National cybersecurity and communications integration center
Definitions
In this section—
the term “cybersecurity risk”—
means threats to and vulnerabilities of information or information systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information or information systems, including such related consequences caused by an act of terrorism; and
does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement;
the terms “cyber threat indicator” and “defensive measure” have the meanings given those terms in section 102 of the Cybersecurity Act of 2015 [6 U.S.C. 1501];
the term “incident” means an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or actually or imminently jeopardizes, without lawful authority, an information system;
the term “information sharing and analysis organization” has the meaning given that term in section 131(5) of this title;
the term “information system” has the meaning given that term in section 3502(8) of title 44; and
the term “sharing” (including all conjugations thereof) means providing, receiving, and disseminating (including all conjugations of each of such terms).
Center
Functions
The cybersecurity functions of the Center shall include—
being a Federal civilian interface for the multi-directional and cross-sector sharing of information related to cyber threat indicators, defensive measures, cybersecurity risks, incidents, analysis, and warnings for Federal and non-Federal entities, including the implementation of title I of the Cybersecurity Act of 2015 [6 U.S.C. 1501 et seq.];
providing shared situational awareness to enable real-time, integrated, and operational actions across the Federal Government and non-Federal entities to address cybersecurity risks and incidents to Federal and non-Federal entities;
coordinating the sharing of information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents across the Federal Government;
facilitating cross-sector coordination to address cybersecurity risks and incidents, including cybersecurity risks and incidents that may be related or could have consequential impacts across multiple sectors;
conducting integration and analysis, including cross-sector integration and analysis, of cyber threat indicators, defensive measures, cybersecurity risks, and incidents; and
sharing the analysis conducted under subparagraph (A) with Federal and non-Federal entities;
upon request, providing timely technical assistance, risk management support, and incident response capabilities to Federal and non-Federal entities with respect to cyber threat indicators, defensive measures, cybersecurity risks, and incidents, which may include attribution, mitigation, and remediation;
providing information and recommendations on security and resilience measures to Federal and non-Federal entities, including information and recommendations to—
facilitate information security;
strengthen information systems against cybersecurity risks and incidents; and
sharing 1
engaging with international partners, in consultation with other appropriate agencies, to—
collaborate on cyber threat indicators, defensive measures, and information related to cybersecurity risks and incidents; and
enhance the security and resilience of global cybersecurity;
sharing cyber threat indicators, defensive measures, and other information related to cybersecurity risks and incidents with Federal and non-Federal entities, including across sectors of critical infrastructure and with State and major urban area fusion centers, as appropriate;
participating, as appropriate, in national exercises run by the Department; and
in coordination with the Office of Emergency Communications of the Department, assessing and evaluating consequence, vulnerability, and threat information regarding cyber incidents to public safety communications to help facilitate continuous improvements to the security and resiliency of such communications.
Composition
In general
The Center shall be composed of—
appropriate representatives of Federal entities, such as—
sector-specific agencies;
civilian and law enforcement agencies; and
elements of the intelligence community, as that term is defined under section 3003(4) of title 50;
appropriate representatives of non-Federal entities, such as—
State, local, and tribal governments;
information sharing and analysis organizations, including information sharing and analysis centers;
owners and operators of critical information systems; and
private entities;
components within the Center that carry out cybersecurity and communications activities;
a designated Federal official for operational coordination with and across each sector;
an entity that collaborates with State and local governments on cybersecurity risks and incidents, and has entered into a voluntary information sharing relationship with the Center; and
other appropriate representatives or entities, as determined by the Secretary.
Incidents
Principles
In carrying out the functions under subsection (c), the Center shall ensure—
to the extent practicable, that—
timely, actionable, and relevant cyber threat indicators, defensive measures, and information related to cybersecurity risks, incidents, and analysis is shared;
when appropriate, cyber threat indicators, defensive measures, and information related to cybersecurity risks, incidents, and analysis is integrated with other relevant information and tailored to the specific characteristics of a sector;
activities are prioritized and conducted based on the level of risk;
industry sector-specific, academic, and national laboratory expertise is sought and receives appropriate consideration;
continuous, collaborative, and inclusive coordination occurs—
across sectors; and
with—
sector coordinating councils;
information sharing and analysis organizations; and
other appropriate non-Federal partners;
as appropriate, the Center works to develop and use mechanisms for sharing information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents that are technology-neutral, interoperable, real-time, cost-effective, and resilient;
the Center works with other agencies to reduce unnecessarily duplicative sharing of information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents; and; 2
the Center designates an agency contact for non-Federal entities;
that information related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents is appropriately safeguarded against unauthorized access or disclosure; and
that activities conducted by the Center comply with all policies, regulations, and laws that protect the privacy and civil liberties of United States persons, including by working with the Privacy Officer appointed under section 142 of this title to ensure that the Center follows the policies and procedures specified in subsections (b) and (d)(5)(C) of section 105 of the Cybersecurity Act of 2015 [6 U.S.C. 1504].
No right or benefit
In general
Certain assistance or information
Automated information sharing
In general
Annual report
Voluntary information sharing procedures
Procedures
In general
National security
Voluntary information sharing relationships
A voluntary information sharing relationship under this subsection may be characterized as an agreement described in this paragraph.
Standard agreement
Negotiated agreement
Existing agreements
Direct reporting
Reports on international cooperation
Outreach
Not later than 60 days after
disseminate to the public information about how to voluntarily share cyber threat indicators and defensive measures with the Center; and
enhance outreach to critical infrastructure owners and operators for purposes of such sharing.
Cybersecurity outreach
In general
Definitions
Coordinated vulnerability disclosure
Source
(Pub. L. 107–296, title II, § 227, formerly § 226, as added Pub. L. 113–282, § 3(a),Notes
References in Text
Prior Provisions
Amendments
Rules of Construction
Prohibition on New Regulatory Authority.—
Nothing in this Act [see section 1 of Pub. L. 113–282, set out as a Short Title of 2014 Amendment note under section 101 of this title] or the amendments made by this Act shall be construed to grant the Secretary [of Homeland Security] any authority to promulgate regulations or set standards relating to the cybersecurity of private sector critical infrastructure that was not in effect on the day before the date of enactment of this Act [
Private Entities.—
Nothing in this Act or the amendments made by this Act shall be construed to require any private entity—
to request assistance from the Secretary; or
that requested such assistance from the Secretary to implement any measure or recommendation suggested by the Secretary.”
Definitions
the term ‘Center’ means the national cybersecurity and communications integration center under section 226 [renumbered 227 by section 223(a)(3) of Pub. L. 114–113] of the Homeland Security Act of 2002 [6 U.S.C. 148], as added by section 3;
the term ‘critical infrastructure’ has the meaning given that term in section 2 of the Homeland Security Act of 2002 (6 U.S.C. 101);
the term ‘cybersecurity risk’ has the meaning given that term in section 226 of the Homeland Security Act of 2002, as added by section 3;
the term ‘information sharing and analysis organization’ has the meaning given that term in section 212(5) of the Homeland Security Act of 2002 (6 U.S.C. 131(5));
the term ‘information system’ has the meaning given that term in section 3502(8) of title 44, United States Code; and
the term ‘Secretary’ means the Secretary of Homeland Security.”