<section xmlns="http://xml.house.gov/schemas/uslm/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dcterms="http://purl.org/dc/terms/" style="-uslm-lc:I80" id="id2aa8a48e-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671"><num value="671">§ 671.</num><heading> Definitions</heading>
<chapeau style="-uslm-lc:I11" class="indent0">In this part:</chapeau><paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2aa8a48f-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/1"><num value="1" class="bold">(1)</num><heading class="bold"> Agency</heading><content><p style="-uslm-lc:I12" class="indent1">The term “agency” has the meaning given it in <ref href="/us/usc/t5/s551">section 551 of title 5</ref>.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2aa8a490-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/2"><num value="2" class="bold">(2)</num><heading class="bold"> Covered Federal agency</heading><content><p style="-uslm-lc:I12" class="indent1">The term “covered Federal agency” means the Department of Homeland Security.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2aa8a491-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/3"><num value="3" class="bold">(3)</num><heading class="bold"> Critical infrastructure information</heading><chapeau>The term “critical infrastructure information” means information not customarily in the public domain and related to the security of critical infrastructure or protected systems—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id2aa8a492-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/3/A"><num value="A">(A)</num><content> actual, potential, or threatened interference with, attack on, compromise of, or incapacitation of critical infrastructure or protected systems by either physical or computer-based attack or other similar conduct (including the misuse of or unauthorized access to all types of communications and data transmission systems) that violates Federal, State, or local law, harms interstate commerce of the United States, or threatens public health or safety;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2aa8caa3-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/3/B"><num value="B">(B)</num><content> the ability of any critical infrastructure or protected system to resist such interference, compromise, or incapacitation, including any planned or past assessment, projection, or estimate of the vulnerability of critical infrastructure or a protected system, including security testing, risk evaluation thereto, risk management planning, or risk audit; or</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2aa8caa4-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/3/C"><num value="C">(C)</num><content> any planned or past operational problem or solution regarding critical infrastructure or protected systems, including repair, recovery, reconstruction, insurance, or continuity, to the extent it is related to such interference, compromise, or incapacitation.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2aa8caa5-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/4"><num value="4" class="bold">(4)</num><heading class="bold"> Critical infrastructure protection program</heading><content><p style="-uslm-lc:I12" class="indent1">The term “critical infrastructure protection program” means any component or bureau of a covered Federal agency that has been designated by the President or any agency head to receive critical infrastructure information.</p>
</content>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2aa8caa6-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/5"><num value="5" class="bold">(5)</num><heading class="bold"> Information Sharing and Analysis Organization</heading><chapeau>The term “Information Sharing and Analysis Organization” means any formal or informal entity or collaboration created or employed by public or private sector organizations, for purposes of—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id2aa8caa7-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/5/A"><num value="A">(A)</num><content> gathering and analyzing critical infrastructure information, including information related to cybersecurity risks and incidents, in order to better understand security problems and interdependencies related to critical infrastructure, including cybersecurity risks and incidents, and protected systems, so as to ensure the availability, integrity, and reliability thereof;</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2aa8caa8-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/5/B"><num value="B">(B)</num><content> communicating or disclosing critical infrastructure information, including cybersecurity risks and incidents, to help prevent, detect, mitigate, or recover from the effects of a <ref class="footnoteRef" idref="fn002078">1</ref><note type="footnote" id="fn002078"><num>1</num> So in original. Probably should be “an”.</note> interference, compromise, or a <ref class="footnoteRef" idref="fn002079">2</ref><note type="footnote" id="fn002079"><num>2</num> So in original. The word “a” probably should not appear.</note> incapacitation problem related to critical infrastructure, including cybersecurity risks and incidents, or protected systems; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2aa8f1b9-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/5/C"><num value="C">(C)</num><content> voluntarily disseminating critical infrastructure information, including cybersecurity risks and incidents, to its members, State, local, and Federal Governments, or any other entities that may be of assistance in carrying out the purposes specified in subparagraphs (A) and (B).