<section xmlns="http://xml.house.gov/schemas/uslm/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" style="-uslm-lc:I80" id="idea6b03a9-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652"><num value="652">§ 652.</num><heading> Cybersecurity and Infrastructure Security Agency</heading><subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idea6b03aa-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/a"><num value="a" class="bold">(a)</num><heading class="bold"> Redesignation</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b03ab-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/a/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I12" class="indent1">The National Protection and Programs Directorate of the Department shall, on and after <date date="2018-11-16">November 16, 2018</date>, be known as the “Cybersecurity and Infrastructure Security Agency”.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b03ac-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/a/2"><num value="2" class="bold">(2)</num><heading class="bold"> References</heading><content><p style="-uslm-lc:I12" class="indent1">Any reference to the National Protection and Programs Directorate of the Department in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Cybersecurity and Infrastructure Security Agency of the Department.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idea6b03ad-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b"><num value="b" class="bold">(b)</num><heading class="bold"> Director</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b03ae-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I12" class="indent1">The Agency shall be headed by the Director, who shall report to the Secretary.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b03af-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b/2"><num value="2" class="bold">(2)</num><heading class="bold"> Qualifications</heading><subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="idea6b03b0-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b/2/A"><num value="A" class="bold">(A)</num><heading class="bold"> In general</heading><chapeau style="-uslm-lc:I13" class="indent2">The Director shall be appointed from among individuals who have—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="idea6b03b1-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b/2/A/i"><num value="i">(i)</num><content> extensive knowledge in at least two of the areas specified in subparagraph (B); and</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03b2-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b/2/A/ii"><num value="ii">(ii)</num><content> not fewer than five years of demonstrated experience in efforts to foster coordination and collaboration between the Federal Government, the private sector, and other entities on issues related to cybersecurity, infrastructure security, or security risk management.</content>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="idea6b03b3-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b/2/B"><num value="B" class="bold">(B)</num><heading class="bold"> Specified areas</heading><chapeau style="-uslm-lc:I13" class="indent2">The areas specified in this subparagraph are the following:</chapeau><clause style="-uslm-lc:I14" class="indent3" id="idea6b03b4-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b/2/B/i"><num value="i">(i)</num><content> Cybersecurity.</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03b5-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b/2/B/ii"><num value="ii">(ii)</num><content> Infrastructure security.</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03b6-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b/2/B/iii"><num value="iii">(iii)</num><content> Security risk management.</content>
</clause>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b03b7-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/b/3"><num value="3" class="bold">(3)</num><heading class="bold"> Reference</heading><content><p style="-uslm-lc:I12" class="indent1">Any reference to an Under Secretary responsible for overseeing critical infrastructure protection, cybersecurity, and any other related program of the Department as described in <ref href="/us/usc/t6/s113/a/1/H">section 113(a)(1)(H) of this title</ref> as in effect on the day before <date date="2018-11-16">November 16, 2018</date>, in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Director of the Cybersecurity and Infrastructure Security Agency.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idea6b03b8-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c"><num value="c" class="bold">(c)</num><heading class="bold"> Responsibilities</heading><chapeau style="-uslm-lc:I11" class="indent0">The Director shall—</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03b9-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/1"><num value="1">(1)</num><content> lead cybersecurity and critical infrastructure security programs, operations, and associated policy for the Agency, including national cybersecurity asset response activities;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03ba-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/2"><num value="2">(2)</num><content> coordinate with Federal entities, including Sector-Specific Agencies, and non-Federal entities, including international entities, to carry out the cybersecurity and critical infrastructure activities of the Agency, as appropriate;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03bb-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/3"><num value="3">(3)</num><content> carry out the responsibilities of the Secretary to secure Federal information and information systems consistent with law, including subchapter II of chapter 35 of title 44 and the Cybersecurity Act of 2015 (contained in division N of the Consolidated Appropriations Act, 2016 (<ref href="/us/pl/114/113">Public Law 114–113</ref>)), including by carrying out a periodic strategic assessment of the related programs and activities of the Agency to ensure such programs and activities contemplate the innovation of information systems and changes in cybersecurity risks and cybersecurity threats;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03bc-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/4"><num value="4">(4)</num><content> coordinate a national effort to secure and protect against critical infrastructure risks, consistent with subsection (e)(1)(E);</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03bd-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/5"><num value="5">(5)</num><content> upon request, provide analyses, expertise, and other technical assistance to critical infrastructure owners and operators and, where appropriate, provide those analyses, expertise, and other technical assistance in coordination with Sector-Specific Agencies and other Federal departments and agencies;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03be-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/6"><num value="6">(6)</num><content> develop and utilize mechanisms for active and frequent collaboration between the Agency and Sector-Specific Agencies to ensure appropriate coordination, situational awareness, and communications with Sector-Specific Agencies;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03bf-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/7"><num value="7">(7)</num><content> maintain and utilize mechanisms for the regular and ongoing consultation and collaboration among the Divisions of the Agency to further operational coordination, integrated situational awareness, and improved integration across the Agency in accordance with this chapter;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03c0-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/8"><num value="8">(8)</num><chapeau> develop, coordinate, and implement—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03c1-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/8/A"><num value="A">(A)</num><content> comprehensive strategic plans for the activities of the Agency; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03c2-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/8/B"><num value="B">(B)</num><content> risk assessments by and for the Agency;</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03c3-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/9"><num value="9">(9)</num><content> carry out emergency communications responsibilities, in accordance with subchapter XIII;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03c4-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/10"><num value="10">(10)</num><content> carry out cybersecurity, infrastructure security, and emergency communications stakeholder outreach and engagement and coordinate that outreach and engagement with critical infrastructure Sector-Specific Agencies, as appropriate;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03c5-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/11"><num value="11">(11)</num><content> provide education, training, and capacity development to Federal and non-Federal entities to enhance the security and resiliency of domestic and global cybersecurity and infrastructure security;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03c6-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/12"><num value="12">(12)</num><content> appoint a Cybersecurity State Coordinator in each State, as described in <ref href="/us/usc/t6/s665c">section 665c of this title</ref>;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03c7-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/13"><num value="13">(13)</num><content> carry out the duties and authorities relating to the .gov internet domain, as described in <ref href="/us/usc/t6/s665">section 665 of this title</ref>; and</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03c8-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/c/14"><num value="14">(14)</num><content> carry out such other duties and powers prescribed by law or delegated by the Secretary.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idea6b03c9-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/d"><num value="d" class="bold">(d)</num><heading class="bold"> Deputy Director</heading><chapeau style="-uslm-lc:I11" class="indent0">There shall be in the Agency a Deputy Director of the Cybersecurity and Infrastructure Security Agency who shall—</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03ca-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/d/1"><num value="1">(1)</num><content> assist the Director in the management of the Agency; and</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03cb-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/d/2"><num value="2">(2)</num><content> report to the Director.