<section xmlns="http://xml.house.gov/schemas/uslm/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" style="-uslm-lc:I80" id="id6eb41e62-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659"><num value="659">§ 659.</num><heading> National cybersecurity and communications integration center</heading><subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb41e63-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/a"><num value="a" class="bold">(a)</num><heading class="bold"> Definitions</heading><chapeau>In this section—</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="id6eb41e64-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/a/1"><num value="1">(1)</num><chapeau> the term “cybersecurity risk”—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb41e65-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/a/1/A"><num value="A">(A)</num><content> means threats to and vulnerabilities of information or information systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information or information systems, including such related consequences caused by an act of terrorism; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb41e66-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/a/1/B"><num value="B">(B)</num><content> does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement;</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb41e67-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/a/2"><num value="2">(2)</num><content> the terms “cyber threat indicator” and “defensive measure” have the meanings given those terms in section 102 of the Cybersecurity Act of 2015 [<ref href="/us/usc/t6/s1501">6 U.S.C. 1501</ref>];</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb41e68-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/a/3"><num value="3">(3)</num><content> the term “incident” means an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or actually or imminently jeopardizes, without lawful authority, an information system;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb44579-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/a/4"><num value="4">(4)</num><content> the term “information sharing and analysis organization” has the meaning given that term in <ref href="/us/usc/t6/s671/5">section 671(5) of this title</ref>;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb4457a-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/a/5"><num value="5">(5)</num><content> the term “information system” has the meaning given that term in <ref href="/us/usc/t44/s3502/8">section 3502(8) of title 44</ref>; and</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb4457b-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/a/6"><num value="6">(6)</num><content> the term “sharing” (including all conjugations thereof) means providing, receiving, and disseminating (including all conjugations of each of such terms).</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb4457c-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/b"><num value="b" class="bold">(b)</num><heading class="bold"> Center</heading><content><p style="-uslm-lc:I11" class="indent0">There is in the Department a national cybersecurity and communications integration center (referred to in this section as the “Center”) to carry out certain responsibilities of the Director. The Center shall be located in the Cybersecurity and Infrastructure Security Agency. The head of the Center shall report to the Assistant Director for Cybersecurity.</p>
</content>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb4457d-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c"><num value="c" class="bold">(c)</num><heading class="bold"> Functions</heading><chapeau>The cybersecurity functions of the Center shall include—</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="id6eb4457e-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/1"><num value="1">(1)</num><content> being a Federal civilian interface for the multi-directional and cross-sector sharing of information related to cyber threat indicators, defensive measures, cybersecurity risks, incidents, analysis, and warnings for Federal and non-Federal entities, including the implementation of title I of the Cybersecurity Act of 2015 [<ref href="/us/usc/t6/s1501">6 U.S.C. 1501</ref> et seq.];</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb4457f-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/2"><num value="2">(2)</num><content> providing shared situational awareness to enable real-time, integrated, and operational actions across the Federal Government and non-Federal entities to address cybersecurity risks and incidents to Federal and non-Federal entities;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb46c90-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/3"><num value="3">(3)</num><content> coordinating the sharing of information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents across the Federal Government;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb46c91-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/4"><num value="4">(4)</num><content> facilitating cross-sector coordination to address cybersecurity risks and incidents, including cybersecurity risks and incidents that may be related or could have consequential impacts across multiple sectors;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb46c92-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/5"><num value="5">(5)</num><subparagraph style="-uslm-lc:I12" class="indent1" id="id6eb46c93-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/5/A"><num value="A">(A)</num><content> conducting integration and analysis, including cross-sector integration and analysis, of cyber threat indicators, defensive measures, cybersecurity risks, and