<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H6024F755485B4FC1AB90698CCD0AC2DB" public-private="public">
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>111th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 5548</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20100616">June 16, 2010</action-date>
			<action-desc><sponsor name-id="H000213">Ms. Harman</sponsor> (for
			 herself and <cosponsor name-id="K000210">Mr. King of New York</cosponsor>)
			 introduced the following bill; which was referred to the
			 <committee-name committee-id="HGO00">Committee on Oversight and Government
			 Reform</committee-name>, and in addition to the Committees on
			 <committee-name committee-id="HHM00">Homeland Security</committee-name>,
			 <committee-name committee-id="">Select Intelligence (Permanent
			 Select)</committee-name>, <committee-name committee-id="HAS00">Armed
			 Services</committee-name>, <committee-name committee-id="HJU00">the
			 Judiciary</committee-name>, and <committee-name committee-id="HED00">Education
			 and Labor</committee-name>, for a period to be subsequently determined by the
			 Speaker, in each case for consideration of such provisions as fall within the
			 jurisdiction of the committee concerned</action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend the Homeland Security Act of 2002 and other laws
		  to enhance the security and resiliency of the cyber and communications
		  infrastructure of the United States.</official-title>
	</form>
	<legis-body id="HA591B2D007684542B61BEF99FFBBD3F2" style="OLC">
		<section id="H54C570C0A503489698B49074F82CECF5" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Protecting Cyberspace as a National
			 Asset Act of 2010</short-title></quote>.</text>
		</section><section id="H3C6F6E93367C4022B76145D12E7B2B52"><enum>2.</enum><header>Table of
			 contents</header><text display-inline="no-display-inline">The table of contents
			 for this Act is as follows:</text>
			<toc>
				<toc-entry idref="H54C570C0A503489698B49074F82CECF5" level="section">Sec. 1. Short title.</toc-entry>
				<toc-entry idref="H3C6F6E93367C4022B76145D12E7B2B52" level="section">Sec. 2. Table of contents.</toc-entry>
				<toc-entry idref="H51C0E48F4D5F4FE8B7B06E908460706A" level="section">Sec. 3. Definitions.</toc-entry>
				<toc-entry idref="H252E212782CD45E2B0E1C476C8D6E394" level="title">TITLE I—Office of Cyberspace Policy</toc-entry>
				<toc-entry idref="H261312BCCCCF48F791D6F85D4F9230CB" level="section">Sec. 101. Establishment of the Office of Cyberspace
				Policy.</toc-entry>
				<toc-entry idref="HB631AB65E0F54E31B51AB0129D837A10" level="section">Sec. 102. Appointment and responsibilities of the
				Director.</toc-entry>
				<toc-entry idref="H9519581AA65E474288016E6A665EB5CF" level="section">Sec. 103. Prohibition on political campaigning.</toc-entry>
				<toc-entry idref="H8BBC284E1FF649C588BD78885C9188D8" level="section">Sec. 104. Review of Federal agency budget requests relating to
				the National Strategy.</toc-entry>
				<toc-entry idref="HDAA640B18FF2462B8319A24637D7D61A" level="section">Sec. 105. Access to intelligence.</toc-entry>
				<toc-entry idref="HD4D2E7CC448C495FB529D5C138E8F688" level="section">Sec. 106. Consultation.</toc-entry>
				<toc-entry idref="H0AF1BF4AC8444AB4B0538B46FD251A0F" level="section">Sec. 107. Reports to Congress.</toc-entry>
				<toc-entry idref="HC7573B2FC267483FB27572DB418DFF37" level="title">TITLE II—National Center for Cybersecurity and
				Communications</toc-entry>
				<toc-entry idref="HF034EDD31D0B45C79AC5464C04B56FE2" level="section">Sec. 201. Cybersecurity.</toc-entry>
				<toc-entry idref="H5268324ED6EA4DA6B757D49BE5BAFDFA" level="title">TITLE III—Federal information security management</toc-entry>
				<toc-entry idref="HECA0217A83A24DA7889295CD1E8BC848" level="section">Sec. 301. Coordination of Federal information
				policy.</toc-entry>
				<toc-entry idref="HC968D53EDBFE4A039B162AD6761CE7AA" level="title">TITLE IV—Recruitment and professional development</toc-entry>
				<toc-entry idref="H226D9E15AF224164BD408FA0A41207B4" level="section">Sec. 401. Definitions.</toc-entry>
				<toc-entry idref="HE2CE352F5BFF411583F9FD926A6C68A3" level="section">Sec. 402. Assessment of cybersecurity workforce.</toc-entry>
				<toc-entry idref="H50EB2D37AB284BC897B4F1C804FB6CCC" level="section">Sec. 403. Strategic cybersecurity workforce
