Information and Analysis and Infrastructure Protection
Intelligence and analysis and infrastructure protection
Under Secretary for Intelligence and Analysis and Assistant Secretary for Infrastructure Protection
Office of Intelligence and Analysis
Chief Intelligence Officer
Office of Infrastructure Protection
Discharge of responsibilities
Responsibilities of Secretary relating to intelligence and analysis and infrastructure protection
The responsibilities of the Secretary relating to intelligence and analysis and infrastructure protection shall be as follows:
To access, receive, and analyze law enforcement information, intelligence information, and other information from agencies of the Federal Government, State and local government agencies (including law enforcement agencies), and private sector entities, and to integrate such information, in support of the mission responsibilities of the Department and the functions of the National Counterterrorism Center established under section 119 of the National Security Act of 1947 [50 U.S.C. 3056], in order to—
identify and assess the nature and scope of terrorist threats to the homeland;
detect and identify threats of terrorism against the United States; and
understand such threats in light of actual and potential vulnerabilities of the homeland.
To carry out comprehensive assessments of the vulnerabilities of the key resources and critical infrastructure of the United States, including the performance of risk assessments to determine the risks posed by particular types of terrorist attacks within the United States (including an assessment of the probability of success of such attacks and the feasibility and potential efficacy of various countermeasures to such attacks).
To integrate relevant information, analysis, and vulnerability assessments (regardless of whether such information, analysis or assessments are provided by or produced by the Department) in order to—
identify priorities for protective and support measures regarding terrorist and other threats to homeland security by the Department, other agencies of the Federal Government, State, and local government agencies and authorities, the private sector, and other entities; and
prepare finished intelligence and information products in both classified and unclassified formats, as appropriate, whenever reasonably expected to be of benefit to a State, local, or tribal government (including a State, local, or tribal law enforcement agency) or a private sector entity.
To ensure, pursuant to section 122 of this title, the timely and efficient access by the Department to all information necessary to discharge the responsibilities under this section, including obtaining such information from other agencies of the Federal Government.
To develop a comprehensive national plan for securing the key resources and critical infrastructure of the United States, including power production, generation, and distribution systems, information technology and telecommunications systems (including satellites), electronic financial and property record storage and transmission systems, emergency preparedness communications systems, and the physical and technological assets that support such systems.
To recommend measures necessary to protect the key resources and critical infrastructure of the United States in coordination with other agencies of the Federal Government and in cooperation with State and local government agencies and authorities, the private sector, and other entities.
To review, analyze, and make recommendations for improvements to the policies and procedures governing the sharing of information within the scope of the information sharing environment established under section 485 of this title, including homeland security information, terrorism information, and weapons of mass destruction information, and any policies, guidelines, procedures, instructions, or standards established under that section.
To disseminate, as appropriate, information analyzed by the Department within the Department, to other agencies of the Federal Government with responsibilities relating to homeland security, and to agencies of State and local governments and private sector entities with such responsibilities in order to assist in the deterrence, prevention, preemption of, or response to, terrorist attacks against the United States.
To consult with the Director of National Intelligence and other appropriate intelligence, law enforcement, or other elements of the Federal Government to establish collection priorities and strategies for information, including law enforcement-related information, relating to threats of terrorism against the United States through such means as the representation of the Department in discussions regarding requirements and priorities in the collection of such information.
To consult with State and local governments and private sector entities to ensure appropriate exchanges of information, including law enforcement-related information, relating to threats of terrorism against the United States.
To ensure that—
any material received pursuant to this chapter is protected from unauthorized disclosure and handled and used only for the performance of official duties; and
any intelligence information under this chapter is shared, retained, and disseminated consistent with the authority of the Director of National Intelligence to protect intelligence sources and methods under the National Security Act of 1947 [50 U.S.C. 3001 et seq.] and related procedures and, as appropriate, similar authorities of the Attorney General concerning sensitive law enforcement information.
To request additional information from other agencies of the Federal Government, State and local government agencies, and the private sector relating to threats of terrorism in the United States, or relating to other areas of responsibility assigned by the Secretary, including the entry into cooperative agreements through the Secretary to obtain such information.
To establish and utilize, in conjunction with the chief information officer of the Department, a secure communications and information technology infrastructure, including data-mining and other advanced analytical tools, in order to access, receive, and analyze data and information in furtherance of the responsibilities under this section, and to disseminate information acquired and analyzed by the Department, as appropriate.