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idea6b03cc-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e"><num value="e" class="bold">(e)</num><heading class="bold"> Cybersecurity and infrastructure security authorities of the Secretary</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b03cd-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><chapeau style="-uslm-lc:I12" class="indent1">The responsibilities of the Secretary relating to cybersecurity and infrastructure security shall include the following:</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03ce-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/A"><num value="A">(A)</num><chapeau> To access, receive, and analyze law enforcement information, intelligence information, and other information from Federal Government agencies, State, local, tribal, and territorial government agencies, including law enforcement agencies, and private sector entities, and to integrate that information, in support of the mission responsibilities of the Department, in order to—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="idea6b03cf-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/A/i"><num value="i">(i)</num><content> identify and assess the nature and scope of terrorist threats to the homeland;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03d0-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/A/ii"><num value="ii">(ii)</num><content> detect and identify threats of terrorism against the United States; and</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03d1-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/A/iii"><num value="iii">(iii)</num><content> understand those threats in light of actual and potential vulnerabilities of the homeland.</content>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03d2-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/B"><num value="B">(B)</num><content> To carry out comprehensive assessments of the vulnerabilities of the key resources and critical infrastructure of the United States, including the performance of risk assessments to determine the risks posed by particular types of terrorist attacks within the United States, including an assessment of the probability of success of those attacks and the feasibility and potential efficacy of various countermeasures to those attacks. At the discretion of the Secretary, such assessments may be carried out in coordination with Sector-Specific Agencies.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03d3-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/C"><num value="C">(C)</num><content> To integrate relevant information, analysis, and vulnerability assessments, regardless of whether the information, analysis, or assessments are provided or produced by the Department, in order to make recommendations, including prioritization, for protective and support measures by the Department, other Federal Government agencies, State, local, tribal, and territorial government agencies and authorities, the private sector, and other entities regarding terrorist and other threats to homeland security.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03d4-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/D"><num value="D">(D)</num><content> To ensure, pursuant to <ref href="/us/usc/t6/s122">section 122 of this title</ref>, the timely and efficient access by the Department to all information necessary to discharge the responsibilities under this subchapter, including obtaining that information from other Federal Government agencies.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03d5-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/E"><num value="E">(E)</num><content> To develop, in coordination with the Sector-Specific Agencies with available expertise, a comprehensive national plan for securing the key resources and critical infrastructure of the United States, including power production, generation, and distribution systems, information technology and telecommunications systems (including satellites), electronic financial and property record storage and transmission systems, emergency communications systems, and the physical and technological assets that support those systems.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03d6-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/F"><num value="F">(F)</num><content> To recommend measures necessary to protect the key resources and critical infrastructure of the United States in coordination with other Federal Government agencies, including Sector-Specific Agencies, and in cooperation with State, local, tribal, and territorial government agencies and authorities, the private sector, and other entities.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03d7-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/G"><num value="G">(G)</num><content> To review, analyze, and make recommendations for improvements to the policies and procedures governing the sharing of information relating to homeland security within the Federal Government and between Federal Government agencies and State, local, tribal, and territorial government agencies and authorities.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03d8-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/H"><num value="H">(H)</num><content> To disseminate, as appropriate, information analyzed by the Department within the Department to other Federal Government agencies with responsibilities relating to homeland security and to State, local, tribal, and territorial government agencies and private sector entities with those responsibilities in order to assist in the deterrence, prevention, or preemption of, or response to, terrorist attacks against the United States.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03d9-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/I"><num value="I">(I)</num><content> To consult with State, local, tribal, and territorial government agencies and private sector entities to ensure appropriate exchanges of information, including law enforcement-related information, relating to threats of terrorism against the United States.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03da-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/J"><num value="J">(J)</num><content> To ensure that any material received pursuant to this chapter is protected from unauthorized disclosure and handled and used only for the performance of official duties.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03db-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/K"><num value="K">(K)</num><content> To request additional information from other Federal Government agencies, State, local, tribal, and territorial government agencies, and the private sector relating to threats of terrorism in the United States, or relating to other areas of responsibility assigned by the Secretary, including the entry into cooperative agreements through the Secretary to obtain such information.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03dc-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/L"><num value="L">(L)</num><content> To establish and utilize, in conjunction with the Chief Information Officer of the Department, a secure communications and information technology infrastructure, including data-mining and other advanced analytical tools, in order to access, receive, and analyze data and information in furtherance of the responsibilities under this section, and to disseminate information acquired and analyzed by the Department, as appropriate.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03dd-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/M"><num value="M">(M)</num><content> To coordinate training and other support to the elements and personnel of the Department, other Federal Government agencies, and State, local, tribal, and territorial government agencies that provide information to the Department, or are consumers of information provided by the Department, in order to facilitate the identification and sharing of information revealed in their ordinary duties and the optimal utilization of information received from the Department.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03de-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/N"><num value="N">(N)</num><content> To coordinate with Federal, State, local, tribal, and territorial law enforcement agencies, and the private sector, as appropriate.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03df-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/O"><num value="O">(O)</num><content> To exercise the authorities and oversight of the functions, personnel, assets, and liabilities of those components transferred to the Department pursuant to <ref href="/us/usc/t6/s121/g">section 121(g) of this title</ref>.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03e0-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/P"><num value="P">(P)</num><content> To carry out the functions of the national cybersecurity and communications integration center under <ref href="/us/usc/t6/s659">section 659 of this title</ref>.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03e1-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/Q"><num value="Q">(Q)</num><content> To carry out the requirements of the Chemical Facility Anti-Terrorism Standards Program established under subchapter XVI and the secure handling of ammonium nitrate program established under part J of subchapter VIII, or any successor programs.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b03e2-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/R"><num value="R">(R)</num><chapeau> To encourage and build cybersecurity awareness and competency across the United States and to develop, attract, and retain the cybersecurity workforce necessary for the cybersecurity related missions of the Department, including by—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="idea6b03e3-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/R/i"><num value="i">(i)</num><content> overseeing elementary and secondary cybersecurity education and awareness related programs at the Agency;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03e4-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/R/ii"><num value="ii">(ii)</num><content> leading efforts to develop, attract, and retain the cybersecurity workforce necessary for the cybersecurity related missions of the Department;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03e5-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/R/iii"><num value="iii">(iii)</num><content> encouraging and building cybersecurity awareness and competency across the United States; and</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03e6-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/R/iv"><num value="iv">(iv)</num><chapeau> carrying out cybersecurity related workforce development activities, including through—</chapeau><subclause style="-uslm-lc:I16" class="indent4" id="idea6b03e7-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/R/iv/I"><num value="I">(I)</num><content> increasing the pipeline of future cybersecurity professionals through programs focused on elementary and secondary education, postsecondary education, and workforce development; and</content>