				planning.</toc-entry>
				<toc-entry idref="H33E56C792D1C447F8A7156C9E8737164" level="section">Sec. 404. Cybersecurity occupation classifications.</toc-entry>
				<toc-entry idref="H45ADCBF5990540D6AE1F277C30001BC8" level="section">Sec. 405. Measures of cybersecurity hiring
				effectiveness.</toc-entry>
				<toc-entry idref="HAD6BAC56375042ABAAF6D236D2AAFFBA" level="section">Sec. 406. Training and education.</toc-entry>
				<toc-entry idref="HF5B3F2B1703645259FD37282905B4C90" level="section">Sec. 407. Cybersecurity incentives.</toc-entry>
				<toc-entry idref="H7B1F29F271574420B16AF28C29927744" level="section">Sec. 408. Recruitment and retention program for the National
				Center for Cybersecurity and Communications.</toc-entry>
				<toc-entry idref="H8FE1AF45D0A44625B7092FB2A2178235" level="title">TITLE V—Other provisions</toc-entry>
				<toc-entry idref="HE433FB8EC5F548DCBE0F6AC9FA0CF4BA" level="section">Sec. 501. Consultation on cybersecurity matters.</toc-entry>
				<toc-entry idref="H5D2AA97A464E4BB496DA2BB10A878C13" level="section">Sec. 502. Cybersecurity research and development.</toc-entry>
				<toc-entry idref="HECCACA2AA61E4AD59594D6417838B3B3" level="section">Sec. 503. Prioritized critical information
				infrastructure.</toc-entry>
				<toc-entry idref="HCA572FFC068342C7A56CCBC80134E53D" level="section">Sec. 504. National Center for Cybersecurity and Communications
				acquisition authorities.</toc-entry>
				<toc-entry idref="H3D864E69EC8B486E868ACE23ACCA7C43" level="section">Sec. 505. Technical and conforming amendments.</toc-entry>
			</toc>
		</section><section id="H51C0E48F4D5F4FE8B7B06E908460706A"><enum>3.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="H33224C58D4C04AA08CDBF749C4F5390D"><enum>(1)</enum><header>Appropriate
			 congressional committees</header><text>The term <term>appropriate congressional
			 committees</term> means—</text>
				<subparagraph id="H23D5FFCCAAE44F2C88B742CBBA469AAA"><enum>(A)</enum><text>the Committee on
			 Homeland Security and Governmental Affairs of the Senate;</text>
				</subparagraph><subparagraph id="H4F634799C6D041EBACC0FEC4E3F9DA7B"><enum>(B)</enum><text>the Committee on
			 Homeland Security of the House of Representatives;</text>
				</subparagraph><subparagraph id="HA6711DB83A9F4FDE81A588CE4D2514B4"><enum>(C)</enum><text>the Committee on
			 Oversight and Government Reform of the House of Representatives; and</text>
				</subparagraph><subparagraph id="HBD56534F51E244D9BDF1F55DF6650E9E"><enum>(D)</enum><text>any other
			 congressional committee with jurisdiction over the particular matter.</text>
				</subparagraph></paragraph><paragraph id="HB1A23B0C51364014A033F3C24983FED0"><enum>(2)</enum><header>Critical
			 infrastructure</header><text>The term <term>critical infrastructure</term> has
			 the meaning given that term in section 1016(e) of the USA PATRIOT Act (42
			 U.S.C. 5195c(e)).</text>
			</paragraph><paragraph id="HED5897A61A2544259DC962CC9DBAAA80"><enum>(3)</enum><header>Cyberspace</header><text>The
			 term <term>cyberspace</term> means the interdependent network of information
			 infrastructure, and includes the Internet, telecommunications networks,
			 computer systems, and embedded processors and controllers in critical
			 industries.</text>
			</paragraph><paragraph commented="no" id="H3A814CFF7EBD428BBD73D34EAFBFA7D6"><enum>(4)</enum><header>Director</header><text>The
			 term <term>Director</term> means the Director of Cyberspace Policy established
			 under section 101.</text>
			</paragraph><paragraph id="H1F714BD778C44B2E9450E0BF49EF64FC"><enum>(5)</enum><header>Federal
			 agency</header><text>The term <term>Federal agency</term>—</text>
				<subparagraph id="H691A1D4DEE0746E3BAD4C4BEFB1150A9"><enum>(A)</enum><text>means any
			 executive department, Government corporation, Government-controlled
			 corporation, or other establishment in the executive branch of the Government
			 (including the Executive Office of the President), or any independent
			 regulatory agency; and</text>
				</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H40C9184D82A24B218C74B19DF0A6E8BF"><enum>(B)</enum><text>does not include
			 the governments of the District of Columbia and of the territories and
			 possessions of the United States and their various subdivisions.</text>
				</subparagraph></paragraph><paragraph id="HFC4D2881832F46258A73B7D8268BF79F"><enum>(6)</enum><header>Federal