incidents; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I12" class="indent1" id="id6eb46c94-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/5/B"><num value="B">(B)</num><content> sharing the analysis conducted under subparagraph (A) with Federal and non-Federal entities;</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb46c95-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/6"><num value="6">(6)</num><content> upon request, providing timely technical assistance, risk management support, and incident response capabilities to Federal and non-Federal entities with respect to cyber threat indicators, defensive measures, cybersecurity risks, and incidents, which may include attribution, mitigation, and remediation;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb46c96-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/7"><num value="7">(7)</num><chapeau> providing information and recommendations on security and resilience measures to Federal and non-Federal entities, including information and recommendations to—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb46c97-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/7/A"><num value="A">(A)</num><content> facilitate information security;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb46c98-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/7/B"><num value="B">(B)</num><content> strengthen information systems against cybersecurity risks and incidents; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb493a9-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/7/C"><num value="C">(C)</num><content> sharing <ref class="footnoteRef" idref="fn002093">1</ref><note type="footnote" id="fn002093"><num>1</num> So in original. Probably should be “share”.</note> cyber threat indicators and defensive measures;</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb493aa-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/8"><num value="8">(8)</num><chapeau> engaging with international partners, in consultation with other appropriate agencies, to—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb493ab-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/8/A"><num value="A">(A)</num><content> collaborate on cyber threat indicators, defensive measures, and information related to cybersecurity risks and incidents; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb493ac-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/8/B"><num value="B">(B)</num><content> enhance the security and resilience of global cybersecurity;</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb493ad-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/9"><num value="9">(9)</num><content> sharing cyber threat indicators, defensive measures, and other information related to cybersecurity risks and incidents with Federal and non-Federal entities, including across sectors of critical infrastructure and with State and major urban area fusion centers, as appropriate;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb493ae-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/10"><num value="10">(10)</num><content> participating, as appropriate, in national exercises run by the Department; and</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb493af-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/c/11"><num value="11">(11)</num><content> in coordination with the Emergency Communications Division of the Department, assessing and evaluating consequence, vulnerability, and threat information regarding cyber incidents to public safety communications to help facilitate continuous improvements to the security and resiliency of such communications.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb493b0-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d"><num value="d" class="bold">(d)</num><heading class="bold"> Composition</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb493b1-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><chapeau>The Center shall be composed of—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb493b2-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/A"><num value="A">(A)</num><chapeau> appropriate representatives of Federal entities, such as—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="id6eb493b3-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/A/i"><num value="i">(i)</num><content> sector-specific agencies;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id6eb4bac4-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/A/ii"><num value="ii">(ii)</num><content> civilian and law enforcement agencies; and</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id6eb4bac5-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/A/iii"><num value="iii">(iii)</num><content> elements of the intelligence community, as that term is defined under <ref href="/us/usc/t50/s3003/4">section 3003(4) of title 50</ref>;</content>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4bac6-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/B"><num value="B">(B)</num><chapeau> appropriate representatives of non-Federal entities, such as—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="id6eb4bac7-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/B/i"><num value="i">(i)</num><content> State, local, and tribal governments;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id6eb4bac8-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/B/ii"><num value="ii">(ii)</num><content> information sharing and analysis organizations, including information sharing and analysis centers;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id6eb4bac9-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/B/iii"><num value="iii">(iii)</num><content> owners and operators of critical information systems; and</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id6eb4baca-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/B/iv"><num