To ensure, in conjunction with the chief information officer of the Department, that any information databases and analytical tools developed or utilized by the Department—
are compatible with one another and with relevant information databases of other agencies of the Federal Government; and
treat information in such databases in a manner that complies with applicable Federal law on privacy.
To coordinate training and other support to the elements and personnel of the Department, other agencies of the Federal Government, and State and local governments that provide information to the Department, or are consumers of information provided by the Department, in order to facilitate the identification and sharing of information revealed in their ordinary duties and the optimal utilization of information received from the Department.
To coordinate with elements of the intelligence community and with Federal, State, and local law enforcement agencies, and the private sector, as appropriate.
To provide intelligence and information analysis and support to other elements of the Department.
To coordinate and enhance integration among the intelligence components of the Department, including through strategic oversight of the intelligence activities of such components.
To establish the intelligence collection, processing, analysis, and dissemination priorities, policies, processes, standards, guidelines, and procedures for the intelligence components of the Department, consistent with any directions from the President and, as applicable, the Director of National Intelligence.
To establish a structure and process to support the missions and goals of the intelligence components of the Department.
To ensure that, whenever possible, the Department—
produces and disseminates unclassified reports and analytic products based on open-source information; and
produces and disseminates such reports and analytic products contemporaneously with reports or analytic products concerning the same or similar information that the Department produced and disseminated in a classified format.
To establish within the Office of Intelligence and Analysis an internal continuity of operations plan.
Based on intelligence priorities set by the President, and guidance from the Secretary and, as appropriate, the Director of National Intelligence—
to provide to the heads of each intelligence component of the Department guidance for developing the budget pertaining to the activities of such component; and
to present to the Secretary a recommendation for a consolidated budget for the intelligence components of the Department, together with any comments from the heads of such components.
To perform such other duties relating to such responsibilities as the Secretary may provide.
To prepare and submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security in the House of Representatives, and to other appropriate congressional committees having jurisdiction over the critical infrastructure or key resources, for each sector identified in the National Infrastructure Protection Plan, a report on the comprehensive assessments carried out by the Secretary of the critical infrastructure and key resources of the United States, evaluating threat, vulnerability, and consequence, as required under this subsection. Each such report—
shall contain, if applicable, actions or countermeasures recommended or taken by the Secretary or the head of another Federal agency to address issues identified in the assessments;
shall be required for fiscal year 2007 and each subsequent fiscal year and shall be submitted not later than 35 days after the last day of the fiscal year covered by the report; and
may be classified.
Staff
In general
Private sector analysts
Security clearances
Detail of personnel
In general
Covered agencies
The agencies referred to in this paragraph are as follows:
The Department of State.
The Central Intelligence Agency.
The Federal Bureau of Investigation.
The National Security Agency.
The National Geospatial-Intelligence Agency.
The Defense Intelligence Agency.
Any other agency of the Federal Government that the President considers appropriate.
Cooperative agreements
Basis
Functions transferred
In accordance with subchapter XII, there shall be transferred to the Secretary, for assignment to the Office of Intelligence and Analysis and the Office of Infrastructure Protection under this section, the functions, personnel, assets, and liabilities of the following:
The National Infrastructure Protection Center of the Federal Bureau of Investigation (other than the Computer Investigations and Operations Section), including the functions of the Attorney General relating thereto.
The National Communications System of the Department of Defense, including the functions of the Secretary of Defense relating thereto.
The Critical Infrastructure Assurance Office of the Department of Commerce, including the functions of the Secretary of Commerce relating thereto.
The National Infrastructure Simulation and Analysis Center of the Department of Energy and the energy security and assurance program and activities of the Department, including the functions of the Secretary of Energy relating thereto.
The Federal Computer Incident Response Center of the General Services Administration, including the functions of the Administrator of General Services relating thereto.
Source
(Pub. L. 107–296, title II, § 201,Notes
References in Text
Codification
Amendments
Effective Date of 2009 Amendment
Regulations
Cybersecurity Collaboration Between the Department of Defense and the Department of Homeland Security
Interdepartmental Collaboration.—
In general.—
The Secretary of Defense and the Secretary of Homeland Security shall provide personnel, equipment, and facilities in order to increase interdepartmental collaboration with respect to—
strategic planning for the cybersecurity of the United States;
mutual support for cybersecurity capabilities development; and
synchronization of current operational cybersecurity mission activities.