			 information infrastructure</header><text>The term <term>Federal information
			 infrastructure</term>—</text>
				<subparagraph id="HD7BA1D0F070146FC876117670D0B75CD"><enum>(A)</enum><text>means information
			 infrastructure that is owned, operated, controlled, or licensed for use by, or
			 on behalf of, any Federal agency, including information systems used or
			 operated by another entity on behalf of a Federal agency; and</text>
				</subparagraph><subparagraph id="H3FD509D89F14470C93C6467A17E0859B"><enum>(B)</enum><text>does not
			 include—</text>
					<clause id="H92BAE131371F4519A42B1F96AC4F813F"><enum>(i)</enum><text>a
			 national security system; or</text>
					</clause><clause id="HFC7C600BA3AE4E739CD2C4B7B7AEC799"><enum>(ii)</enum><text>information
			 infrastructure that is owned, operated, controlled, or licensed for use by, or
			 on behalf of, the Department of Defense, a military department, or another
			 element of the intelligence community.</text>
					</clause></subparagraph></paragraph><paragraph commented="no" id="HFDF267BE365E4807B0F3B8ADBD89E105"><enum>(7)</enum><header>Incident</header><text>The
			 term <term>incident</term> means an occurrence that—</text>
				<subparagraph commented="no" id="HEF01DB91A8F1465EBC820F9B072E77C7"><enum>(A)</enum><text>actually or
			 potentially jeopardizes—</text>
					<clause commented="no" id="HAA5894E859BC42E3B5D406EFA8D2FE7E"><enum>(i)</enum><text>the information
			 security of information infrastructure; or</text>
					</clause><clause commented="no" id="HFF1F84FCDFAE4291AE3376FCCAB18100"><enum>(ii)</enum><text>the information
			 that information infrastructure processes, stores, receives, or transmits;
			 or</text>
					</clause></subparagraph><subparagraph commented="no" id="H35F87B4F346D4468AC5D48DFB3F161D9"><enum>(B)</enum><text>constitutes a
			 violation or threat of violation of security policies, security procedures, or
			 acceptable use policies applicable to information infrastructure.</text>
				</subparagraph></paragraph><paragraph id="H8071B3EDCA354E15B8784B1572B7A8EC"><enum>(8)</enum><header>Information
			 infrastructure</header><text>The term <term>information infrastructure</term>
			 means the underlying framework that information systems and assets rely on to
			 process, transmit, receive, or store information electronically, including
			 programmable electronic devices and communications networks and any associated
			 hardware, software, or data.</text>
			</paragraph><paragraph id="H719397375A7643769E5B345600504E91"><enum>(9)</enum><header>Information
			 security</header><text>The term <term>information security</term> means
			 protecting information and information systems from disruption or unauthorized
			 access, use, disclosure, modification, or destruction in order to
			 provide—</text>
				<subparagraph id="H84DD6AC9B24A45FCB34A6C6691DB0D1E"><enum>(A)</enum><text>integrity, by
			 guarding against improper information modification or destruction, including by
			 ensuring information nonrepudiation and authenticity;</text>
				</subparagraph><subparagraph id="H790040B307824597B56856BAB0869F00"><enum>(B)</enum><text>confidentiality,
			 by preserving authorized restrictions on access and disclosure, including means
			 for protecting personal privacy and proprietary information; and</text>
				</subparagraph><subparagraph id="H3F5611F4BBA2472B8C0320CD78E37DC7"><enum>(C)</enum><text>availability, by
			 ensuring timely and reliable access to and use of information.</text>
				</subparagraph></paragraph><paragraph id="H69AEDC0A51E24C6B921B5DE3E3BD190E"><enum>(10)</enum><header>Information
			 technology</header><text>The term <term>information technology</term> has the
			 meaning given that term in section 11101 of title 40, United States
			 Code.</text>
			</paragraph><paragraph id="HC58B209035164D95B2A03EE683146523"><enum>(11)</enum><header>Intelligence
			 community</header><text>The term <term>intelligence community</term> has the
			 meaning given that term under section 3(4) of the National Security Act of 1947
			 (50 U.S.C. 401a(4)).</text>
			</paragraph><paragraph id="HCCC2E4F3224943FDA2F45FB067935D41"><enum>(12)</enum><header>Key
			 resources</header><text>The term <term>key resources</term> has the meaning
			 given that term in section 2 of the Homeland Security Act of 2002 (6 U.S.C.
