<section xmlns="http://xml.house.gov/schemas/uslm/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" style="-uslm-lc:I80" id="id2966ab4f-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660"><num value="660">§ 660.</num><heading> Cybersecurity plans</heading><subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id2966ab50-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/a"><num value="a" class="bold">(a)</num><heading class="bold"> Definitions</heading><chapeau style="-uslm-lc:I11" class="indent0">In this section—</chapeau><paragraph style="-uslm-lc:I12" class="indent1" id="id2966ab51-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/a/1"><num value="1">(1)</num><content> the term “agency information system” means an information system used or operated by an agency or by another entity on behalf of an agency;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id2966ab52-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/a/2"><num value="2">(2)</num><content> the terms “cybersecurity risk” and “information system” have the meanings given those terms in <ref href="/us/usc/t6/s659">section 659 of this title</ref>;</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id2966ab53-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/a/3"><num value="3">(3)</num><content> the term “intelligence community” has the meaning given the term in <ref href="/us/usc/t50/s3003/4">section 3003(4) of title 50</ref>; and</content>
</paragraph>
<paragraph style="-uslm-lc:I12" class="indent1" id="id2966ab54-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/a/4"><num value="4">(4)</num><content> the term “national security system” has the meaning given the term in <ref href="/us/usc/t40/s11103">section 11103 of title 40</ref>.</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id2966ab55-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/b"><num value="b" class="bold">(b)</num><heading class="bold"> Intrusion assessment plan</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2966ab56-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/b/1"><num value="1" class="bold">(1)</num><heading class="bold"> Requirement</heading><chapeau style="-uslm-lc:I12" class="indent1">The Secretary, in coordination with the Director of the Office of Management and Budget, shall—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab57-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/b/1/A"><num value="A">(A)</num><content> develop and implement an intrusion assessment plan to proactively detect, identify, and remove intruders in agency information systems on a routine basis; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab58-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/b/1/B"><num value="B">(B)</num><content> update such plan as necessary.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2966ab59-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/b/2"><num value="2" class="bold">(2)</num><heading class="bold"> Exception</heading><content><p style="-uslm-lc:I12" class="indent1">The intrusion assessment plan required under paragraph (1) shall not apply to the Department of Defense, a national security system, or an element of the intelligence community.</p>
</content>
</paragraph>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id2966ab5a-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/c"><num value="c" class="bold">(c)</num><heading class="bold"> Cyber incident response plan</heading><content><p style="-uslm-lc:I11" class="indent0">The Director of Cybersecurity and Infrastructure Security shall, in coordination with appropriate Federal departments and agencies, State and local governments, sector coordinating councils, information sharing and analysis organizations (as defined in <ref href="/us/usc/t6/s671/5">section 671(5) of this title</ref>), owners and operators of critical infrastructure, and other appropriate entities and individuals, develop, update not less often than biennially, maintain, and exercise adaptable cyber incident response plans to address cybersecurity risks (as defined in <ref href="/us/usc/t6/s659">section 659 of this title</ref>) to critical infrastructure. The Director, in consultation with relevant Sector Risk Management Agencies and the National Cyber Director, shall develop mechanisms to engage with stakeholders to educate such stakeholders regarding Federal Government cybersecurity roles and responsibilities for cyber incident response.</p>