</subclause>
<subclause style="-uslm-lc:I16" class="indent4" id="idea6b03e8-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/1/R/iv/II"><num value="II">(II)</num><content> building awareness of and competency in cybersecurity across the civilian Federal Government workforce.</content>
</subclause>
</clause>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b03e9-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/2"><num value="2" class="bold">(2)</num><heading class="bold"> Reallocation</heading><content><p style="-uslm-lc:I12" class="indent1">The Secretary may reallocate within the Agency the functions specified in sections 653(b) and 654(b) of this title, consistent with the responsibilities provided in paragraph (1), upon certifying to and briefing the appropriate congressional committees, and making available to the public, at least 60 days prior to the reallocation that the reallocation is necessary for carrying out the activities of the Agency.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b03ea-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/3"><num value="3" class="bold">(3)</num><heading class="bold"> Staff</heading><subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="idea6b03eb-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/3/A"><num value="A" class="bold">(A)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I13" class="indent2">The Secretary shall provide the Agency with a staff of analysts having appropriate expertise and experience to assist the Agency in discharging the responsibilities of the Agency under this section.</p>
</content>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="idea6b03ec-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/3/B"><num value="B" class="bold">(B)</num><heading class="bold"> Private sector analysts</heading><content><p style="-uslm-lc:I13" class="indent2">Analysts under this subsection may include analysts from the private sector.</p>
</content>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="idea6b03ed-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/3/C"><num value="C" class="bold">(C)</num><heading class="bold"> Security clearances</heading><content><p style="-uslm-lc:I13" class="indent2">Analysts under this subsection shall possess security clearances appropriate for their work under this section.</p>
</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b03ee-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4"><num value="4" class="bold">(4)</num><heading class="bold"> Detail of personnel</heading><subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="idea6b03ef-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/A"><num value="A" class="bold">(A)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I13" class="indent2">In order to assist the Agency in discharging the responsibilities of the Agency under this section, personnel of the Federal agencies described in subparagraph (B) may be detailed to the Agency for the performance of analytic functions and related duties.</p>
</content>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="idea6b03f0-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/B"><num value="B" class="bold">(B)</num><heading class="bold"> Agencies</heading><chapeau style="-uslm-lc:I13" class="indent2">The Federal agencies described in this subparagraph are—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="idea6b03f1-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/B/i"><num value="i">(i)</num><content> the Department of State;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03f2-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/B/ii"><num value="ii">(ii)</num><content> the Central Intelligence Agency;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03f3-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/B/iii"><num value="iii">(iii)</num><content> the Federal Bureau of Investigation;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03f4-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/B/iv"><num value="iv">(iv)</num><content> the National Security Agency;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03f5-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/B/v"><num value="v">(v)</num><content> the National Geospatial-Intelligence Agency;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03f6-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/B/vi"><num value="vi">(vi)</num><content> the Defense Intelligence Agency;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03f7-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/B/vii"><num value="vii">(vii)</num><content> Sector-Specific Agencies; and</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="idea6b03f8-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/B/viii"><num value="viii">(viii)</num><content> any other agency of the Federal Government that the President considers appropriate.</content>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="idea6b03f9-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/C"><num value="C" class="bold">(C)</num><heading class="bold"> Interagency agreements</heading><content><p style="-uslm-lc:I13" class="indent2">The Secretary and the head of a Federal agency described in subparagraph (B) may enter into agreements for the purpose of detailing personnel under this paragraph.</p>
</content>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="idea6b03fa-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/e/4/D"><num value="D" class="bold">(D)</num><heading class="bold"> Basis</heading><content><p style="-uslm-lc:I13" class="indent2">The detail of personnel under this paragraph may be on a reimbursable or non-reimbursable basis.</p>
</content>
</subparagraph>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idea6b03fb-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/f"><num value="f" class="bold">(f)</num><heading class="bold"> Composition</heading><chapeau style="-uslm-lc:I11" class="indent0">The Agency shall be composed of the following divisions:</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03fc-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/f/1"><num value="1">(1)</num><content> The Cybersecurity Division, headed by an Executive Assistant Director.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03fd-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/f/2"><num value="2">(2)</num><content> The Infrastructure Security Division, headed by an Executive Assistant Director.</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="idea6b03fe-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/f/3"><num value="3">(3)</num><content> The Emergency Communications Division under subchapter XIII, headed by an Executive Assistant Director.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idea6b03ff-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/g"><num value="g" class="bold">(g)</num><heading class="bold"> Co-location</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b0400-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/g/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I12" class="indent1">To the maximum extent practicable, the Director shall examine the establishment of central locations in geographical regions with a significant Agency presence.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b0401-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/g/2"><num value="2" class="bold">(2)</num><heading class="bold"> Coordination</heading><content><p style="-uslm-lc:I12" class="indent1">When establishing the central locations described in paragraph (1), the Director shall coordinate with component heads and the Under Secretary for Management to co-locate or partner on any new real property leases, renewing any occupancy agreements for existing leases, or agreeing to extend or newly occupy any Federal space or new construction.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idea6b0402-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/h"><num value="h" class="bold">(h)</num><heading class="bold"> Privacy</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b0403-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/h/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I12" class="indent1">There shall be a Privacy Officer of the Agency with primary responsibility for privacy policy and compliance for the Agency.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="idea6b0404-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/h/2"><num value="2" class="bold">(2)</num><heading class="bold"> Responsibilities</heading><chapeau style="-uslm-lc:I12" class="indent1">The responsibilities of the Privacy Officer of the Agency shall include—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b0405-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/h/2/A"><num value="A">(A)</num><content> assuring that the use of technologies by the Agency sustain, and do not erode, privacy protections relating to the use, collection, and disclosure of personal information;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b0406-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/h/2/B"><num value="B">(B)</num><content> assuring that personal information contained in systems of records of the Agency is handled in full compliance as specified in <ref href="/us/usc/t5/s552a">section 552a of title 5</ref> (commonly known as the “Privacy Act of 1974”);</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b0407-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/h/2/C"><num value="C">(C)</num><content> evaluating legislative and regulatory proposals involving collection, use, and disclosure of personal information by the Agency; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="idea6b0408-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/h/2/D"><num value="D">(D)</num><content> conducting a privacy impact assessment of proposed rules of the Agency on the privacy of personal information, including the type of personal information collected and the number of people affected.</content>