			 101).</text>
			</paragraph><paragraph id="H6A1D4DEE22854C32AABCA26CFE386E61"><enum>(13)</enum><header>National Center
			 for Cybersecurity and Communications</header><text>The term <term>National
			 Center for Cybersecurity and Communications</term> means the National Center
			 for Cybersecurity and Communications established under section 242(a) of the
			 Homeland Security Act of 2002, as added by this Act.</text>
			</paragraph><paragraph id="H4AC3139FB06942248198B7521F32C949"><enum>(14)</enum><header>National
			 information infrastructure</header><text>The term <term>national information
			 infrastructure</term> means information infrastructure—</text>
				<subparagraph id="H6620467F7C674BFA91CE25D3DBF2668B"><enum>(A)</enum><clause commented="no" display-inline="yes-display-inline" id="HFBAC22E64C4A4755A6E36448FAEFB89B"><enum>(i)</enum><text>that is owned, operated,
			 or controlled within or from the United States; or</text>
					</clause><clause id="HB218104F93C0417584C3BC1DFBC4C627" indent="up1"><enum>(ii)</enum><text>if located outside the United
			 States, the disruption of which could result in national or regional
			 catastrophic damage in the United States; and</text>
					</clause></subparagraph><subparagraph id="H831ECC95306F439290CE6FE3CD0FEE72"><enum>(B)</enum><text>that is not owned,
			 operated, controlled, or licensed for use by a Federal agency.</text>
				</subparagraph></paragraph><paragraph id="HAB05ADBBDC3B439FB71BD8513FCA66D8"><enum>(15)</enum><header>National
			 security system</header><text>The term <term>national security system</term>
			 has the meaning given that term in section 3551 of title 44, United States
			 Code, as added by this Act.</text>
			</paragraph><paragraph id="H329A86096020466FBFC4C60320291254"><enum>(16)</enum><header>National
			 strategy</header><text>The term <term>National Strategy</term> means the
			 national strategy to increase the security and resiliency of cyberspace
			 developed under section 101(a)(1).</text>
			</paragraph><paragraph id="HB73D7DFCD66B4074BE31A979232F1430"><enum>(17)</enum><header>Office</header><text>The
			 term <term>Office</term> means the Office of Cyberspace Policy established
			 under section 101.</text>
			</paragraph><paragraph id="H1C96184CAA244B1C86FF3EA58CCD4D24"><enum>(18)</enum><header>Risk</header><text>The
			 term <term>risk</term> means the potential for an unwanted outcome resulting
			 from an incident, as determined by the likelihood of the occurrence of the
			 incident and the associated consequences, including potential for an adverse
			 outcome assessed as a function of threats, vulnerabilities, and consequences
			 associated with an incident.</text>
			</paragraph><paragraph id="H30722DAEA6404118956DD6A2F3386876"><enum>(19)</enum><header>Risk-based
			 security</header><text>The term <term>risk-based security</term> has the
			 meaning given that term in section 3551 of title 44, United States Code, as
			 added by this Act.</text>
			</paragraph></section><title id="H252E212782CD45E2B0E1C476C8D6E394"><enum>I</enum><header>Office of
			 Cyberspace Policy</header>
			<section id="H261312BCCCCF48F791D6F85D4F9230CB"><enum>101.</enum><header>Establishment
			 of the Office of Cyberspace Policy</header>
				<subsection id="HB362BD525A17451384F9C1C7A9594E7E"><enum>(a)</enum><header>Establishment of
			 office</header><text>There is established in the Executive Office of the
			 President an Office of Cyberspace Policy which shall—</text>
					<paragraph id="H8D017A183F7F487C8BED371220F2E0CD"><enum>(1)</enum><text>develop, not later
			 than 1 year after the date of enactment of this Act, and update as needed, but
			 not less frequently than once every 2 years, a national strategy to increase