value="iv">(iv)</num><content> private entities, including cybersecurity specialists;</content>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4bacb-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/C"><num value="C">(C)</num><content> components within the Center that carry out cybersecurity and communications activities;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4bacc-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/D"><num value="D">(D)</num><content> a designated Federal official for operational coordination with and across each sector;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4bacd-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/E"><num value="E">(E)</num><content> an entity that collaborates with State and local governments on cybersecurity risks and incidents, and has entered into a voluntary information sharing relationship with the Center; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4bace-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/1/F"><num value="F">(F)</num><content> other appropriate representatives or entities, as determined by the Secretary.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb4bacf-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/d/2"><num value="2" class="bold">(2)</num><heading class="bold"> Incidents</heading><content><p style="-uslm-lc:I12" class="indent1">In the event of an incident, during exigent circumstances the Secretary may grant a Federal or non-Federal entity immediate temporary access to the Center.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb4bad0-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e"><num value="e" class="bold">(e)</num><heading class="bold"> Principles</heading><chapeau>In carrying out the functions under subsection (c), the Center shall ensure—</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="id6eb4e1e1-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1"><num value="1">(1)</num><chapeau> to the extent practicable, that—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4e1e2-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/A"><num value="A">(A)</num><content> timely, actionable, and relevant cyber threat indicators, defensive measures, and information related to cybersecurity risks, incidents, and analysis is shared;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4e1e3-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/B"><num value="B">(B)</num><content> when appropriate, cyber threat indicators, defensive measures, and information related to cybersecurity risks, incidents, and analysis is integrated with other relevant information and tailored to the specific characteristics of a sector;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4e1e4-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/C"><num value="C">(C)</num><content> activities are prioritized and conducted based on the level of risk;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4e1e5-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/D"><num value="D">(D)</num><content> industry sector-specific, academic, and national laboratory expertise is sought and receives appropriate consideration;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4e1e6-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/E"><num value="E">(E)</num><chapeau> continuous, collaborative, and inclusive coordination occurs—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="id6eb4e1e7-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/E/i"><num value="i">(i)</num><content> across sectors; and</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id6eb4e1e8-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/E/ii"><num value="ii">(ii)</num><chapeau> with—</chapeau><subclause style="-uslm-lc:I16" class="indent4" id="id6eb4e1e9-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/E/ii/I"><num value="I">(I)</num><content> sector coordinating councils;</content>
</subclause>
<subclause style="-uslm-lc:I16" class="indent4" id="id6eb4e1ea-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/E/ii/II"><num value="II">(II)</num><content> information sharing and analysis organizations; and</content>
</subclause>
<subclause style="-uslm-lc:I16" class="indent4" id="id6eb4e1eb-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/E/ii/III"><num value="III">(III)</num><content> other appropriate non-Federal partners;</content>
</subclause>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4e1ec-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/F"><num value="F">(F)</num><content> as appropriate, the Center works to develop and use mechanisms for sharing information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents that are technology-neutral, interoperable, real-time, cost-effective, and resilient;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb4e1ed-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/G"><num value="G">(G)</num><content> the Center works with other agencies to reduce unnecessarily duplicative sharing of information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents; and; <ref class="footnoteRef" idref="fn002094">2</ref><note type="footnote" id="fn002094"><num>2</num> So in original. The semicolon probably should not appear.