</subparagraph>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="idea6b0409-6371-11ee-b880-a1730754906d" identifier="/us/usc/t6/s652/i"><num value="i" class="bold">(i)</num><heading class="bold"> Savings</heading><content><p style="-uslm-lc:I11" class="indent0">Nothing in this subchapter may be construed as affecting in any manner the authority, existing on the day before <date date="2018-11-16">November 16, 2018</date>, of any other component of the Department or any other Federal department or agency, including the authority provided to the Sector Risk Management Agency specified in section 61003(c) of division F of the Fixing America’s Surface Transportation Act (<ref href="/us/usc/t6/s121">6 U.S.C. 121</ref> note; <ref href="/us/pl/114/94">Public Law 114–94</ref>).</p>
</content>
</subsection>
<sourceCredit id="idea6b040a-6371-11ee-b880-a1730754906d">(<ref href="/us/pl/107/296/tXXII/s2202">Pub. L. 107–296, title XXII, § 2202</ref>, as added <ref href="/us/pl/115/278/s2/a">Pub. L. 115–278, § 2(a)</ref>, <date date="2018-11-16">Nov. 16, 2018</date>, <ref href="/us/stat/132/4169">132 Stat. 4169</ref>; amended <ref href="/us/pl/116/260/dU/tIX/s904/b/1/A">Pub. L. 116–260, div. U, title IX, § 904(b)(1)(A)</ref>, <date date="2020-12-27">Dec. 27, 2020</date>, <ref href="/us/stat/134/2298">134 Stat. 2298</ref>; <ref href="/us/pl/116/283/dA/tXVII">Pub. L. 116–283, div. A, title XVII</ref>, §§ 1717(a)(1)(A), 1719(a), (b), div. H, title XC, §§ 9001(a), 9002(c)(2)(D), <date date="2021-01-01">Jan. 1, 2021</date>, <ref href="/us/stat/134/4099">134 Stat. 4099</ref>, 4105, 4766, 4773; <ref href="/us/pl/117/81/dA/tXV">Pub. L. 117–81, div. A, title XV</ref>, §§ 1547(b)(1)(A)(i), (B), 1549(a), <date date="2021-12-27">Dec. 27, 2021</date>, <ref href="/us/stat/135/2060">135 Stat. 2060</ref>, 2061, 2063; <ref href="/us/pl/117/263/dG/tLXXI/s7143/a/1">Pub. L. 117–263, div. G, title LXXI, § 7143(a)(1)</ref>, (b)(2)(C), (c)(5), <date date="2022-12-23">Dec. 23, 2022</date>, <ref href="/us/stat/136/3654">136 Stat. 3654</ref>, 3659, 3663.)</sourceCredit>
<notes type="uscNote" id="idea6b040b-6371-11ee-b880-a1730754906d">
<note style="-uslm-lc:I74" role="crossHeading" topic="editorialNotes" id="idea6b040c-6371-11ee-b880-a1730754906d"><heading class="centered"><b>Editorial Notes</b></heading></note>
<note style="-uslm-lc:I75" topic="referencesInText" id="idea6b040d-6371-11ee-b880-a1730754906d">
<heading class="centered smallCaps">References in Text</heading><p style="-uslm-lc:I21" class="indent0">The Cybersecurity Act of 2015, referred to in subsec. (c)(3), is div. N of <ref href="/us/pl/114/113">Pub. L. 114–113</ref>, <date date="2015-12-18">Dec. 18, 2015</date>, <ref href="/us/stat/129/2935">129 Stat. 2935</ref>. For complete classification of this Act to the Code, see Short Title note set out under <ref href="/us/usc/t6/s1501">section 1501 of this title</ref> and Tables.</p>
<p style="-uslm-lc:I21" class="indent0">This chapter, referred to in subsecs. (c)(7) and (e)(1)(J), was in the original “this Act”, meaning <ref href="/us/pl/107/296">Pub. L. 107–296</ref>, <date date="2002-11-25">Nov. 25, 2002</date>, <ref href="/us/stat/116/2135">116 Stat. 2135</ref>, known as the Homeland Security Act of 2002, which is classified principally to this chapter. For complete classification of this Act to the Code, see Short Title note set out under <ref href="/us/usc/t6/s101">section 101 of this title</ref> and Tables.</p>
</note>
<note style="-uslm-lc:I74" topic="amendments" id="idea6b040e-6371-11ee-b880-a1730754906d"><heading class="centered smallCaps">Amendments</heading><p style="-uslm-lc:I21" class="indent0">2022—<ref href="/us/pl/117/263/s7143/a/1">Pub. L. 117–263, § 7143(a)(1)</ref>, made amendment identical to that made by <ref href="/us/pl/117/81/s1547/b/1/B">Pub. L. 117–81, § 1547(b)(1)(B)</ref>. See 2021 Amendment note below.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (a)(1). <ref href="/us/pl/117/263/s7143/b/2/C/i">Pub. L. 117–263, § 7143(b)(2)(C)(i)</ref>, which directed striking out “(in this part referred to as the Agency)”, was executed by striking out “(in this part referred to as the ‘Agency’)” before period at end, to reflect the probable intent of Congress.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (b)(1). <ref href="/us/pl/117/263/s7143/b/2/C/ii">Pub. L. 117–263, § 7143(b)(2)(C)(ii)</ref>, substituted “the Director” for “a Director of Cybersecurity and Infrastructure Security (in this part referred to as the ‘Director’)”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (b)(3). <ref href="/us/pl/117/263/s7143/c/5/A">Pub. L. 117–263, § 7143(c)(5)(A)</ref>, substituted “Director of the Cybersecurity and Infrastructure Security Agency” for “Director of Cybersecurity and Infrastructure Security of the Department”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d). <ref href="/us/pl/117/263/s7143/c/5/B">Pub. L. 117–263, § 7143(c)(5)(B)</ref>, substituted “Director of the Cybersecurity and Infrastructure Security Agency” for “Director of Cybersecurity and Infrastructure Security” in introductory provisions.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (f). <ref href="/us/pl/117/263/s7143/b/2/C/iii">Pub. L. 117–263, § 7143(b)(2)(C)(iii)</ref>, inserted “Executive” before “Assistant Director” in pars. (1) to (3).</p>
<p style="-uslm-lc:I21" class="indent0">2021—<ref href="/us/pl/117/81/s1547/b/1/B">Pub. L. 117–81, § 1547(b)(1)(B)</ref>, made technical amendment to directory language of <ref href="/us/pl/116/260/s904/b/1">Pub. L. 116–260, § 904(b)(1)</ref>. See 2020 Amendment notes below.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (b)(2), (3). <ref href="/us/pl/116/283/s9001/a">Pub. L. 116–283, § 9001(a)</ref>, added par. (2) and redesignated former par. (2) as (3).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(3). <ref href="/us/pl/117/81/s1549/a">Pub. L. 117–81, § 1549(a)</ref>, substituted “, including by carrying out a periodic strategic assessment of the related programs and activities of the Agency to ensure such programs and activities contemplate the innovation of information systems and changes in cybersecurity risks and cybersecurity threats;” for semicolon at end.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(10). <ref href="/us/pl/116/283">Pub. L. 116–283</ref>, §§ 1717(a)(1)(A)(i), 1719(b)(1), which directed identical amendments of par. (10) by striking out “and” at end, could not be executed because the word “and” did not appear at end after amendment by <ref href="/us/pl/116/260/s904/b/1/A/i">Pub. L. 116–260, § 904(b)(1)(A)(i)</ref>. See 2020 Amendment note below.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(11). <ref href="/us/pl/117/81/s1547/b/1/A/i/I">Pub. L. 117–81, § 1547(b)(1)(A)(i)(I)</ref>, struck out “and” after the semicolon.</p>
<p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/116/283/s1719/b/3">Pub. L. 116–283, § 1719(b)(3)</ref>, added par. (11) relating to providing education, training, and capacity development to Federal and non-Federal entities. Former par. (11), relating to appointment of a Cybersecurity State Coordinator, redesignated (12).</p>
<p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/116/283/s1717/a/1/A/iii">Pub. L. 116–283, § 1717(a)(1)(A)(iii)</ref>, added par. (11) relating to appointment of a Cybersecurity State Coordinator. Former par. (11), relating to the .gov internet domain, redesignated (12).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(12). <ref href="/us/pl/117/81/s1547/b/1/A/i/II">Pub. L. 117–81, § 1547(b)(1)(A)(i)(II)</ref>, struck out “and” at end and made technical amendment to reference in original Act which appears in text as reference to <ref href="/us/usc/t6/s665c">section 665c of this title</ref>.</p>
<p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/116/283/s1719/b/2">Pub. L. 116–283, § 1719(b)(2)</ref>, redesignated par. (11) relating to appointment of a Cybersecurity State Coordinator as (12).</p>
<p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/116/283/s1717/a/1/A/ii">Pub. L. 116–283, § 1717(a)(1)(A)(ii)</ref>, redesignated par. (11) relating to the .gov internet domain as (12).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(13). <ref href="/us/pl/117/81/s1547/b/1/A/i/III">Pub. L. 117–81, § 1547(b)(1)(A)(i)(III)</ref>, redesignated par. (12) relating to the .gov internet domain as (13).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(14). <ref href="/us/pl/117/81/s1547/b/1/A/i/IV">Pub. L. 117–81, § 1547(b)(1)(A)(i)(IV)</ref>, redesignated par. (12) relating to carrying out such other duties and powers as (14).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (e)(1)(R). <ref href="/us/pl/116/283/s1719/a">Pub. L. 116–283, § 1719(a)</ref>, added subpar. (R).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (i). <ref href="/us/pl/116/283/s9002/c/2/D">Pub. L. 116–283, § 9002(c)(2)(D)</ref>, substituted “Sector Risk Management Agency” for “Sector-Specific Agency”.</p>
<p style="-uslm-lc:I21" class="indent0">2020—Subsec. (c)(10). <ref href="/us/pl/116/260/s904/b/1/A/i">Pub. L. 116–260, § 904(b)(1)(A)(i)</ref>, as amended by <ref href="/us/pl/117/81/s1547/b/1/B">Pub. L. 117–81, § 1547(b)(1)(B)</ref>, struck out “and” at end.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(11), (12). <ref href="/us/pl/116/260/s904/b/1/A/ii">Pub. L. 116–260, § 904(b)(1)(A)(ii)</ref>, (iii), as amended by <ref href="/us/pl/117/81/s1547/b/1/B">Pub. L. 117–81, § 1547(b)(1)(B)</ref>, added par. (11) relating to the .gov internet domain and redesignated former par. (11) relating to carrying out such other duties and powers as (12).</p>
</note>
<note style="-uslm-lc:I74" role="crossHeading" topic="statutoryNotes" id="idea6b040f-6371-11ee-b880-a1730754906d"><heading class="centered"><b>Statutory Notes and Related Subsidiaries</b></heading></note>