			 the security and resiliency of cyberspace, that includes goals and objectives
			 relating to—</text>
						<subparagraph id="HABC48B7F638346A2AB8A5893C5CF0370"><enum>(A)</enum><text>computer network
			 operations, including offensive activities, defensive activities, and other
			 activities;</text>
						</subparagraph><subparagraph id="HED65400981924A53B4E42FCB98C1E52C"><enum>(B)</enum><text>information
			 assurance;</text>
						</subparagraph><subparagraph id="H753CAA58329A4C8EAB756F92F13BC179"><enum>(C)</enum><text>protection of
			 critical infrastructure and key resources;</text>
						</subparagraph><subparagraph id="H1292A776CFD24E61AC8C61EBB611200E"><enum>(D)</enum><text>research and
			 development priorities;</text>
						</subparagraph><subparagraph id="H8690BE6A1F3C4E2DBFAB51CFD62AD0DA"><enum>(E)</enum><text>law
			 enforcement;</text>
						</subparagraph><subparagraph id="HC0BB059EBBA443FEB31A21F10FFAA9AB"><enum>(F)</enum><text>diplomacy;</text>
						</subparagraph><subparagraph id="HE9132886DEAA4081B9A6367182BF7029"><enum>(G)</enum><text>homeland security;
			 and</text>
						</subparagraph><subparagraph id="HD7C07634650845D1B654F955ADE037CA"><enum>(H)</enum><text>military and
			 intelligence activities;</text>
						</subparagraph></paragraph><paragraph id="H9A289ED009E447B88B3C2ECFFABF8BA8"><enum>(2)</enum><text>oversee,
			 coordinate, and integrate all policies and activities of the Federal Government
			 across all instruments of national power relating to ensuring the security and
			 resiliency of cyberspace, including—</text>
						<subparagraph id="H40AE8E825CD34BDD9DD075A94283580D"><enum>(A)</enum><text>diplomatic,
			 economic, military, intelligence, homeland security, and law enforcement
			 policies and activities within and among Federal agencies; and</text>
						</subparagraph><subparagraph id="H6BF99393528540EA8E72DB095D51226E"><enum>(B)</enum><text>offensive
			 activities, defensive activities, and other policies and activities necessary
			 to ensure effective capabilities to operate in cyberspace;</text>
						</subparagraph></paragraph><paragraph id="H468204B45BAE4CB59F30307F2CB3BC24"><enum>(3)</enum><text>ensure that all
			 Federal agencies comply with appropriate guidelines, policies, and directives
			 from the Department of Homeland Security, other Federal agencies with
			 responsibilities relating to cyberspace security or resiliency, and the
			 National Center for Cybersecurity and Communications; and</text>
					</paragraph><paragraph id="H3E426BA34489410E950E380C337F4896"><enum>(4)</enum><text>ensure that
			 Federal agencies have access to, receive, and appropriately disseminate law
			 enforcement information, intelligence information, terrorism information, and
			 any other information (including information relating to incidents provided
			 under subsections (a)(4) and (c) of section 246 of the Homeland Security Act of
			 2002, as added by this Act) relevant to—</text>
						<subparagraph id="H95EC117238DC4901A924A3DDE44BA485"><enum>(A)</enum><text>the security of
			 the Federal information infrastructure or the national information
			 infrastructure; and</text>
						</subparagraph><subparagraph id="H3774FCFBF82D44A7AD945B2BF1B8FDC8"><enum>(B)</enum><text>the security
			 of—</text>
							<clause id="H9642D108DCFA49B18A979A93FEF7BE70"><enum>(i)</enum><text>information
			 infrastructure that is owned, operated, controlled, or licensed for use by, or
			 on behalf of, the Department of Defense, a military department, or another
			 element of the intelligence community; or</text>
							</clause><clause id="HDF883F68DBDF478B83E4A07D3697E5AD"><enum>(ii)</enum><text>a
			 national security system.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="H505968161A214A1E9ED38F7E9009FEA4"><enum>(b)</enum><header>Director of