</note></content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb508fe-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/1/H"><num value="H">(H)</num><content> the Center designates an agency contact for non-Federal entities;</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb508ff-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/2"><num value="2">(2)</num><content> that information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents is appropriately safeguarded against unauthorized access or disclosure; and</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb50900-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/e/3"><num value="3">(3)</num><content> that activities conducted by the Center comply with all policies, regulations, and laws that protect the privacy and civil liberties of United States persons, including by working with the Privacy Officer appointed under <ref href="/us/usc/t6/s142">section 142 of this title</ref> to ensure that the Center follows the policies and procedures specified in subsections (b) and (d)(5)(C) of section 105 of the Cybersecurity Act of 2015 [<ref href="/us/usc/t6/s1504">6 U.S.C. 1504</ref>].</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb50901-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f"><num value="f" class="bold">(f)</num><heading class="bold"> Cyber hunt and incident response teams</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb50902-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><chapeau>The Center shall maintain cyber hunt and incident response teams for the purpose of leading Federal asset response activities and providing timely technical assistance to Federal and non-Federal entities, including across all critical infrastructure sectors, regarding actual or potential security incidents, as appropriate and upon request, including—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb50903-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/1/A"><num value="A">(A)</num><content> assistance to asset owners and operators in restoring services following a cyber incident;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb50904-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/1/B"><num value="B">(B)</num><content> identification and analysis of cybersecurity risk and unauthorized cyber activity;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb50905-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/1/C"><num value="C">(C)</num><content> mitigation strategies to prevent, deter, and protect against cybersecurity risks;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb53016-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/1/D"><num value="D">(D)</num><content> recommendations to asset owners and operators for improving overall network and control systems security to lower cybersecurity risks, and other recommendations, as appropriate; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb53017-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/1/E"><num value="E">(E)</num><content> such other capabilities as the Secretary determines appropriate.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb53018-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/2"><num value="2" class="bold">(2)</num><heading class="bold"> Associated metrics</heading><chapeau>The Center shall—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb53019-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/2/A"><num value="A">(A)</num><content> define the goals and desired outcomes for each cyber hunt and incident response team; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id6eb5301a-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/2/B"><num value="B">(B)</num><chapeau> develop metrics—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="id6eb5301b-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/2/B/i"><num value="i">(i)</num><content> to measure the effectiveness and efficiency of each cyber hunt and incident response team in achieving the goals and desired outcomes defined under subparagraph (A); and</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id6eb5301c-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/2/B/ii"><num value="ii">(ii)</num><chapeau> that—</chapeau><subclause style="-uslm-lc:I16" class="indent4" id="id6eb5301d-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/2/B/ii/I"><num value="I">(I)</num><content> are quantifiable and actionable; and</content>
</subclause>
<subclause style="-uslm-lc:I16" class="indent4" id="id6eb5301e-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/2/B/ii/II"><num value="II">(II)</num><content> the Center shall use to improve the effectiveness and accountability of, and service delivery by, cyber hunt and incident response teams.</content>
</subclause>
</clause>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb5301f-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/f/3"><num value="3" class="bold">(3)</num><heading class="bold"> Cybersecurity specialists</heading><content><p style="-uslm-lc:I12" class="indent1">After notice to, and with the approval of, the entity requesting action by or technical assistance from the Center, the Secretary may include cybersecurity specialists from the private sector on a cyber hunt and incident response team.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb53020-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/g"><num value="g" class="bold">(g)</num><heading class="bold"> No right or benefit</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb53021-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/g/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I12" class="indent1">The provision of assistance or information to, and inclusion in the Center, or any team or activity of the Center, of, governmental or private entities under this section shall be at the sole and unreviewable discretion of the Director.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb53022-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/g/2"><num value="2" class="bold">(2)</num><heading class="bold"> Certain assistance or information</heading><content><p style="-uslm-lc:I12" class="indent1">The provision of certain assistance or information to, or inclusion in the Center, or any team or activity of the Center, of, one governmental or private entity pursuant to this section shall not create a right or benefit, substantive or procedural, to similar assistance or information for any other governmental or private entity.