<note style="-uslm-lc:I74" topic="effectiveDateOfAmendment" id="idea6b0410-6371-11ee-b880-a1730754906d"><heading class="centered smallCaps">Effective Date of 2022 Amendment</heading><p><ref href="/us/pl/117/263/dG/tLXXI/s7143/a/2">Pub. L. 117–263, div. G, title LXXI, § 7143(a)(2)</ref>, <date date="2022-12-23">Dec. 23, 2022</date>, <ref href="/us/stat/136/3654">136 Stat. 3654</ref>, provided that: <quotedContent origin="/us/pl/117/263/dG/tLXXI/s7143/a/2">“The amendment made by paragraph (1) [amending this section and <ref href="/us/usc/t6/s665">section 665 of this title</ref>] shall take effect as if enacted as part of the DOTGOV Act of 2020 (title IX of division U of <ref href="/us/pl/116/260">Public Law 116–260</ref>).”</quotedContent>
</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idea6b0411-6371-11ee-b880-a1730754906d"><heading class="centered smallCaps">Construction of 2022 Amendment</heading><p style="-uslm-lc:I21" class="indent0">Nothing in amendment made by <ref href="/us/pl/117/263">Pub. L. 117–263</ref> to be construed to alter the authorities, responsibilities, functions, or activities of any agency (as such term is defined in <ref href="/us/usc/t44/s3502">44 U.S.C. 3502</ref>) or officer or employee of the United States on or before <date date="2022-12-23">Dec. 23, 2022</date>, see <ref href="/us/pl/117/263/s7143/f/1">section 7143(f)(1) of Pub. L. 117–263</ref>, set out as a note under <ref href="/us/usc/t6/s650">section 650 of this title</ref>.</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idea6d7412-6371-11ee-b880-a1730754906d"><heading class="centered smallCaps">Construction of 2021 Amendment</heading><p style="-uslm-lc:I21" class="indent0">Amendment by <ref href="/us/pl/116/283/s1717/a/1/A">section 1717(a)(1)(A) of Pub. L. 116–283</ref> not to be construed to affect or otherwise modify the authority of Federal law enforcement agencies with respect to investigations relating to cybersecurity incidents, see <ref href="/us/pl/116/283/s1717/a/4">section 1717(a)(4) of Pub. L. 116–283</ref>, set out as a note under <ref href="/us/usc/t6/s665c">section 665c of this title</ref>.</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idea6d7413-6371-11ee-b880-a1730754906d"><heading class="centered smallCaps">National Cybersecurity Preparedness Consortium</heading><p><ref href="/us/pl/117/122">Pub. L. 117–122</ref>, <date date="2022-05-12">May 12, 2022</date>, <ref href="/us/stat/136/1193">136 Stat. 1193</ref>, provided that:<quotedContent origin="/us/pl/117/122">
<section style="-uslm-lc:I580467"><num value="1">“SECTION 1.</num><heading> SHORT TITLE.</heading><content><p style="-uslm-lc:I21" class="indent0">“This Act may be cited as the ‘National Cybersecurity Preparedness Consortium Act of 2021’.</p>
</content>
</section>
<section style="-uslm-lc:I580467"><num value="2">“SEC. 2.</num><heading> NATIONAL CYBERSECURITY PREPAREDNESS CONSORTIUM.</heading><subsection style="-uslm-lc:I21" class="indent0"><num value="a">“(a)</num><heading> <inline class="small-caps">In General</inline>.—</heading><content>The Secretary may work with one or more consortia to support efforts to address cybersecurity risks and incidents.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="b">“(b)</num><heading> <inline class="small-caps">Assistance to DHS</inline>.—</heading><chapeau>The Secretary may work with one or more consortia to carry out the Secretary’s responsibility pursuant to section 2202(e)(1)(P) of the Homeland Security Act of 2002 (<ref href="/us/usc/t6/s652/e/1/P">6 U.S.C. 652(e)(1)(P)</ref>) to—</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> provide training and education to State, Tribal, and local first responders and officials specifically for preparing for and responding to cybersecurity risks and incidents, in accordance with applicable law;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> develop and update a curriculum utilizing existing training and educational programs and models in accordance with section 2209 of the Homeland Security Act of 2002 (<ref href="/us/usc/t6/s659">6 U.S.C. 659</ref>), for State, Tribal, and local first responders and officials, related to cybersecurity risks and incidents;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><content> provide technical assistance services, training, and educational programs to build and sustain capabilities in support of preparedness for and response to cybersecurity risks and incidents, including threats of acts of terrorism, in accordance with such section 2209;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="4">“(4)</num><content> conduct cross-sector cybersecurity training, education, and simulation exercises for entities, including State and local governments and Tribal organizations, critical infrastructure owners and operators, and private industry, to encourage community-wide coordination in defending against and responding to cybersecurity risks and incidents, in accordance with section 2210(c) of the Homeland Security Act of 2002 (<ref href="/us/usc/t6/s660/c">6 U.S.C. 660(c)</ref>);</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="5">“(5)</num><content> help States, Tribal organizations, and communities develop cybersecurity information sharing programs, in accordance with section 2209 of the Homeland Security Act of 2002 (<ref href="/us/usc/t6/s659">6 U.S.C. 659</ref>), for the dissemination of homeland security information related to cybersecurity risks and incidents;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="6">“(6)</num><content> help incorporate cybersecurity risk and incident prevention and response into existing State, Tribal, and local emergency plans, including continuity of operations plans; and</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="7">“(7)</num><content> assist State governments and Tribal organizations in developing cybersecurity plans.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="c">“(c)</num><heading> <inline class="small-caps">Considerations Regarding Selection of a Consortium</inline>.—</heading><chapeau>In selecting a consortium with which to work under this Act, the Secretary shall take into consideration the following:</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> Prior experience conducting cybersecurity training, education, and exercises for State and local entities.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> Geographic diversity of the members of any such consortium so as to maximize coverage of the different regions of the United States.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><content> The participation in such consortium of one or more historically Black colleges and universities, Hispanic-serving institutions, Tribal Colleges and Universities, other minority-serving institutions, and community colleges that participate in the National Centers of Excellence in Cybersecurity program, as carried out by the Department of Homeland Security.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="d">“(d)</num><heading> <inline class="small-caps">Metrics</inline>.—</heading><content>If the Secretary works with a consortium under subsection (a), the Secretary shall measure the effectiveness of the activities undertaken by the consortium under this Act.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="e">“(e)</num><heading> <inline class="small-caps">Outreach</inline>.—</heading><content>The Secretary shall conduct outreach to universities and colleges, including, in particular, outreach to historically Black colleges and universities, Hispanic-serving institutions, Tribal Colleges and Universities, other minority-serving institutions, and community colleges, regarding opportunities to support efforts to address cybersecurity risks and incidents, by working with the Secretary under subsection (a).</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="f">“(f)</num><heading> <inline class="small-caps">Rule of Construction</inline>.—</heading><content>Nothing in this section may be construed to authorize a consortium to control or direct any law enforcement agency in the exercise of the duties of the law enforcement agency.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="g">“(g)</num><heading> <inline class="small-caps">Definitions</inline>.—</heading><chapeau>In this section—</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> the term ‘community college’ has the meaning given the term ‘junior or community college’ in section 312 of the Higher Education Act of 1965 (<ref href="/us/usc/t20/s1058">20 U.S.C. 1058</ref>);</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> the term ‘consortium’ means a group primarily composed of nonprofit entities, including academic institutions, that develop, update, and deliver cybersecurity training and education in support of homeland security;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><content> the terms ‘cybersecurity risk’ and ‘incident’ have the meanings given those terms in section 2209(a) of the Homeland Security Act of 2002 (<ref href="/us/usc/t6/s659/a">6 U.S.C. 659(a)</ref>) [see <ref href="/us/usc/t6/s650/7">6 U.S.C. 650(7)</ref>, (12)];</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="4">“(4)</num><content> the term ‘Department’ means the Department of Homeland Security;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="5">“(5)</num><content> the term ‘Hispanic-serving institution’ has the meaning given the term in section 502 of the Higher Education Act of 1965 (<ref href="/us/usc/t20/s1101a">20 U.S.C. 1101a</ref>);</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="6">“(6)</num><content> the term ‘historically Black college and university’ has the meaning given the term ‘part B institution’ in section 322 of the Higher Education Act of 1965 (<ref href="/us/usc/t20/s1061">20 U.S.C. 1061</ref>);</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="7">“(7)</num><content> the term ‘minority-serving institution’ means an institution of higher education described in section 371(a) of the Higher Education Act of 1965 (<ref href="/us/usc/t20/s1067q/a">20 U.S.C. 1067q(a)</ref>);</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="8">“(8)</num><content> the term ‘Secretary’ means the Secretary of Homeland Security;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="9">“(9)</num><content> The term ‘State’ means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the United States Virgin Islands, Guam, American Samoa, the Commonwealth of the Northern Mariana Islands, and any possession of the United States;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="10">“(10)</num><content> the term ‘Tribal Colleges and Universities’ has the meaning given the term in section 316 of the Higher Education Act of 1965 (<ref href="/us/usc/t20/s1059c">20 U.S.C. 1059c</ref>); and</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="11">“(11)</num><content> the term ‘Tribal organization’ has the meaning given the term in section 4(e) of the Indian Self-Determination and Education Assistance Act (<ref href="/us/usc/t25/s5304/e">25 U.S.C. 5304(e)</ref>).”</content>