			 Cyberspace Policy</header>
					<paragraph id="HDCBDC550A3054BC9B3D297D6A977E8B9"><enum>(1)</enum><header>In
			 general</header><text>There shall be a Director of Cyberspace Policy, who shall
			 be the head of the Office.</text>
					</paragraph><paragraph id="H5AAC9875655D4F3BA2FF05DB0E94C032"><enum>(2)</enum><header>Executive
			 schedule position</header><text>Section 5312 of title 5, United States Code, is
			 amended by adding at the end the following:</text>
						<quoted-block display-inline="no-display-inline" id="HA5D2FE33B3F04738AF8BB762183E9A33" style="OLC"><list level="paragraph">
								<list-item>Director of Cyberspace
				  Policy.</list-item></list>
							<after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection></section><section id="HB631AB65E0F54E31B51AB0129D837A10"><enum>102.</enum><header>Appointment and
			 responsibilities of the Director</header>
				<subsection id="H6CC5B10718FB4816BDF3AD0C39432A3B"><enum>(a)</enum><header>Appointment</header>
					<paragraph id="H8148E2128C394455A89B16558089A572"><enum>(1)</enum><header>In
			 general</header><text>The Director shall be appointed by the President, by and
			 with the advice and consent of the Senate.</text>
					</paragraph><paragraph id="H59D8B865A0234BCD920E3834CC09D2BF"><enum>(2)</enum><header>Qualifications</header><text>The
			 President shall appoint the Director from among individuals who have
			 demonstrated ability and knowledge in information technology, cybersecurity,
			 and the operations, security, and resiliency of communications networks.</text>
					</paragraph><paragraph id="HFF913A23CF654C898C89527A41CD961B"><enum>(3)</enum><header>Prohibition</header><text>No
			 person shall serve as Director while serving in any other position in the
			 Federal Government.</text>
					</paragraph></subsection><subsection id="HD69AB31675164BDB87BD11E98BD6B3E7"><enum>(b)</enum><header>Responsibilities</header><text>The
			 Director shall—</text>
					<paragraph id="H1F91FE9B94434C60A1BE9507A622D4E7"><enum>(1)</enum><text>advise the
			 President regarding the establishment of policies, goals, objectives, and
			 priorities for securing the information infrastructure of the Nation;</text>
					</paragraph><paragraph id="H4E93D7CD0908490FBDCDFDB9D4CB2AD2"><enum>(2)</enum><text>advise the
			 President and other entities within the Executive Office of the President
			 regarding mechanisms to build, and improve the resiliency and efficiency of,
			 the information and communication industry of the Nation, in collaboration with
			 the private sector, while promoting national economic interests;</text>
					</paragraph><paragraph id="H5DA9458830094BF78A43C7FEE137127C"><enum>(3)</enum><text>work with Federal
			 agencies to—</text>
						<subparagraph id="H9A03B33EE466404599DAFDB04CCF1F05"><enum>(A)</enum><text>oversee,
			 coordinate, and integrate the implementation of the National Strategy,
			 including coordination with—</text>
							<clause id="H489956D4AF6C476A9FB42671B56B518B"><enum>(i)</enum><text>the
			 Department of Homeland Security;</text>
							</clause><clause id="HA626BAB8E26448CFBC0A9E5ECE9EA2F9"><enum>(ii)</enum><text>the
			 Department of Defense;</text>
							</clause><clause id="H0675A3AF971743EAA73A06B1BA5C13F9"><enum>(iii)</enum><text>the Department
			 of Commerce;</text>
							</clause><clause id="H535989CB389B4E758DF56C59BF5C884E"><enum>(iv)</enum><text>the
			 Department of State;</text>
							</clause><clause id="HF8AC87A0C6A24AE89084A8AF515AB9F4"><enum>(v)</enum><text>the
			 Department of Justice;</text>
							</clause><clause id="HE8BDB5DECACD4C2190276D3E024F7763"><enum>(vi)</enum><text>the
			 Department of Energy;</text>
							</clause><clause id="H8861C37BBB054714BFDAAF9485D22C3C"><enum>(vii)</enum><text>through the