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb55733-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/h"><num value="h" class="bold">(h)</num><heading class="bold"> Automated information sharing</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb55734-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/h/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I12" class="indent1">The Director, in coordination with industry and other stakeholders, shall develop capabilities making use of existing information technology industry standards and best practices, as appropriate, that support and rapidly advance the development, adoption, and implementation of automated mechanisms for the sharing of cyber threat indicators and defensive measures in accordance with title I of the Cybersecurity Act of 2015 [<ref href="/us/usc/t6/s1501">6 U.S.C. 1501</ref> et seq.].</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb55735-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/h/2"><num value="2" class="bold">(2)</num><heading class="bold"> Annual report</heading><content><p style="-uslm-lc:I12" class="indent1">The Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives an annual report on the status and progress of the development of the capabilities described in paragraph (1). Such reports shall be required until such capabilities are fully implemented.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb55736-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/i"><num value="i" class="bold">(i)</num><heading class="bold"> Voluntary information sharing procedures</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb55737-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/i/1"><num value="1" class="bold">(1)</num><heading class="bold"> Procedures</heading><subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="id6eb55738-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/i/1/A"><num value="A" class="bold">(A)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I13" class="indent2">The Center may enter into a voluntary information sharing relationship with any consenting non-Federal entity for the sharing of cyber threat indicators and defensive measures for cybersecurity purposes in accordance with this section. Nothing in this subsection may be construed to require any non-Federal entity to enter into any such information sharing relationship with the Center or any other entity. The Center may terminate a voluntary information sharing relationship under this subsection, at the sole and unreviewable discretion of the Secretary, acting through the Director, for any reason, including if the Center determines that the non-Federal entity with which the Center has entered into such a relationship has violated the terms of this subsection.</p>
</content>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="id6eb55739-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/i/1/B"><num value="B" class="bold">(B)</num><heading class="bold"> National security</heading><content><p style="-uslm-lc:I13" class="indent2">The Secretary may decline to enter into a voluntary information sharing relationship under this subsection, at the sole and unreviewable discretion of the Secretary, acting through the Director, for any reason, including if the Secretary determines that such is appropriate for national security.</p>
</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb57e4a-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/i/2"><num value="2" class="bold">(2)</num><heading class="bold"> Voluntary information sharing relationships</heading><chapeau>A voluntary information sharing relationship under this subsection may be characterized as an agreement described in this paragraph.</chapeau><subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="id6eb57e4b-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/i/2/A"><num value="A" class="bold">(A)</num><heading class="bold"> Standard agreement</heading><content><p style="-uslm-lc:I13" class="indent2">For the use of a non-Federal entity, the Center shall make available a standard agreement, consistent with this section, on the Department’s website.</p>
</content>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="id6eb57e4c-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/i/2/B"><num value="B" class="bold">(B)</num><heading class="bold"> Negotiated agreement</heading><content><p style="-uslm-lc:I13" class="indent2">At the request of a non-Federal entity, and if determined appropriate by the Center, at the sole and unreviewable discretion of the Secretary, acting through the Director, the Department shall negotiate a non-standard agreement, consistent with this section.</p>
</content>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="id6eb57e4d-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/i/2/C"><num value="C" class="bold">(C)</num><heading class="bold"> Existing agreements</heading><content><p style="-uslm-lc:I13" class="indent2">An agreement between the Center and a non-Federal entity that is entered into before <date date="2015-12-18">December 18, 2015</date>, or such an agreement that is in effect before such date, shall be deemed in compliance with the requirements of this subsection, notwithstanding any other provision or requirement of this subsection. An agreement under this subsection shall include the relevant privacy protections as in effect under the Cooperative Research and Development Agreement for Cybersecurity Information Sharing and Collaboration, as of <date date="2014-12-31">December 31, 2014</date>. Nothing in this subsection may be construed to require a non-Federal entity to enter into either a standard or negotiated agreement to be in compliance with this subsection.</p>