</paragraph>
</subsection>
</section>
</quotedContent>
</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idea6d7414-6371-11ee-b880-a1730754906d"><heading class="centered smallCaps">Ransomware Vulnerability Warning Pilot Program</heading><p><ref href="/us/pl/117/103/dY/s105">Pub. L. 117–103, div. Y, § 105</ref>, <date date="2022-03-15">Mar. 15, 2022</date>, <ref href="/us/stat/136/1055">136 Stat. 1055</ref>, provided that:<quotedContent origin="/us/pl/117/103/dY/s105">
<subsection style="-uslm-lc:I21" class="indent0"><num value="a">“(a)</num><heading> <inline class="small-caps">Program</inline>.—</heading><content>Not later than 1 year after the date of enactment of this Act [<date date="2022-03-15">Mar. 15, 2022</date>], the Director [of the Cybersecurity and Infrastructure Security Agency] shall establish a ransomware vulnerability warning pilot program to leverage existing authorities and technology to specifically develop processes and procedures for, and to dedicate resources to, identifying information systems that contain security vulnerabilities associated with common ransomware attacks, and to notify the owners of those vulnerable systems of their security vulnerability.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="b">“(b)</num><heading> <inline class="small-caps">Identification of Vulnerable Systems</inline>.—</heading><chapeau>The pilot program established under subsection (a) shall—</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> identify the most common security vulnerabilities utilized in ransomware attacks and mitigation techniques; and</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> utilize existing authorities to identify information systems that contain the security vulnerabilities identified in paragraph (1).</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="c">“(c)</num><heading> <inline class="small-caps">Entity Notification.—</inline></heading><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">Identification</inline>.—</heading><content>If the Director is able to identify the entity at risk that owns or operates a vulnerable information system identified in subsection (b), the Director may notify the owner of the information system.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">No identification</inline>.—</heading><content>If the Director is not able to identify the entity at risk that owns or operates a vulnerable information system identified in subsection (b), the Director may utilize the subpoena authority pursuant to section 2209 of the Homeland Security Act of 2002 (<ref href="/us/usc/t6/s659">6 U.S.C. 659</ref>) to identify and notify the entity at risk pursuant to the procedures under that section.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><heading> <inline class="small-caps">Required information</inline>.—</heading><content>A notification made under paragraph (1) shall include information on the identified security vulnerability and mitigation techniques.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="d">“(d)</num><heading> <inline class="small-caps">Prioritization of Notifications</inline>.—</heading><content>To the extent practicable, the Director shall prioritize covered entities for identification and notification activities under the pilot program established under this section.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="e">“(e)</num><heading> <inline class="small-caps">Limitation on Procedures</inline>.—</heading><content>No procedure, notification, or other authorities utilized in the execution of the pilot program established under subsection (a) shall require an owner or operator of a vulnerable information system to take any action as a result of a notice of a security vulnerability made pursuant to subsection (c).</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="f">“(f)</num><heading> <inline class="small-caps">Rule of Construction</inline>.—</heading><content>Nothing in this section shall be construed to provide additional authorities to the Director to identify vulnerabilities or vulnerable systems.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="g">“(g)</num><heading> <inline class="small-caps">Termination</inline>.—</heading><content>The pilot program established under subsection (a) shall terminate on the date that is 4 years after the date of enactment of this Act.”</content>
</subsection>
</quotedContent>
</p>
<p style="-uslm-lc:I21" class="indent0">[For definitions of terms used in <ref href="/us/pl/117/103/dY/s105">section 105 of div. Y of Pub. L. 117–103</ref>, set out above, see <ref href="/us/usc/t6/s681">section 681 of this title</ref>, as made applicable by <ref href="/us/pl/117/103/dY/s102/1">section 102(1) of div. Y of Pub. L. 117–103</ref>, which is set out as a note under <ref href="/us/usc/t6/s665j">section 665j of this title</ref>, and see <ref href="/us/usc/t6/s650">section 650 of this title</ref>, as made applicable by <ref href="/us/pl/117/263/dG/s7143/f/2">section 7143(f)(2) of div. G of Pub. L. 117–263</ref>, which is set out as a note under <ref href="/us/usc/t6/s650">section 650 of this title</ref>.]</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idea6d7415-6371-11ee-b880-a1730754906d"><heading class="centered smallCaps">Pilot Program on Public-Private Partnerships With Internet Ecosystem Companies To Detect and Disrupt Adversary Cyber Operations</heading><p><ref href="/us/pl/117/81/dA/tXV/s1550">Pub. L. 117–81, div. A, title XV, § 1550</ref>, <date date="2021-12-27">Dec. 27, 2021</date>, <ref href="/us/stat/135/2064">135 Stat. 2064</ref>, provided that:<quotedContent origin="/us/pl/117/81/dA/tXV/s1550">
<subsection style="-uslm-lc:I21" class="indent0"><num value="a">“(a)</num><heading> <inline class="small-caps">Pilot Required</inline>.—</heading><content>Not later than one year after the date of the enactment of this Act [<date date="2021-12-27">Dec. 27, 2021</date>], the Secretary, acting through the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security and in coordination with the Secretary of Defense and the National Cyber Director, shall commence a pilot program to assess the feasibility and advisability of entering into public-private partnerships with internet ecosystem companies to facilitate, within the bounds of applicable provisions of law and such companies’ terms of service, policies, procedures, contracts, and other agreements, actions by such companies to discover and disrupt use by malicious cyber actors of the platforms, systems, services, and infrastructure of such companies.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="b">“(b)</num><heading> <inline class="small-caps">Public-private Partnerships.—</inline></heading><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">In general</inline>.—</heading><content>In carrying out the pilot program under subsection (a), the Secretary shall seek to enter into one or more public-private partnerships with internet ecosystem companies.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">Voluntary participation.—</inline></heading><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><heading> <inline class="small-caps">In general</inline>.—</heading><content>Participation by an internet ecosystem company in a public-private partnership under the pilot program, including in any activity described in subsection (c), shall be voluntary.</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><heading> <inline class="small-caps">Prohibition</inline>.—</heading><content>No funds appropriated by any Act may be used to direct, pressure, coerce, or otherwise require that any internet ecosystem company take any action on their platforms, systems, services, or infrastructure as part of the pilot program.</content>
</subparagraph>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="c">“(c)</num><heading> <inline class="small-caps">Authorized Activities</inline>.—</heading><chapeau>In carrying out the pilot program under subsection (a), the Secretary may—</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> provide assistance to a participating internet ecosystem company to develop effective know-your-customer processes and requirements;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> provide information, analytics, and technical assistance to improve the ability of participating companies to detect and prevent illicit or suspicious procurement, payment, and account creation on their own platforms, systems, services, or infrastructure;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><content> develop and socialize best practices for the collection, retention, and sharing of data by participating internet ecosystem companies to support discovery of malicious cyber activity, investigations, and attribution on the platforms, systems, services, or infrastructure of such companies;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="4">“(4)</num><content> provide to participating internet ecosystem companies actionable, timely, and relevant information, such as information about ongoing operations and infrastructure, threats, tactics, and procedures, and indicators of compromise, to enable such companies to detect and disrupt the use by malicious cyber actors of the platforms, systems, services, or infrastructure of such companies;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="5">“(5)</num><content> provide recommendations for (but not design, develop, install, operate, or maintain) operational workflows, assessment and compliance practices, and training that participating internet ecosystem companies can implement to reliably detect and disrupt the use by malicious cyber actors of the platforms, systems, services, or infrastructure of such companies;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="6">“(6)</num><content> provide recommendations for accelerating, to the greatest extent practicable, the automation of existing or implemented operational workflows to operate at line-rate in order to enable real-time mitigation without the need for manual review or action;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="7">“(7)</num><content> provide recommendations for (but not design, develop, install, operate, or maintain) technical capabilities to enable participating internet ecosystem companies to collect and analyze data on malicious activities occurring on the platforms, systems, services, or infrastructure of such companies to detect and disrupt operations of malicious cyber actors; and</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="8">“(8)</num><content> provide recommendations regarding relevant mitigations for suspected or discovered malicious cyber activity and thresholds for action.