</content>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id2966ab5b-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/d"><num value="d" class="bold">(d)</num><heading class="bold"> National Response Framework</heading><content><p style="-uslm-lc:I11" class="indent0">The Secretary, in coordination with the heads of other appropriate Federal departments and agencies, and in accordance with the National Cybersecurity Incident Response Plan required under subsection (c), shall regularly update, maintain, and exercise the Cyber Incident Annex to the National Response Framework of the Department.</p>
</content>
</subsection>
<subsection style="-uslm-lc:I19" class="indent2 firstIndent-2" id="id2966ab5c-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e"><num value="e" class="bold">(e)</num><heading class="bold"> Homeland Security Strategy to Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments</heading><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2966ab5d-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/1"><num value="1" class="bold">(1)</num><heading class="bold"> In general</heading><subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="id2966ab5e-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/1/A"><num value="A" class="bold">(A)</num><heading class="bold"> Requirement</heading><content><p style="-uslm-lc:I13" class="indent2">Not later than one year after <date date="2021-12-27">December 27, 2021</date>, the Secretary, acting through the Director, shall, in coordination with the heads of appropriate Federal agencies, State, local, Tribal, and territorial governments, and other stakeholders, as appropriate, develop and make publicly available a Homeland Security Strategy to Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments.</p>
</content>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="id2966ab5f-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/1/B"><num value="B" class="bold">(B)</num><heading class="bold"> Recommendations and requirements</heading><content><p style="-uslm-lc:I13" class="indent2">The strategy required under subparagraph (A) shall provide recommendations relating to the ways in which the Federal Government should support and promote the ability of State, local, Tribal, and territorial governments to identify, mitigate against, protect against, detect, respond to, and recover from cybersecurity risks (as such term is defined in <ref href="/us/usc/t6/s659">section 659 of this title</ref>), cybersecurity threats, and incidents (as such term is defined in <ref href="/us/usc/t6/s659">section 659 of this title</ref>).</p>
</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2966ab60-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2"><num value="2" class="bold">(2)</num><heading class="bold"> Contents</heading><chapeau style="-uslm-lc:I12" class="indent1">The strategy required under paragraph (1) shall—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab61-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2/A"><num value="A">(A)</num><content> identify capability gaps in the ability of State, local, Tribal, and territorial governments to identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab62-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2/B"><num value="B">(B)</num><content> identify Federal resources and capabilities that are available or could be made available to State, local, Tribal, and territorial governments to help those governments identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab63-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2/C"><num value="C">(C)</num><content> identify and assess the limitations of Federal resources and capabilities available to State, local, Tribal, and territorial governments to help those governments identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents and make recommendations to address such limitations;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab64-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2/D"><num value="D">(D)</num><chapeau> identify opportunities to improve the coordination of the Agency with Federal and non-Federal entities, such as the Multi-State Information Sharing and Analysis Center, to improve—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="id2966ab65-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2/D/i"><num value="i">(i)</num><content> incident exercises, information sharing and incident notification procedures;</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id2966ab66-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2/D/ii"><num value="ii">(ii)</num><content> the ability for State, local, Tribal, and territorial governments to voluntarily adapt and implement guidance in Federal binding operational directives; and</content>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id2966ab67-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2/D/iii"><num value="iii">(iii)</num><content> opportunities to leverage Federal schedules for cybersecurity investments under <ref href="/us/usc/t40/s502">section 502 of title 40</ref>;</content>