</content>
</subparagraph>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb57e4e-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/j"><num value="j" class="bold">(j)</num><heading class="bold"> Direct reporting</heading><content><p style="-uslm-lc:I11" class="indent0">The Secretary shall develop policies and procedures for direct reporting to the Secretary by the Director of the Center regarding significant cybersecurity risks and incidents.</p>
</content>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb57e4f-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/k"><num value="k" class="bold">(k)</num><heading class="bold"> Reports on international cooperation</heading><content><p style="-uslm-lc:I11" class="indent0">Not later than 180 days after <date date="2015-12-18">December 18, 2015</date>, and periodically thereafter, the Secretary of Homeland Security shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the range of efforts underway to bolster cybersecurity collaboration with relevant international partners in accordance with subsection (c)(8).</p>
</content>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb57e50-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/l"><num value="l" class="bold">(l)</num><heading class="bold"> Outreach</heading><chapeau>Not later than 60 days after <date date="2015-12-18">December 18, 2015</date>, the Secretary, acting through the Director, shall—</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="id6eb57e51-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/l/1"><num value="1">(1)</num><content> disseminate to the public information about how to voluntarily share cyber threat indicators and defensive measures with the Center; and</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id6eb57e52-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/l/2"><num value="2">(2)</num><content> enhance outreach to critical infrastructure owners and operators for purposes of such sharing.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb57e53-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/m"><num value="m" class="bold">(m)</num><heading class="bold"> Cybersecurity outreach</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb5a564-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/m/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I12" class="indent1">The Secretary may leverage small business development centers to provide assistance to small business concerns by disseminating information on cyber threat indicators, defense measures, cybersecurity risks, incidents, analyses, and warnings to help small business concerns in developing or enhancing cybersecurity infrastructure, awareness of cyber threat indicators, and cyber training programs for employees.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id6eb5a565-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/m/2"><num value="2" class="bold">(2)</num><heading class="bold"> Definitions</heading><content><p style="-uslm-lc:I12" class="indent1">For purposes of this subsection, the terms “small business concern” and “small business development center” have the meaning given such terms, respectively, under <ref href="/us/usc/t15/s632">section 632 of title 15</ref>.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id6eb5a566-a3fe-11ea-a0f5-ea66c03e78d5" identifier="/us/usc/t6/s659/n"><num value="n" class="bold">(n)</num><heading class="bold"> Coordinated vulnerability disclosure</heading><content><p style="-uslm-lc:I11" class="indent0">The Secretary, in coordination with industry and other stakeholders, may develop and adhere to Department policies and procedures for coordinating vulnerability disclosures.</p>
</content>
</subsection>
<sourceCredit id="id6eb5a567-a3fe-11ea-a0f5-ea66c03e78d5">(<ref href="/us/pl/107/296/tXXII/s2209">Pub. L. 107–296, title XXII, § 2209</ref>, formerly title II, § 227, formerly § 226, as added <ref href="/us/pl/113/282/s3/a">Pub. L. 113–282, § 3(a)</ref>, <date date="2014-12-18">Dec. 18, 2014</date>, <ref href="/us/stat/128/3066">128 Stat. 3066</ref>; renumbered § 227 and amended <ref href="/us/pl/114/113/dN/tII">Pub. L. 114–113, div. N, title II</ref>, §§ 203, 223(a)(3), <date date="2015-12-18">Dec. 18, 2015</date>, <ref href="/us/stat/129/2957">129 Stat. 2957</ref>, 2963; <ref href="/us/pl/114/328/dA/tXVIII/s1841/b">Pub. L. 114–328, div. A, title XVIII, § 1841(b)</ref>, <date date="2016-12-23">Dec. 23, 2016</date>, <ref href="/us/stat/130/2663">130 Stat. 2663</ref>; renumbered title XXII, § 2209, and amended <ref href="/us/pl/115/278/s2/g/2/I">Pub. L. 115–278, § 2(g)(2)(I)</ref>, (9)(A)(iii), <date date="2018-11-16">Nov. 16, 2018</date>, <ref href="/us/stat/132/4178">132 Stat. 4178</ref>, 4180; <ref href="/us/pl/116/94/dL/s102/a">Pub. L. 116–94, div. L, § 102(a)</ref>, <date date="2019-12-20">Dec. 20, 2019</date>, <ref href="/us/stat/133/3089">133 Stat. 3089</ref>.)</sourceCredit>
<notes type="uscNote" id="id6eb5a568-a3fe-11ea-a0f5-ea66c03e78d5">
<note style="-uslm-lc:I75" topic="referencesInText" id="id6eb5a569-a3fe-11ea-a0f5-ea66c03e78d5">
<heading class="centered smallCaps">References in Text</heading><p style="-uslm-lc:I21" class="indent0">Title I of the Cybersecurity Act of 2015, referred to in subsecs. (c)(1) and (h)(1), is title I of <ref href="/us/pl/114/113/dN">Pub. L. 114–113, div. N</ref>, <date date="2015-12-18">Dec. 18, 2015</date>, <ref href="/us/stat/129/2936">129 Stat. 2936</ref>, also known as the Cybersecurity Information Sharing Act of 2015, which is classified generally to subchapter I of chapter 6 of this title. For complete classification of title I to the Code, see Short Title note set out under <ref href="/us/usc/t6/s1501">section 1501 of this title</ref> and Tables.</p>
</note>