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="d">“(d)</num><heading> <inline class="small-caps">Competition Concerns</inline>.—</heading><content>Consistent with <ref href="/us/usc/t18/s1905">section 1905 of title 18</ref>, United States Code, the Secretary shall ensure that any trade secret or proprietary information of a participating internet ecosystem company made known to the Federal Government pursuant to a public-private partnership under the pilot program remains private and protected unless explicitly authorized by such company.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="e">“(e)</num><heading> <inline class="small-caps">Impartiality</inline>.—</heading><content>In carrying out the pilot program under subsection (a), the Secretary may not take any action that is intended primarily to advance the particular business interests of an internet ecosystem company but is authorized to take actions that advance the interests of the United States, notwithstanding differential impact or benefit to a given company’s or given companies’ business interests.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="f">“(f)</num><heading> <inline class="small-caps">Responsibilities.—</inline></heading><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">Secretary of homeland security</inline>.—</heading><content>The Secretary shall exercise primary responsibility for the pilot program under subsection (a), including organizing and directing authorized activities with participating Federal Government organizations and internet ecosystem companies to achieve the objectives of the pilot program.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">National cyber director</inline>.—</heading><content>The National Cyber Director shall support prioritization and cross-agency coordination for the pilot program, including ensuring appropriate participation by participating agencies and the identification and prioritization of key private sector entities and initiatives for the pilot program.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><heading> <inline class="small-caps">Secretary of defense</inline>.—</heading><content>The Secretary of Defense shall provide support and resources to the pilot program, including the provision of technical and operational expertise drawn from appropriate and relevant officials and components of the Department of Defense, including the National Security Agency, United States Cyber Command, the Chief Information Officer, the Office of the Secretary of Defense, military department Principal Cyber Advisors, and the Defense Advanced Research Projects Agency.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="g">“(g)</num><heading> <inline class="small-caps">Participation of Other Federal Government Components</inline>.—</heading><content>The Secretary may invite to participate in the pilot program required under subsection (a) the heads of such departments or agencies as the Secretary considers appropriate.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="h">“(h)</num><heading> <inline class="small-caps">Integration With Other Efforts</inline>.—</heading><chapeau>The Secretary shall ensure that the pilot program required under subsection (a) makes use of, builds upon, and, as appropriate, integrates with and does not duplicate other efforts of the Department of Homeland Security and the Department of Defense relating to cybersecurity, including the following:</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> The Joint Cyber Defense Collaborative of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> The Cybersecurity Collaboration Center and Enduring Security Framework of the National Security Agency.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="i">“(i)</num><heading> <inline class="small-caps">Rules of Construction</inline>.—</heading><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">Limitation on government access to data</inline>.—</heading><content>Nothing in this section authorizes sharing of information, including information relating to customers of internet ecosystem companies or private individuals, from an internet ecosystem company to an agency, officer, or employee of the Federal Government unless otherwise authorized by another provision of law.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">Stored communications act</inline>.—</heading><content>Nothing in this section may be construed to permit or require disclosure by a provider of a remote computing service or a provider of an electronic communication service to the public of information not otherwise permitted or required to be disclosed under chapter 121 of title 18, United States Code (commonly known as the ‘Stored Communications Act’).</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><heading> <inline class="small-caps">Third party customers</inline>.—</heading><content>Nothing in this section may be construed to require a third party, such as a customer or managed service provider of an internet ecosystem company, to participate in the pilot program under subsection (a).</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="j">“(j)</num><heading> <inline class="small-caps">Briefings.—</inline></heading><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">Initial.—</inline></heading><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><heading> <inline class="small-caps">In general</inline>.—</heading><content>Not later than one year after the date of the enactment of this Act, the Secretary, in coordination with the Secretary of Defense and the National Cyber Director, shall brief the appropriate committees of Congress on the pilot program required under subsection (a).</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><heading> <inline class="small-caps">Elements</inline>.—</heading><chapeau>The briefing required under subparagraph (A) shall include the following:</chapeau><clause style="-uslm-lc:I24" class="indent3"><num value="i">“(i)</num><content> The plans of the Secretary for the implementation of the pilot program.</content>
</clause>
<clause style="-uslm-lc:I24" class="indent3"><num value="ii">“(ii)</num><content> Identification of key priorities for the pilot program.</content>
</clause>
<clause style="-uslm-lc:I24" class="indent3"><num value="iii">“(iii)</num><content> Identification of any potential challenges in standing up the pilot program or impediments, such as a lack of liability protection, to private sector participation in the pilot program.</content>
</clause>
<clause style="-uslm-lc:I24" class="indent3"><num value="iv">“(iv)</num><content> A description of the roles and responsibilities in the pilot program of each participating Federal entity.</content>
</clause>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">Annual.—</inline></heading><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><heading> <inline class="small-caps">In general</inline>.—</heading><content>Not later than two years after the date of the enactment of this Act and annually thereafter for three years, the Secretary, in coordination with the Secretary of Defense and the National Cyber Director, shall brief the appropriate committees of Congress on the progress of the pilot program required under subsection (a).</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><heading> <inline class="small-caps">Elements</inline>.—</heading><chapeau>Each briefing required under subparagraph (A) shall include the following:</chapeau><clause style="-uslm-lc:I24" class="indent3"><num value="i">“(i)</num><content> Recommendations for addressing relevant policy, budgetary, and legislative gaps to increase the effectiveness of the pilot program.</content>
</clause>
<clause style="-uslm-lc:I24" class="indent3"><num value="ii">“(ii)</num><content> Recommendations, such as providing liability protection, for increasing private sector participation in the pilot program.</content>
</clause>
<clause style="-uslm-lc:I24" class="indent3"><num value="iii">“(iii)</num><content> A description of the challenges encountered in carrying out the pilot program, including any concerns expressed by internet ecosystem companies regarding participation in the pilot program.</content>
</clause>
<clause style="-uslm-lc:I24" class="indent3"><num value="iv">“(iv)</num><content> The findings of the Secretary with respect to the feasibility and advisability of extending or expanding the pilot program.</content>
</clause>
<clause style="-uslm-lc:I24" class="indent3"><num value="v">“(v)</num><content> Such other matters as the Secretary considers appropriate.</content>
</clause>
</subparagraph>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="k">“(k)</num><heading> <inline class="small-caps">Termination</inline>.—</heading><content>The pilot program required under subsection (a) shall terminate on the date that is five years after the date of the enactment of this Act [<date date="2021-12-27">Dec. 27, 2021</date>].</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="l">“(l)</num><heading> <inline class="small-caps">Definitions</inline>.—</heading><chapeau>In this section:</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">Appropriate committees of congress</inline>.—</heading><chapeau>The term ‘appropriate committees of Congress’ means—</chapeau><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><content> the Committee on Homeland Security and Governmental Affairs and the Committee on Armed Services of the Senate; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><content> the Committee on Homeland Security and the Committee on Armed Services of the House of Representatives.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">Internet ecosystem company</inline>.—</heading><content>The term ‘internet ecosystem company’ means a business incorporated in the United States that provides cybersecurity services, internet service, content delivery services, Domain Name Service, cloud services, mobile telecommunications services, email and messaging services, internet browser services, or such other services as the Secretary determines appropriate for the purposes of the pilot program under subsection (a).</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><heading> <inline class="small-caps">Secretary</inline>.—</heading><content>The term ‘Secretary’ means the Secretary of Homeland Security.”</content>