</clause>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab68-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2/E"><num value="E">(E)</num><content> recommend new initiatives the Federal Government should undertake to improve the ability of State, local, Tribal, and territorial governments to identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab69-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2/F"><num value="F">(F)</num><content> set short-term and long-term goals that will improve the ability of State, local, Tribal, and territorial governments to identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab6a-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/2/G"><num value="G">(G)</num><content> set dates, including interim benchmarks, as appropriate for State, local, Tribal, and territorial governments to establish baseline capabilities to identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, incidents, and ransomware incidents.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2966ab6b-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/3"><num value="3" class="bold">(3)</num><heading class="bold"> Considerations</heading><chapeau style="-uslm-lc:I12" class="indent1">In developing the strategy required under paragraph (1), the Director, in coordination with the heads of appropriate Federal agencies, State, local, Tribal, and territorial governments, and other stakeholders, as appropriate, shall consider—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab6c-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/3/A"><num value="A">(A)</num><content> lessons learned from incidents that have affected State, local, Tribal, and territorial governments, and exercises with Federal and non-Federal entities;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab6d-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/3/B"><num value="B">(B)</num><content> the impact of incidents that have affected State, local, Tribal, and territorial governments, including the resulting costs to such governments;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab6e-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/3/C"><num value="C">(C)</num><content> the information related to the interest and ability of state and non-state threat actors to compromise information systems (as such term is defined in <ref href="/us/usc/t6/s1501">section 1501 of this title</ref>) owned or operated by State, local, Tribal, and territorial governments; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2966ab6f-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/3/D"><num value="D">(D)</num><content> emerging cybersecurity risks and cybersecurity threats to State, local, Tribal, and territorial governments resulting from the deployment of new technologies.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2966ab70-a6d2-11ec-b715-952873bb6ea0" identifier="/us/usc/t6/s660/e/4"><num value="4" class="bold">(4)</num><heading class="bold"> Exemption</heading><content><p style="-uslm-lc:I12" class="indent1">Chapter 35 of title 44 (commonly known as the “Paperwork Reduction Act”) shall not apply to any action to implement this subsection.</p>
</content>
</paragraph>
</subsection>
<sourceCredit id="id2966ab71-a6d2-11ec-b715-952873bb6ea0">(<ref href="/us/pl/107/296/tXXII/s2210">Pub. L. 107–296, title XXII, § 2210</ref>, formerly title II, § 228, as added and amended <ref href="/us/pl/114/113/dN/tII">Pub. L. 114–113, div. N, title II</ref>, §§ 205, 223(a)(2), (4), (5), <date date="2015-12-18">Dec. 18, 2015</date>, <ref href="/us/stat/129/2961">129 Stat. 2961</ref>, 2963, 2964; renumbered title XXII, § 2210, and amended <ref href="/us/pl/115/278/s2/g/2/I">Pub. L. 115–278, § 2(g)(2)(I)</ref>, (9)(A)(iv), <date date="2018-11-16">Nov. 16, 2018</date>, <ref href="/us/stat/132/4178">132 Stat. 4178</ref>, 4181; <ref href="/us/pl/117/81/dA/tXV">Pub. L. 117–81, div. A, title XV</ref>, §§ 1545, 1546, <date date="2021-12-27">Dec. 27, 2021</date>, <ref href="/us/stat/135/2057">135 Stat. 2057</ref>, 2059.)</sourceCredit>
<notes type="uscNote" id="id2966ab72-a6d2-11ec-b715-952873bb6ea0">
<note style="-uslm-lc:I74" role="crossHeading" topic="editorialNotes" id="id2966ab73-a6d2-11ec-b715-952873bb6ea0"><heading class="centered"><b>Editorial Notes</b></heading></note>
