Definitions
Except as otherwise specifically provided, in this subchapter:
Agency
Appropriate congressional committees
The term “appropriate congressional committees” means—
the Committee on Homeland Security and Governmental Affairs of the Senate; and
the Committee on Homeland Security of the House of Representatives.
Cloud service provider
Critical infrastructure information
The term “critical infrastructure information” means information not customarily in the public domain and related to the security of critical infrastructure or protected systems—
actual, potential, or threatened interference with, attack on, compromise of, or incapacitation of critical infrastructure or protected systems by either physical or computer-based attack or other similar conduct (including the misuse of or unauthorized access to all types of communications and data transmission systems) that violates Federal, State, or local law, harms interstate commerce of the United States, or threatens public health or safety;
the ability of any critical infrastructure or protected system to resist such interference, compromise, or incapacitation, including any planned or past assessment, projection, or estimate of the vulnerability of critical infrastructure or a protected system, including security testing, risk evaluation thereto, risk management planning, or risk audit; or
any planned or past operational problem or solution regarding critical infrastructure or protected systems, including repair, recovery, reconstruction, insurance, or continuity, to the extent it is related to such interference, compromise, or incapacitation.
Cyber threat indicator
The term “cyber threat indicator” means information that is necessary to describe or identify—
malicious reconnaissance, including anomalous patterns of communications that appear to be transmitted for the purpose of gathering technical information related to a cybersecurity threat or security vulnerability;
a method of defeating a security control or exploitation of a security vulnerability;
a security vulnerability, including anomalous activity that appears to indicate the existence of a security vulnerability;
a method of causing a user with legitimate access to an information system or information that is stored on, processed by, or transiting an information system to unwittingly enable the defeat of a security control or exploitation of a security vulnerability;
malicious cyber command and control;
the actual or potential harm caused by an incident, including a description of the information exfiltrated as a result of a particular cybersecurity threat;
any other attribute of a cybersecurity threat, if disclosure of such attribute is not otherwise prohibited by law; or
any combination thereof.
Cybersecurity purpose
Cybersecurity risk
The term “cybersecurity risk”—
means threats to and vulnerabilities of information or information systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information or information systems, including such related consequences caused by an act of terrorism; and
does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.
Cybersecurity threat
In general
Exclusion
Defensive measure
In general
Exclusion
The term “defensive measure” does not include a measure that destroys, renders unusable, provides unauthorized access to, or substantially harms an information system or information stored on, processed by, or transiting such information system not owned by—
the private entity, as defined in section 1501 of this title, operating the measure; or
another entity or Federal entity that is authorized to provide consent and has provided consent to that private entity for operation of such measure.
Director
Homeland Security Enterprise
Incident
Information Sharing and Analysis Organization
The term “Information Sharing and Analysis Organization” means any formal or informal entity or collaboration created or employed by public or private sector organizations, for purposes of—
gathering and analyzing critical infrastructure information, including information related to cybersecurity risks and incidents, in order to better understand security problems and interdependencies related to critical infrastructure, including cybersecurity risks and incidents, and protected systems, so as to ensure the availability, integrity, and reliability thereof;
communicating or disclosing critical infrastructure information, including cybersecurity risks and incidents, to help prevent, detect, mitigate, or recover from the effects of an interference, a compromise, or an incapacitation problem related to critical infrastructure, including cybersecurity risks and incidents, or protected systems; and
voluntarily disseminating critical infrastructure information, including cybersecurity risks and incidents, to its members, State, local, and Federal Governments, or any other entities that may be of assistance in carrying out the purposes specified in subparagraphs (A) and (B).
Information system
The term “information system”—
has the meaning given the term in section 3502 of title 44; and
includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers.
Intelligence community
Malicious cyber command and control
Malicious reconnaissance
Managed service provider
Monitor
National cybersecurity asset response activities
The term “national cybersecurity asset response activities” means—
furnishing cybersecurity technical assistance to entities affected by cybersecurity risks to protect assets, mitigate vulnerabilities, and reduce impacts of cyber incidents;
identifying other entities that may be at risk of an incident and assessing risk to the same or similar vulnerabilities;
assessing potential cybersecurity risks to a sector or region, including potential cascading effects, and developing courses of action to mitigate such risks;
facilitating information sharing and operational coordination with threat response; and
providing guidance on how best to utilize Federal resources and capabilities in a timely, effective manner to speed recovery from cybersecurity risks.
National security system
Ransomware attack
The term “ransomware attack”—
means an incident that includes the use or threat of use of unauthorized or malicious code on an information system, or the use or threat of use of another digital mechanism such as a denial of service attack, to interrupt or disrupt the operations of an information system or compromise the confidentiality, availability, or integrity of electronic data stored on, processed by, or transiting an information system to extort a demand for a ransom payment; and
does not include any such event in which the demand for payment is—
not genuine; or
made in good faith by an entity in response to a specific request by the owner or operator of the information system.
Sector Risk Management Agency
Security control
Security vulnerability
Sharing
SLTT entity
Supply chain compromise
Source
(Pub. L. 107–296, title XXII, § 2200, as added Pub. L. 117–263, div. G, title LXXI, § 7143(b)(1),Notes
Statutory Notes and Related Subsidiaries
Rule of Construction
Interpretation of technical corrections.—
Nothing in the amendments made by subsections (a) through (d) [enacting this section and amending sections 195f, 321l, 464, 571, 624, 651 to 652a, 655, 656, 659 to 663, 665, 665b, 665d, 665g, 665i, 671, 681, 1501, 1521, and 1524 of this title, sections 278g–3a and 648 of Title 15, Commerce and Trade, section 824s–1 of Title 16, Conservation, sections 300hh–10 and 18723 of Title 42, The Public Health and Welfare, section 70101 of Title 46, Shipping, and sections 3049a and 3371a of Title 50, War and National Defense] shall be construed to alter the authorities, responsibilities, functions, or activities of any agency (as such term is defined in section 3502 of title 44, United States Code) or officer or employee of the United States on or before the date of enactment of this Act [
Interpretation of references to definitions.—
Any reference to a term defined in the Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) on the day before the date of enactment of this Act that is defined in section 2200 of that Act [6 U.S.C. 650] pursuant to the amendments made under this Act [Pub. L. 117–263, see Tables for classification] shall be deemed to be a reference to that term as defined in section 2200 of the Homeland Security Act of 2002, as added by this Act.”