			 Director of National Intelligence, the intelligence community; and</text>
							</clause><clause id="H0BD2E474EEA749D586D643391468123C"><enum>(viii)</enum><text>and any other
			 Federal agency with responsibilities relating to the National Strategy;
			 and</text>
							</clause></subparagraph><subparagraph id="HA8D18EEFC0DC400DAEAD5EA8C1C4BD99"><enum>(B)</enum><text>resolve any
			 disputes that arise between Federal agencies relating to the National Strategy
			 or other matters within the responsibility of the Office;</text>
						</subparagraph></paragraph><paragraph id="HE355681D9E164B54BC60339628648B1B"><enum>(4)</enum><text>if the policies or
			 activities of a Federal agency are not in compliance with the responsibilities
			 of the Federal agency under the National Strategy—</text>
						<subparagraph id="H2FC591C537E74C918C6313A6B85E5152"><enum>(A)</enum><text>notify the Federal
			 agency;</text>
						</subparagraph><subparagraph id="HA3F5780396944B25AC62F1E58DB04078"><enum>(B)</enum><text>transmit a copy of
			 each notification under subparagraph (A) to the President and the appropriate
			 congressional committees; and</text>
						</subparagraph><subparagraph id="HCC165F1C7ADA4FBCBCD5B1AF385C75CD"><enum>(C)</enum><text>coordinate the
			 efforts to bring the Federal agency into compliance;</text>
						</subparagraph></paragraph><paragraph id="H252FEE9617BF472283CA1C5E75B8D3EB"><enum>(5)</enum><text>ensure the
			 adequacy of protections for privacy and civil liberties in carrying out the
			 responsibilities of the Director under this title, including through
			 consultation with the Privacy and Civil Liberties Oversight Board established
			 under section 1061 of the National Security Intelligence Reform Act of 2004 (42
			 U.S.C. 2000ee);</text>
					</paragraph><paragraph id="H97D9CFF078D04F1A948352D689146D13"><enum>(6)</enum><text>upon reasonable
			 request, appear before any duly constituted committees of the Senate or of the
			 House of Representatives;</text>
					</paragraph><paragraph id="H35C84F86C40746D6AF780C9AC75CFDD1"><enum>(7)</enum><text>recommend to the
			 Office of Management and Budget or the head of a Federal agency actions
			 (including requests to Congress relating to the reprogramming of funds) that
			 the Director determines are necessary to ensure risk-based security of—</text>
						<subparagraph id="H3F586A8506EB414395485428149C0FE4"><enum>(A)</enum><text>the Federal
			 information infrastructure;</text>
						</subparagraph><subparagraph id="H1F8EA050FE824885B19D18669417A6FC"><enum>(B)</enum><text>information
			 infrastructure that is owned, operated, controlled, or licensed for use by, or
			 on behalf of, the Department of Defense, a military department, or another
			 element of the intelligence community; or</text>
						</subparagraph><subparagraph id="H1B6CE304F39E460D91E720A24C57CA1B"><enum>(C)</enum><text>a national
			 security system;</text>
						</subparagraph></paragraph><paragraph id="HD7CFFB0A2C974DA0BC9F821AE440BC0F"><enum>(8)</enum><text>advise the
			 Administrator of the Office of E-Government and Information Technology and the
			 Administrator of the Office of Information and Regulatory Affairs on the
			 development, and oversee the implementation, of policies, principles,
			 standards, guidelines, and budget priorities for information technology
			 functions and activities of the Federal Government;</text>
					</paragraph><paragraph id="HCE6E736FD9B546E08B60624CC964C160"><enum>(9)</enum><text>coordinate and
			 ensure, to the maximum extent practicable, that the standards and guidelines
			 developed for national security systems and the standards and guidelines under
			 section 20 of the National Institute of Standards and Technology Act (15 U.S.C.
