemented consistent with applicable law and subject to the availability of appropriations. Nothing in this order shall be construed to alter or limit any authority or responsibility of an agency under existing law including those activities conducted with the private sector relating to criminal and national security threats. Nothing in this order shall be construed to provide an agency with authority for regulating the security of critical infrastructure in addition to or to a greater extent than the authority the agency has under existing law.</p>
<p style="-uslm-lc:I21" class="indent0">(c) All actions taken pursuant to this order shall be consistent with requirements and authorities to protect intelligence and law enforcement sources and methods.</p>
<p style="-uslm-lc:I21" class="indent0">(d) This order is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.</p>
<signature>
<name>Barack Obama.</name>
</signature>
</note>
</notes>
</section>