<note style="-uslm-lc:I76" topic="codification" id="id6eb5a56a-a3fe-11ea-a0f5-ea66c03e78d5"><heading class="centered smallCaps">Codification</heading>
<p style="-uslm-lc:I21" class="indent0">Section was formerly classified to <ref href="/us/usc/t6/s148">section 148 of this title</ref> prior to renumbering by <ref href="/us/pl/115/278">Pub. L. 115–278</ref>.</p>
</note>
<note style="-uslm-lc:I74" topic="amendments" id="id6eb5a56b-a3fe-11ea-a0f5-ea66c03e78d5"><heading class="centered smallCaps">Amendments</heading><p style="-uslm-lc:I21" class="indent0">2019—Subsec. (d)(1)(B)(iv). <ref href="/us/pl/116/94/s102/a/1">Pub. L. 116–94, § 102(a)(1)</ref>, inserted “, including cybersecurity specialists” after “entities”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (f). <ref href="/us/pl/116/94/s102/a/3">Pub. L. 116–94, § 102(a)(3)</ref>, added subsec. (f). Former subsec. (f) redesignated (g).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (g). <ref href="/us/pl/116/94/s102/a/2">Pub. L. 116–94, § 102(a)(2)</ref>, redesignated subsec. (f) as (g). Former subsec. (g) redesignated (h).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (g)(1), (2). <ref href="/us/pl/116/94/s102/a/4">Pub. L. 116–94, § 102(a)(4)</ref>, inserted “, or any team or activity of the Center,” after “Center”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsecs. (h) to (n). <ref href="/us/pl/116/94/s102/a/2">Pub. L. 116–94, § 102(a)(2)</ref>, redesignated subsecs. (g) to (m) as (h) to (n), respectively.</p>
<p style="-uslm-lc:I21" class="indent0">2018—<ref href="/us/pl/115/278/s2/g/9/A/iii/I">Pub. L. 115–278, § 2(g)(9)(A)(iii)(I)</ref>, substituted “Director” for “Under Secretary appointed under <ref href="/us/usc/t6/s113/a/1/H">section 113(a)(1)(H) of this title</ref>” wherever appearing.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (a)(4). <ref href="/us/pl/115/278/s2/g/9/A/iii/II">Pub. L. 115–278, § 2(g)(9)(A)(iii)(II)</ref>, substituted “<ref href="/us/usc/t6/s671/5">section 671(5) of this title</ref>” for “<ref href="/us/usc/t6/s131/5">section 131(5) of this title</ref>”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (b). <ref href="/us/pl/115/278/s2/g/9/A/iii/III">Pub. L. 115–278, § 2(g)(9)(A)(iii)(III)</ref>, inserted at end “The Center shall be located in the Cybersecurity and Infrastructure Security Agency. The head of the Center shall report to the Assistant Director for Cybersecurity.”</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(11). <ref href="/us/pl/115/278/s2/g/9/A/iii/IV">Pub. L. 115–278, § 2(g)(9)(A)(iii)(IV)</ref>, substituted “Emergency Communications Division” for “Office of Emergency Communications”.</p>
<p style="-uslm-lc:I21" class="indent0">2016—Subsecs. (<i>l</i>), (m). <ref href="/us/pl/114/328">Pub. L. 114–328</ref> added subsec. (<i>l</i>) and redesignated former subsec. (<i>l</i>) as (m).</p>
<p style="-uslm-lc:I21" class="indent0">2015—Subsec. (a)(1) to (5). <ref href="/us/pl/114/113/s203/1/A">Pub. L. 114–113, § 203(1)(A)</ref>, (B), added pars. (1) to (3), redesignated former pars. (3) and (4) as (4) and (5), respectively, and struck out former pars. (1) and (2), which defined “cybersecurity risk” and “incident”, respectively.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (a)(6). <ref href="/us/pl/114/113/s203/1/C">Pub. L. 114–113, § 203(1)(C)</ref>–(E), added par. (6).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(1). <ref href="/us/pl/114/113/s203/2/A">Pub. L. 114–113, § 203(2)(A)</ref>, inserted “cyber threat indicators, defensive measures,” before “cybersecurity risks” and “, including the implementation of title I of the Cybersecurity Act of 2015” before semicolon at end.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(3). <ref href="/us/pl/114/113/s203/2/B">Pub. L. 114–113, § 203(2)(B)</ref>, substituted “cyber threat indicators, defensive measures, cybersecurity risks,” for “cybersecurity risks”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(5)(A). <ref href="/us/pl/114/113/s203/2/C">Pub. L. 114–113, § 203(2)(C)</ref>, substituted “cyber threat indicators, defensive measures, cybersecurity risks,” for “cybersecurity risks”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(6). <ref href="/us/pl/114/113/s203/2/D">Pub. L. 114–113, § 203(2)(D)</ref>, substituted “cyber threat indicators, defensive measures, cybersecurity risks,” for “cybersecurity risks” and struck out “and” at end.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(7)(C). <ref href="/us/pl/114/113/s203/2/E">Pub. L. 114–113, § 203(2)(E)</ref>, added subpar. (C).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c)(8) to (11). <ref href="/us/pl/114/113/s203/2/F">Pub. L. 114–113, § 203(2)(F)</ref>, added pars. (8) to (11).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(1)(B)(i). <ref href="/us/pl/114/113/s203/3/A/i">Pub. L. 114–113, § 203(3)(A)(i)</ref>, substituted “, local, and tribal” for “and local”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(1)(B)(ii). <ref href="/us/pl/114/113/s203/3/A/ii">Pub. L. 114–113, § 203(3)(A)(ii)</ref>, substituted “, including information sharing and analysis centers;” for “; and”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(1)(B)(iv). <ref href="/us/pl/114/113/s203/3/A/iii">Pub. L. 114–113, § 203(3)(A)(iii)</ref>, (iv), added cl. (iv).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d)(1)(E), (F). <ref href="/us/pl/114/113/s203/3/B">Pub. L. 114–113, § 203(3)(B)</ref>–(D), added subpar. (E) and redesignated former subpar. (E) as (F).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (e)(1)(A). <ref href="/us/pl/114/113/s203/4/A/i">Pub. L. 114–113, § 203(4)(A)(i)</ref>, inserted “cyber threat indicators, defensive measures, and” before “information”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (e)(1)(B). <ref href="/us/pl/114/113/s203/4/A/ii">Pub. L. 114–113, § 203(4)(A)(ii)</ref>, inserted “cyber threat indicators, defensive measures, and” before “information related”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (e)(1)(F). <ref href="/us/pl/114/113/s203/4/A/iii">Pub. L. 114–113, § 203(4)(A)(iii)</ref>, substituted “cyber threat indicators, defensive measures, cybersecurity risks,” for “cybersecurity risks” and struck out “and” at end.