Efficiencies.—
The collaboration provided for under paragraph (1) shall be designed—
to improve the efficiency and effectiveness of requirements formulation and requests for products, services, and technical assistance for, and coordination and performance assessment of, cybersecurity missions executed across a variety of Department of Defense and Department of Homeland Security elements; and
to leverage the expertise of each individual Department and to avoid duplicating, replicating, or aggregating unnecessarily the diverse line organizations across technology developments, operations, and customer support that collectively execute the cybersecurity mission of each Department.
Responsibilities.—
Department of homeland security.—
The Secretary of Homeland Security shall identify and assign, in coordination with the Department of Defense, a Director of Cybersecurity Coordination within the Department of Homeland Security to undertake collaborative activities with the Department of Defense.
Department of defense.—
The Secretary of Defense shall identify and assign, in coordination with the Department of Homeland Security, one or more officials within the Department of Defense to coordinate, oversee, and execute collaborative activities and the provision of cybersecurity support to the Department of Homeland Security.”
Cybersecurity Oversight
Notification of Cybersecurity Programs.—
Requirement for notification.—
Existing programs.—
Not later than 30 days after the date of the enactment of this Act [
New programs.—
Not later than 30 days after the date of the commencement of operations of a new cybersecurity program, the President shall submit to Congress a notification of such commencement that includes the documentation referred to in subparagraphs (A) through (F) of paragraph (2).
Documentation.—
A notification required by paragraph (1) for a cybersecurity program shall include—
the legal basis for the cybersecurity program;
the certification, if any, made pursuant to section 2511(2)(a)(ii)(B) of title 18, United States Code, or other statutory certification of legality for the cybersecurity program;
the concept for the operation of the cybersecurity program that is approved by the head of the appropriate department or agency of the United States;
the assessment, if any, of the privacy impact of the cybersecurity program prepared by the privacy or civil liberties protection officer or comparable officer of such department or agency;
the plan, if any, for independent audit or review of the cybersecurity program to be carried out by the head of such department or agency, in conjunction with the appropriate inspector general; and
recommendations, if any, for legislation to improve the capabilities of the United States Government to protect the cybersecurity of the United States.
Program Reports.—
Requirement for reports.—
The head of a department or agency of the United States with responsibility for a cybersecurity program for which a notification was submitted under subsection (a), in consultation with the inspector general for that department or agency, shall submit to Congress and the President a report on such cybersecurity program that includes—
the results of any audit or review of the cybersecurity program carried out under the plan referred to in subsection (a)(2)(E), if any; and
an assessment of whether the implementation of the cybersecurity program—
is in compliance with—
the legal basis referred to in subsection (a)(2)(A); and
an assessment referred to in subsection (a)(2)(D), if any;
is adequately described by the concept of operation referred to in subsection (a)(2)(C); and
includes an adequate independent audit or review system and whether improvements to such independent audit or review system are necessary.
Schedule for submission of reports.—
Existing programs.—
Not later than 180 days after the date of the enactment of this Act [
New programs.—
Not later than 120 days after the date on which a certification is submitted under subsection (a)(1)(B), and annually thereafter, the head of a department or agency of the United States with responsibility for the cybersecurity program for which such certification is submitted shall submit a report required under paragraph (1).
Cooperation and coordination.—
Cooperation.—
The head of each department or agency of the United States required to submit a report under paragraph (1) for a particular cybersecurity program, and the inspector general of each such department or agency, shall, to the extent practicable, work in conjunction with any other such head or inspector general required to submit such a report for such cybersecurity program.
Coordination.—
The heads of all of the departments and agencies of the United States required to submit a report under paragraph (1) for a particular cybersecurity program shall designate one such head to coordinate the conduct of the reports on such program.
Information Sharing Report.—
Not later than one year after the date of the enactment of this Act [
a description of how cyber-threat intelligence information, including classified information, is shared among the agencies and departments of the United States and with persons responsible for critical infrastructure;
a description of the mechanisms by which classified cyber-threat information is distributed;
an assessment of the effectiveness of cyber-threat information sharing and distribution; and
any other matters identified by either Inspector General that would help to fully inform Congress or the President regarding the effectiveness and legality of cybersecurity programs.
Personnel Details.—
Authority to detail.—
Notwithstanding any other provision of law, the head of an element of the intelligence community that is funded through the National Intelligence Program may detail an officer or employee of such element to the National Cyber Investigative Joint Task Force or to the Department of Homeland Security to assist the Task Force or the Department with cybersecurity, as jointly agreed by the head of such element and the Task Force or the Department.