</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2aa8f1ba-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/6"><num value="6" class="bold">(6)</num><heading class="bold"> Protected system</heading><chapeau>The term “protected system”—</chapeau><subparagraph style="-uslm-lc:I13" class="indent2" id="id2aa8f1bb-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/6/A"><num value="A">(A)</num><content> means any service, physical or computer-based system, process, or procedure that directly or indirectly affects the viability of a facility of critical infrastructure; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I13" class="indent2" id="id2aa8f1bc-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/6/B"><num value="B">(B)</num><content> includes any physical or computer-based system, including a computer, computer system, computer or communications network, or any component hardware or element thereof, software program, processing instructions, or information or data in transmission or storage therein, irrespective of the medium of transmission or storage.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2aa8f1bd-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/7"><num value="7" class="bold">(7)</num><heading class="bold"> Voluntary</heading><subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="id2aa8f1be-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/7/A"><num value="A" class="bold">(A)</num><heading class="bold"> In general</heading><content><p style="-uslm-lc:I13" class="indent2">The term “voluntary”, in the case of any submittal of critical infrastructure information to a covered Federal agency, means the submittal thereof in the absence of such agency’s exercise of legal authority to compel access to or submission of such information and may be accomplished by a single entity or an Information Sharing and Analysis Organization on behalf of itself or its members.</p>
</content>
</subparagraph>
<subparagraph style="-uslm-lc:I18" class="indent4 firstIndent-2" id="id2aa8f1bf-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/7/B"><num value="B" class="bold">(B)</num><heading class="bold"> Exclusions</heading><chapeau>The term “voluntary”—</chapeau><clause style="-uslm-lc:I14" class="indent3" id="id2aa8f1c0-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/7/B/i"><num value="i">(i)</num><chapeau> in the case of any action brought under the securities laws as is defined in <ref href="/us/usc/t15/s78c/a/47">section 78c(a)(47) of title 15</ref>—</chapeau><subclause style="-uslm-lc:I16" class="indent4" id="id2aa8f1c1-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/7/B/i/I"><num value="I">(I)</num><content> does not include information or statements contained in any documents or materials filed with the Securities and Exchange Commission, or with Federal banking regulators, pursuant to section 78<i>l</i>(i) of title 15; and</content>
</subclause>
<subclause style="-uslm-lc:I16" class="indent4" id="id2aa8f1c2-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/7/B/i/II"><num value="II">(II)</num><content> with respect to the submittal of critical infrastructure information, does not include any disclosure or writing that when made accompanied the solicitation of an offer or a sale of securities; and</content>
</subclause>
</clause>
<clause style="-uslm-lc:I14" class="indent3" id="id2aa918d3-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/7/B/ii"><num value="ii">(ii)</num><content> does not include information or statements submitted or relied upon as a basis for making licensing or permitting determinations, or during regulatory proceedings.</content>
</clause>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I79" class="indent3 firstIndent-2" id="id2aa918d4-ec4e-11e9-8160-d29560e3776b" identifier="/us/usc/t6/s671/8"><num value="8" class="bold">(8)</num><heading class="bold"> Cybersecurity risk; incident</heading><content><p style="-uslm-lc:I12" class="indent1">The terms “cybersecurity risk” and “incident” have the meanings given those terms in <ref href="/us/usc/t6/s659">section 659 of this title</ref>.</p>
</content>
</paragraph>
<sourceCredit id="id2aa918d5-ec4e-11e9-8160-d29560e3776b">(<ref href="/us/pl/107/296/tXXII/s2222">Pub. L. 107–296, title XXII, § 2222</ref>, formerly title II, § 212, <date date="2002-11-25">Nov. 25, 2002</date>, <ref href="/us/stat/116/2150">116 Stat. 2150</ref>; <ref href="/us/pl/114/113/dN/tII/s204">Pub. L. 114–113, div. N, title II, § 204</ref>, <date date="2015-12-18">Dec. 18, 2015</date>, <ref href="/us/stat/129/2961">129 Stat. 2961</ref>; renumbered title XXII, § 2222, and amended <ref href="/us/pl/115/278/s2/g/2/H">Pub. L. 115–278, § 2(g)(2)(H)</ref>, (9)(B)(i), <date date="2018-11-16">Nov. 16, 2018</date>, <ref href="/us/stat/132/4178">132 Stat. 4178</ref>, 4181.)</sourceCredit>
<notes type="uscNote" id="id2aa918d6-ec4e-11e9-8160-d29560e3776b">
<note style="-uslm-lc:I76" topic="codification" id="id2aa918d7-ec4e-11e9-8160-d29560e3776b"><heading class="centered smallCaps">Codification</heading>
<p style="-uslm-lc:I21" class="indent0">Section was formerly classified to <ref href="/us/usc/t6/s131">section 131 of this title</ref> prior to renumbering by <ref href="/us/pl/115/278">Pub. L. 115–278</ref>.</p>
</note>