</paragraph>
</subsection>
</quotedContent>
</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idea6d7416-6371-11ee-b880-a1730754906d"><heading class="centered smallCaps">K–12 Cybersecurity</heading><p><ref href="/us/pl/117/47">Pub. L. 117–47</ref>, <date date="2021-10-08">Oct. 8, 2021</date>, <ref href="/us/stat/135/397">135 Stat. 397</ref>, provided that:<quotedContent origin="/us/pl/117/47">
<section style="-uslm-lc:I580467"><num value="1">“SECTION 1.</num><heading> SHORT TITLE.</heading><content><p style="-uslm-lc:I21" class="indent0">“This Act may be cited as the ‘K–12 Cybersecurity Act of 2021’.</p>
</content>
</section>
<section style="-uslm-lc:I580467"><num value="2">“SEC. 2.</num><heading> FINDINGS.</heading><chapeau style="-uslm-lc:I21" class="indent0">“Congress finds the following:</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> K–12 educational institutions across the United States are facing cyber attacks.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><chapeau> Cyber attacks place the information systems of K–12 educational institutions at risk of possible disclosure of sensitive student and employee information, including—</chapeau><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><content> grades and information on scholastic development;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><content> medical records;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="C">“(C)</num><content> family records; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="D">“(D)</num><content> personally identifiable information.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><content> Providing K–12 educational institutions with resources to aid cybersecurity efforts will help K–12 educational institutions prevent, detect, and respond to cyber events.</content>
</paragraph>
</section>
<section style="-uslm-lc:I580467"><num value="3">“SEC. 3.</num><heading> K–12 EDUCATION CYBERSECURITY INITIATIVE.</heading><subsection style="-uslm-lc:I21" class="indent0"><num value="a">“(a)</num><heading> <inline class="small-caps">Definitions</inline>.—</heading><chapeau>In this section:</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">Cybersecurity risk</inline>.—</heading><content>The term ‘cybersecurity risk’ has the meaning given the term in section 2209 of the Homeland Security Act of 2002 (<ref href="/us/usc/t6/s659">6 U.S.C. 659</ref>) [see <ref href="/us/usc/t6/s650">6 U.S.C. 650</ref>].</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">Director</inline>.—</heading><content>The term ‘Director’ means the Director of Cybersecurity and Infrastructure Security.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><heading> <inline class="small-caps">Information system</inline>.—</heading><content>The term ‘information system’ has the meaning given the term in <ref href="/us/usc/t44/s3502">section 3502 of title 44</ref>, United States Code.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="4">“(4)</num><heading> K–12 <inline class="small-caps">educational institution</inline>.—</heading><content>The term ‘K–12 educational institution’ means an elementary school or a secondary school, as those terms are defined in section 8101 of the Elementary and Secondary Education Act of 1965 (<ref href="/us/usc/t20/s7801">20 U.S.C. 7801</ref>).</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="b">“(b)</num><heading> <inline class="small-caps">Study.—</inline></heading><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">In general</inline>.—</heading><chapeau>Not later than 120 days after the date of enactment of this Act [<date date="2021-10-08">Oct. 8, 2021</date>], the Director, in accordance with subsection (g)(1), shall conduct a study on the specific cybersecurity risks facing K–12 educational institutions that—</chapeau><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><content> analyzes how identified cybersecurity risks specifically impact K–12 educational institutions;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><chapeau> includes an evaluation of the challenges K–12 educational institutions face in—</chapeau><clause style="-uslm-lc:I24" class="indent3"><num value="i">“(i)</num><chapeau> securing—</chapeau><subclause style="-uslm-lc:I36" class="indent4 firstIndent-4"><num value="I">     “(I)</num><content> information systems owned, leased, or relied upon by K–12 educational institutions; and</content>
</subclause>
<subclause style="-uslm-lc:I36" class="indent4 firstIndent-4"><num value="II">     “(II)</num><content> sensitive student and employee records; and</content>
</subclause>
</clause>
<clause style="-uslm-lc:I24" class="indent3"><num value="ii">“(ii)</num><content> implementing cybersecurity protocols;</content>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="C">“(C)</num><content> identifies cybersecurity challenges relating to remote learning; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="D">“(D)</num><content> evaluates the most accessible ways to communicate cybersecurity recommendations and tools.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">Congressional briefing</inline>.—</heading><content>Not later than 120 days after the date of enactment of this Act, the Director shall provide a Congressional briefing on the study conducted under paragraph (1).</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="c">“(c)</num><heading> <inline class="small-caps">Cybersecurity Recommendations</inline>.—</heading><content>Not later than 60 days after the completion of the study required under subsection (b)(1), the Director, in accordance with subsection (g)(1), shall develop recommendations that include cybersecurity guidelines designed to assist K–12 educational institutions in facing the cybersecurity risks described in subsection (b)(1), using the findings of the study.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="d">“(d)</num><heading> <inline class="small-caps">Online Training Toolkit</inline>.—</heading><chapeau>Not later than 120 days after the completion of the development of the recommendations required under subsection (c), the Director shall develop an online training toolkit designed for officials at K–12 educational institutions to—</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> educate the officials about the cybersecurity recommendations developed under subsection (c); and</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> provide strategies for the officials to implement the recommendations developed under subsection (c).</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="e">“(e)</num><heading> <inline class="small-caps">Public Availability</inline>.—</heading><chapeau>The Director shall make available on the website of the Department of Homeland Security with other information relating to school safety the following:</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> The findings of the study conducted under subsection (b)(1).</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> The cybersecurity recommendations developed under subsection (c).</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><content> The online training toolkit developed under subsection (d).</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="f">“(f)</num><heading> <inline class="small-caps">Voluntary Use</inline>.—</heading><content>The use of the cybersecurity recommendations developed under [subsection] (c) by K–12 educational institutions shall be voluntary.</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="g">“(g)</num><heading> <inline class="small-caps">Consultation</inline>.—</heading><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">In general</inline>.—</heading><chapeau>In the course of the conduction of the study required under subsection (b)(1) and the development of the recommendations required under subsection (c), the Director shall consult with individuals and entities focused on cybersecurity and education, as appropriate, including—</chapeau><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><content> teachers;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><content> school administrators;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="C">“(C)</num><content> Federal agencies;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="D">“(D)</num><content> non-Federal cybersecurity entities with experience in education issues; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="E">“(E)</num><content> private sector organizations.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">Inapplicability of faca</inline>.—</heading><content>The Federal Advisory Committee Act ([former] 5 U.S.C App.) [see <ref href="/us/usc/t5/s1001">5 U.S.C. 1001</ref> et seq.] shall not apply to any consultation under paragraph (1).”</content>
</paragraph>
</subsection>
</section>
</quotedContent>
</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="idea6d7417-6371-11ee-b880-a1730754906d"><heading class="centered smallCaps">Under Secretary Responsible for Overseeing Critical Infrastructure Protection, Cybersecurity and Related Programs Authorized To Serve as Director of Cybersecurity and Infrastructure Security</heading><p><ref href="/us/pl/115/278/s2/b/1">Pub. L. 115–278, § 2(b)(1)</ref>, <date date="2018-11-16">Nov. 16, 2018</date>, <ref href="/us/stat/132/4175">132 Stat. 4175</ref>, provided that: <quotedContent origin="/us/pl/115/278/s2/b/1">“The individual serving as the Under Secretary appointed pursuant to section 103(a)(1)(H) of the Homeland Security Act of 2002 (<ref href="/us/usc/t6/s113/a/1/H">6 U.S.C. 113(a)(1)(H)</ref>) of the Department of Homeland Security on the day before the date of enactment of this Act [<date date="2018-11-16">Nov. 16, 2018</date>] may continue to serve as the Director of Cybersecurity and Infrastructure Security of the Department on and after such date.”</quotedContent>
</p>
</note>
</notes>
</section>