Basis for detail.—
A personnel detail made under paragraph (1) may be made—
for a period of not more than three years; and
on a reimbursable or nonreimbursable basis.
Additional Plan.—
Not later than 180 days after the date of the enactment of this Act [
an assessment of the capabilities of the current workforce;
an examination of issues of recruiting, retention, and the professional development of such workforce, including the possibility of providing retention bonuses or other forms of compensation;
an assessment of the benefits of outreach and training with both private industry and academic institutions with respect to such workforce;
an assessment of the impact of the establishment of the Department of Defense Cyber Command on such workforce;
an examination of best practices for making the intelligence community workforce aware of cybersecurity best practices and principles; and
strategies for addressing such other matters as the Director of National Intelligence considers necessary to the cybersecurity of the intelligence community.
Report on Guidelines and Legislation To Improve Cybersecurity of the United States.—
Initial.—
Not later than one year after the date of the enactment of this Act [
improving the ability of the intelligence community to detect hostile actions and attribute attacks to specific parties;
the need for data retention requirements to assist the intelligence community and law enforcement agencies;
improving the ability of the intelligence community to anticipate nontraditional targets of foreign intelligence services; and
the adequacy of existing criminal statutes to successfully deter cyber attacks, including statutes criminalizing the facilitation of criminal acts, the scope of laws for which a cyber crime constitutes a predicate offense, trespassing statutes, data breach notification requirements, and victim restitution statutes.
Subsequent.—
Not later than one year after the date on which the initial report is submitted under paragraph (1), and annually thereafter for two years, the Director of National Intelligence, in consultation with the Attorney General, the Director of the National Security Agency, the White House Cybersecurity Coordinator, and any other officials the Director of National Intelligence considers appropriate, shall submit to Congress an update of the report required under paragraph (1).
Sunset.—
The requirements and authorities of subsections (a) through (e) shall terminate on
Definitions.—
In this section:
Cybersecurity program.—
The term ‘cybersecurity program’ means a class or collection of similar cybersecurity operations of a department or agency of the United States that involves personally identifiable data that is—
screened by a cybersecurity system outside of the department or agency of the United States that was the intended recipient of the personally identifiable data;
transferred, for the purpose of cybersecurity, outside the department or agency of the United States that was the intended recipient of the personally identifiable data; or
transferred, for the purpose of cybersecurity, to an element of the intelligence community.
National cyber investigative joint task force.—
The term ‘National Cyber Investigative Joint Task Force’ means the multiagency cyber investigation coordination organization overseen by the Director of the Federal Bureau of Investigation known as the National Cyber Investigative Joint Task Force that coordinates, integrates, and provides pertinent information related to cybersecurity investigations.
Critical infrastructure.—
The term ‘critical infrastructure’ has the meaning given that term in section 1016 of the USA PATRIOT Act (42 U.S.C. 5195c).”
Treatment of Incumbent Under Secretary for Intelligence and Analysis
Reports To Be Submitted to Certain Committees
Section 1016(j)(1) of the Intelligence Reform and Terrorist [Terrorism] Prevention Act of 2004 (6 U.S.C. 485(j)(1)).
Section 511(d) of this Act [121 Stat. 323].
[Former] Subsection (a)(3)(D) of section 2022 of the Homeland Security Act of 2002 [former 6 U.S.C. 612(a)(3)(D)], as added by section 101 of this Act.
Section 7215(d) of the Intelligence Reform and Terrorism Prevention Act of 2004 (6 U.S.C. 123(d)).
Section 7209(b)(1)(C) of the Intelligence Reform and Terrorism Prevention Act of 2004 [Pub. L. 108–458] (8 U.S.C. 1185 note).
Section 804(c) of this Act [42 U.S.C. 2000ee–3(c)].
Section 901(b) of this Act [121 Stat. 370].
Section 1002(a) of this Act [amending this section].
Title III of this Act [enacting sections 579 and 580 of this title and amending sections 194 and 572 of this title].”
Security Management Systems Demonstration Project
Demonstration Project Required.—
Not later than 120 days after the date of enactment of this Act [
establish a demonstration project to conduct demonstrations of security management systems that—
shall use a management system standards approach; and
may be integrated into quality, safety, environmental and other internationally adopted management systems; and
enter into one or more agreements with a private sector entity to conduct such demonstrations of security management systems.
Security Management System Defined.—
In this section, the term ‘security management system’ means a set of guidelines that address the security assessment needs of critical infrastructure and key resources that are consistent with a set of generally accepted management standards ratified and adopted by a standards making body.”