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (e)(1)(G). <ref href="/us/pl/114/113/s203/4/A/iv">Pub. L. 114–113, § 203(4)(A)(iv)</ref>, substituted “cyber threat indicators, defensive measures, cybersecurity risks, and incidents; and” for “cybersecurity risks and incidents”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (e)(1)(H). <ref href="/us/pl/114/113/s203/4/A/v">Pub. L. 114–113, § 203(4)(A)(v)</ref>, added subpar. (H).</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (e)(2). <ref href="/us/pl/114/113/s203/4/B">Pub. L. 114–113, § 203(4)(B)</ref>, substituted “cyber threat indicators, defensive measures, cybersecurity risks,” for “cybersecurity risks” and inserted “or disclosure” after “access”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (e)(3). <ref href="/us/pl/114/113/s203/4/C">Pub. L. 114–113, § 203(4)(C)</ref>, inserted “, including by working with the Privacy Officer appointed under <ref href="/us/usc/t6/s142">section 142 of this title</ref> to ensure that the Center follows the policies and procedures specified in subsections (b) and (d)(5)(C) of section 105 of the Cybersecurity Act of 2015” before period at end.</p>
<p style="-uslm-lc:I21" class="indent0">Subsecs. (g) to (<i>l</i>). <ref href="/us/pl/114/113/s203/5">Pub. L. 114–113, § 203(5)</ref>, added subsecs. (g) to (<i>l</i>).</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="id6eb5f38c-a3fe-11ea-a0f5-ea66c03e78d5"><heading class="centered smallCaps">Rules of Construction</heading><p><ref href="/us/pl/113/282/s8">Pub. L. 113–282, § 8</ref>, <date date="2014-12-18">Dec. 18, 2014</date>, <ref href="/us/stat/128/3072">128 Stat. 3072</ref>, provided that:<quotedContent origin="/us/pl/113/282/s8">
<subsection style="-uslm-lc:I21" class="indent0"><num value="a">“(a)</num><heading> <inline class="small-caps">Prohibition on New Regulatory Authority</inline>.—</heading><content>Nothing in this Act [see <ref href="/us/pl/113/282/s1">section 1 of Pub. L. 113–282</ref>, set out as a Short Title of 2014 Amendment note under <ref href="/us/usc/t6/s101">section 101 of this title</ref>] or the amendments made by this Act shall be construed to grant the Secretary [of Homeland Security] any authority to promulgate regulations or set standards relating to the cybersecurity of private sector critical infrastructure that was not in effect on the day before the date of enactment of this Act [<date date="2014-12-18">Dec. 18, 2014</date>].</content>
</subsection>
<subsection style="-uslm-lc:I21" class="indent0"><num value="b">“(b)</num><heading> <inline class="small-caps">Private Entities</inline>.—</heading><chapeau>Nothing in this Act or the amendments made by this Act shall be construed to require any private entity—</chapeau><paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> to request assistance from the Secretary; or</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> that requested such assistance from the Secretary to implement any measure or recommendation suggested by the Secretary.”</content>
</paragraph>
</subsection>
</quotedContent>
</p>
</note>
<note style="-uslm-lc:I87" topic="definitions" id="id6eb5f38d-a3fe-11ea-a0f5-ea66c03e78d5">
<heading class="centered smallCaps">Definitions</heading>
<p><ref href="/us/pl/113/282/s2">Pub. L. 113–282, § 2</ref>, <date date="2014-12-18">Dec. 18, 2014</date>, <ref href="/us/stat/128/3066">128 Stat. 3066</ref>, provided that: <quotedContent origin="/us/pl/113/282/s2">
<inline>“In this Act [see <ref href="/us/pl/113/282/s1">section 1 of Pub. L. 113–282</ref>, set out as a Short Title of 2014 Amendment note under <ref href="/us/usc/t6/s101">section 101 of this title</ref>]—</inline>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><content> the term ‘Center’ means the national cybersecurity and communications integration center under section 226 [renumbered 227 by <ref href="/us/pl/114/113/s223/a/3">section 223(a)(3) of Pub. L. 114–113</ref> and renumbered 2209 by <ref href="/us/pl/115/278/s2/g/2/I">section 2(g)(2)(I) of Pub. L. 115–278</ref>] of the Homeland Security Act of 2002 [<ref href="/us/usc/t6/s659">6 U.S.C. 659</ref>], as added by section 3;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><content> the term ‘critical infrastructure’ has the meaning given that term in section 2 of the Homeland Security Act of 2002 (<ref href="/us/usc/t6/s101">6 U.S.C. 101</ref>);</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><content> the term ‘cybersecurity risk’ has the meaning given that term in section 226 [2209] of the Homeland Security Act of 2002, as added by section 3;</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="4">“(4)</num><content> the term ‘information sharing and analysis organization’ has the meaning given that term in section 212(5) [renumbered 2222(5) by <ref href="/us/pl/115/278/s2/g/2/H">section 2(g)(2)(H) of Pub. L. 115–278</ref>] of the Homeland Security Act of 2002 ([former] <ref href="/us/usc/t6/s131/5">6 U.S.C. 131(5)</ref>) [now <ref href="/us/usc/t6/s671/5">6 U.S.C. 671(5)</ref>];</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="5">“(5)</num><content> the term ‘information system’ has the meaning given that term in <ref href="/us/usc/t44/s3502/8">section 3502(8) of title 44</ref>, United States Code; and</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="6">“(6)</num><content> the term ‘Secretary’ means the Secretary of Homeland Security.”</content>
</paragraph>
</quotedContent>
</p>
</note>
</notes>
</section>