<note style="-uslm-lc:I74" topic="amendments" id="id2aa918d8-ec4e-11e9-8160-d29560e3776b"><heading class="centered smallCaps">Amendments</heading><p style="-uslm-lc:I21" class="indent0">2018—Par. (8). <ref href="/us/pl/115/278/s2/g/9/B/i">Pub. L. 115–278, § 2(g)(9)(B)(i)</ref>, substituted “<ref href="/us/usc/t6/s659">section 659 of this title</ref>” for “<ref href="/us/usc/t6/s148">section 148 of this title</ref>”.</p>
<p style="-uslm-lc:I21" class="indent0">2015—Par. (5)(A). <ref href="/us/pl/114/113/s204/1/A">Pub. L. 114–113, § 204(1)(A)</ref>, inserted “, including information related to cybersecurity risks and incidents,” after “critical infrastructure information” and “, including cybersecurity risks and incidents,” after “related to critical infrastructure”.</p>
<p style="-uslm-lc:I21" class="indent0">Par. (5)(B). <ref href="/us/pl/114/113/s204/1/B">Pub. L. 114–113, § 204(1)(B)</ref>, inserted “, including cybersecurity risks and incidents,” after “critical infrastructure information” and “, including cybersecurity risks and incidents,” after “related to critical infrastructure”.</p>
<p style="-uslm-lc:I21" class="indent0">Par. (5)(C). <ref href="/us/pl/114/113/s204/1/C">Pub. L. 114–113, § 204(1)(C)</ref>, inserted “, including cybersecurity risks and incidents,” after “critical infrastructure information”.</p>
<p style="-uslm-lc:I21" class="indent0">Par. (8). <ref href="/us/pl/114/113/s204/2">Pub. L. 114–113, § 204(2)</ref>, added par. (8).</p>
</note>
<note style="-uslm-lc:I74" topic="shortTitle" id="id2aa918d9-ec4e-11e9-8160-d29560e3776b"><heading class="centered smallCaps">Short Title</heading><p style="-uslm-lc:I21" class="indent0">For short title of this part as the “Critical Infrastructure Information Act of 2002”, see <ref href="/us/pl/107/296/s2221">section 2221 of Pub. L. 107–296</ref>, set out as a note under <ref href="/us/usc/t6/s101">section 101 of this title</ref>.</p>
</note>
<note style="-uslm-lc:I74" topic="miscellaneous" id="id2aa918da-ec4e-11e9-8160-d29560e3776b"><heading class="centered smallCaps">Prohibition on New Regulatory Authority</heading><p><ref href="/us/pl/114/113/dN/tII/s210">Pub. L. 114–113, div. N, title II, § 210</ref>, <date date="2015-12-18">Dec. 18, 2015</date>, <ref href="/us/stat/129/2962">129 Stat. 2962</ref>, provided that: <quotedContent origin="/us/pl/114/113/dN/tII/s210">“Nothing in this subtitle [subtitle A (§§ 201–211) of title II of div. N of <ref href="/us/pl/114/113">Pub. L. 114–113</ref>, see Short Title of 2015 Amendment note set out under <ref href="/us/usc/t6/s101">section 101 of this title</ref>] or the amendments made by this subtitle may be construed to grant the Secretary any authority to promulgate regulations or set standards relating to the cybersecurity of non-Federal entities, not including State, local, and tribal governments, that was not in effect on the day before the date of enactment of this Act [<date date="2015-12-18">Dec. 18, 2015</date>].”</quotedContent>
</p>
</note>
<note style="-uslm-lc:I74" topic="definitions" id="id2aa93feb-ec4e-11e9-8160-d29560e3776b"><heading class="centered smallCaps">Definitions</heading><p><ref href="/us/pl/114/113/dN/tII/s202">Pub. L. 114–113, div. N, title II, § 202</ref>, <date date="2015-12-18">Dec. 18, 2015</date>, <ref href="/us/stat/129/2956">129 Stat. 2956</ref>, as amended by <ref href="/us/pl/115/278/s2/h/1/A">Pub. L. 115–278, § 2(h)(1)(A)</ref>, <date date="2018-11-16">Nov. 16, 2018</date>, <ref href="/us/stat/132/4181">132 Stat. 4181</ref>, provided that: <quotedContent origin="/us/pl/115/278/s2/h/1/A">
<inline>“In this subtitle [subtitle A (§§ 201–211) of title II of div. N of <ref href="/us/pl/114/113">Pub. L. 114–113</ref>, see Short Title of 2015 Amendment note set out under <ref href="/us/usc/t6/s101">section 101 of this title</ref>]:</inline>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="1">“(1)</num><heading> <inline class="small-caps">Appropriate congressional committees</inline>.—</heading><chapeau>The term ‘appropriate congressional committees’ means—</chapeau><subparagraph style="-uslm-lc:I23" class="indent2"><num value="A">“(A)</num><content> the Committee on Homeland Security and Governmental Affairs of the Senate; and</content>
</subparagraph>
<subparagraph style="-uslm-lc:I23" class="indent2"><num value="B">“(B)</num><content> the Committee on Homeland Security of the House of Representatives.</content>
</subparagraph>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="2">“(2)</num><heading> <inline class="small-caps">Cybersecurity risk; incident</inline>.—</heading><content>The terms ‘cybersecurity risk’ and ‘incident’ have the meanings given those terms in section 2209 of the Homeland Security Act of 2002 [<ref href="/us/usc/t6/s659">6 U.S.C. 659</ref>].</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="3">“(3)</num><heading> <inline class="small-caps">Cyber threat indicator; defensive measure</inline>.—</heading><content>The terms ‘cyber threat indicator’ and ‘defensive measure’ have the meanings given those terms in section 102 [<ref href="/us/usc/t6/s1501">6 U.S.C. 1501</ref>].</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="4">“(4)</num><heading> <inline class="small-caps">Department</inline>.—</heading><content>The term ‘Department’ means the Department of Homeland Security.</content>
</paragraph>
<paragraph style="-uslm-lc:I22" class="indent1"><num value="5">“(5)</num><heading> <inline class="small-caps">Secretary</inline>.—</heading><content>The term ‘Secretary’ means the Secretary of Homeland Security.”</content>
</paragraph>
</quotedContent>
</p>
</note>
</notes>
</section>