<note style="-uslm-lc:I76" topic="codification" id="id2966ab74-a6d2-11ec-b715-952873bb6ea0"><heading class="centered smallCaps">Codification</heading>
<p style="-uslm-lc:I21" class="indent0">Section was formerly classified to <ref href="/us/usc/t6/s149">section 149 of this title</ref> prior to renumbering by <ref href="/us/pl/115/278">Pub. L. 115–278</ref>.</p>
<p style="-uslm-lc:I21" class="indent0">Former <ref href="/us/usc/t6/s149">section 149 of this title</ref>, which was transferred and redesignated as subsec. (c) of this section by <ref href="/us/pl/114/113/dN/tII/s223/a/2">Pub. L. 114–113, div. N, title II, § 223(a)(2)</ref>, <date date="2015-12-18">Dec. 18, 2015</date>, <ref href="/us/stat/129/2963">129 Stat. 2963</ref>, was based on <ref href="/us/pl/107/296/tII/s227">Pub. L. 107–296, title II, § 227</ref>, as added by <ref href="/us/pl/113/282/s7/a">Pub. L. 113–282, § 7(a)</ref>, <date date="2014-12-18">Dec. 18, 2014</date>, <ref href="/us/stat/128/3070">128 Stat. 3070</ref>.</p>
</note>
<note style="-uslm-lc:I74" topic="amendments" id="id2966ab75-a6d2-11ec-b715-952873bb6ea0"><heading class="centered smallCaps">Amendments</heading><p style="-uslm-lc:I21" class="indent0">2021—Subsec. (c). <ref href="/us/pl/117/81/s1546">Pub. L. 117–81, § 1546</ref>, substituted “update not less often than biennially” for “regularly update” and inserted “The Director, in consultation with relevant Sector Risk Management Agencies and the National Cyber Director, shall develop mechanisms to engage with stakeholders to educate such stakeholders regarding Federal Government cybersecurity roles and responsibilities for cyber incident response.” at end.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (e). <ref href="/us/pl/117/81/s1545">Pub. L. 117–81, § 1545</ref>, added subsec. (e).</p>
<p style="-uslm-lc:I21" class="indent0">2018—Subsec. (a)(2). <ref href="/us/pl/115/278/s2/g/9/A/iv/I">Pub. L. 115–278, § 2(g)(9)(A)(iv)(I)</ref>, substituted “<ref href="/us/usc/t6/s659">section 659 of this title</ref>” for “<ref href="/us/usc/t6/s148">section 148 of this title</ref>”.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (c). <ref href="/us/pl/115/278/s2/g/9/A/iv">Pub. L. 115–278, § 2(g)(9)(A)(iv)</ref>, substituted “Director of Cybersecurity and Infrastructure Security” for “Under Secretary appointed under <ref href="/us/usc/t6/s113/a/1/H">section 113(a)(1)(H) of this title</ref>”, “<ref href="/us/usc/t6/s671/5">section 671(5) of this title</ref>” for “<ref href="/us/usc/t6/s131/5">section 131(5) of this title</ref>”, and “<ref href="/us/usc/t6/s659">section 659 of this title</ref>” for “<ref href="/us/usc/t6/s148">section 148 of this title</ref>”.</p>
<p style="-uslm-lc:I21" class="indent0">2015—Subsec. (c). <ref href="/us/pl/114/113/s223/a/5">Pub. L. 114–113, § 223(a)(5)</ref>, made technical amendment to reference in original act which appears in text as reference to <ref href="/us/usc/t6/s148">section 148 of this title</ref>.</p>
<p style="-uslm-lc:I21" class="indent0"><ref href="/us/pl/114/113/s223/a/2">Pub. L. 114–113, § 223(a)(2)</ref>, transferred former <ref href="/us/usc/t6/s149">section 149 of this title</ref> to subsec. (c) of this section. See Codification note above.</p>
<p style="-uslm-lc:I21" class="indent0">Subsec. (d). <ref href="/us/pl/114/113/s205">Pub. L. 114–113, § 205</ref>, added subsec. (d).</p>
</note>
<note style="-uslm-lc:I74" role="crossHeading" topic="statutoryNotes" id="id2966ab76-a6d2-11ec-b715-952873bb6ea0"><heading class="centered"><b>Statutory Notes and Related Subsidiaries</b></heading></note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="id2966ab77-a6d2-11ec-b715-952873bb6ea0"><heading class="centered smallCaps">Rule of Construction</heading><p><ref href="/us/pl/113/282/s7/c">Pub. L. 113–282, § 7(c)</ref>, <date date="2014-12-18">Dec. 18, 2014</date>, <ref href="/us/stat/128/3072">128 Stat. 3072</ref>, provided that: <quotedContent origin="/us/pl/113/282/s7/c">“Nothing in the amendment made by subsection (a) [enacting subsec. (c) of this section and <ref href="/us/usc/t6/s150">section 150 of this title</ref>] or in subsection (b)(1) [formerly classified as a note under <ref href="/us/usc/t44/s3543">section 3543 of Title 44</ref>, Public Printing and Documents, see now <ref href="/us/pl/113/283/s2/d/1">section 2(d)(1) of Pub. L. 113–283</ref>, set out as a note under <ref href="/us/usc/t44/s3553">section 3553 of Title 44</ref>] shall be construed to alter any authority of a Federal agency or department.”</quotedContent>
</p>
</note>
</notes>
</section>