			 278g–3) are complementary and unified;</text>
					</paragraph><paragraph id="H4D3BDE4F5F404037A22A0BFD10DD0D72"><enum>(10)</enum><text>in consultation
			 with the Administrator of the Office of Information and Regulatory Affairs,
			 coordinate efforts of Federal agencies relating to the development of
			 regulations, rules, requirements, or other actions applicable to the national
			 information infrastructure to ensure, to the maximum extent practicable, that
			 the efforts are complementary;</text>
					</paragraph><paragraph id="H93A8E9D92BFB41069DF46F1A811A0B66"><enum>(11)</enum><text>coordinate the
			 activities of the Office of Science and Technology Policy, the National
			 Economic Council, the Office of Management and Budget, the National Security
			 Council, the Homeland Security Council, and the United States Trade
			 Representative related to the National Strategy and other matters within the
			 purview of the Office; and</text>
					</paragraph><paragraph id="H131263BD1D4048BD936557040A85F435"><enum>(12)</enum><text>as assigned by
			 the President, other duties relating to the security and resiliency of
			 cyberspace.</text>
					</paragraph></subsection></section><section id="H9519581AA65E474288016E6A665EB5CF"><enum>103.</enum><header>Prohibition on
			 political campaigning</header><text display-inline="no-display-inline">Section
			 7323(b)(2)(B) of title 5, United States Code, is amended—</text>
				<paragraph id="HF68547587D184CD7B2FF2EC842EAD968"><enum>(1)</enum><text>in clause (i), by
			 striking <quote>or</quote> at the end;</text>
				</paragraph><paragraph id="HE72B48490AD749178B481564FE28617F"><enum>(2)</enum><text>in clause (ii), by
			 striking the period at the end and inserting <quote>; or</quote>; and</text>
				</paragraph><paragraph id="H7E6B9E48405C4CE1BDAECB6D35BD136E"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block display-inline="no-display-inline" id="H62443DB168CD4415B12711984B9FC885" style="OLC">
						<clause commented="no" id="HE0D5DA9DA50C4C1B8454A748DF21BF2D"><enum>(iii)</enum><text>notwithstanding
				the exception under subparagraph (A) (relating to an appointment made by the
				President, by and with the advice and consent of the Senate), the Director of
				Cyberspace
				Policy.</text>
						</clause><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></section><section id="H8BBC284E1FF649C588BD78885C9188D8"><enum>104.</enum><header>Review of
			 Federal agency budget requests relating to the National Strategy</header>
				<subsection id="HC368C1A0F84348D681FE8822C2853473"><enum>(a)</enum><header>In
			 general</header><text>For each fiscal year, the head of each Federal agency
			 shall transmit to the Director a copy of any portion of the budget of the
			 Federal agency intended to implement the National Strategy at the same time as
			 that budget request is submitted to the Office of Management and Budget in the
			 preparation of the budget of the President submitted to Congress under section
			 1105 (a) of title 31, United States Code.</text>
				</subsection><subsection id="H07AC576547204C96A13BA91F4D30F6CA"><enum>(b)</enum><header>Timely
			 submissions</header><text>The head of each Federal agency shall ensure the
			 timely development and submission to the Director of each proposed budget under
			 this section, in such format as may be designated by the Director with the
			 concurrence of the Director of the Office of Management and Budget.</text>
				</subsection><subsection id="HE9F126F68A28401D9B6D2B6A3E11FC9C"><enum>(c)</enum><header>Adequacy of the
			 proposed budget requests</header><text>With the assistance of, and in
			 coordination with, the Office of E-Government and Information Technology and
			 the National Center for Cybersecurity and Communications, the Director shall
			 review each budget submission to assess the adequacy of the proposed request
			 with regard to implementation of the National Strategy.</text>
				</subsection><subsection id="H139F555032BA451FA03DE0369D00F5C2"><enum>(d)</enum><header>Inadequate
			 budget requests</header><text>If the Director concludes that a budget request
			 submitted under subsection (a) is inadequate, in whole or in part, to implement
			 the objectives of the National Strategy, the Director shall submit to the
			 Director of the Office of Management and Budget and the head of the Federal
			 agency submitting the budget request a written description of funding levels
			 and specific initiatives that would, in the determination of the Director, make
			 the request adequate.</text>
				</subsection></section><section id="HDAA640B18FF2462B8319A24637D7D61A"><enum>105.</enum><header>Access to
			 intelligence</header><text display-inline="no-display-inline">The Director
			 shall have access to law enforcement information, intelligence information,
			 terrorism information, and any other information (including information
			 relating to incidents provided under subsections (a)(4) and (c) of section 246
			 of the Homeland Security Act of 2002, as added by this Act) that is obtained
			 by, or in the possession of, any Federal agency that the Director determines
			 relevant to the security of—</text>
				<paragraph id="H84AB140B98AE4E5CB13FAA56F3E94489"><enum>(1)</enum><text display-inline="yes-display-inline">the Federal information
			 infrastructure;</text>
				</paragraph><paragraph id="H6B9BB3AA5CF04EFBB2B757749C550F2A"><enum>(2)</enum><text display-inline="yes-display-inline">information infrastructure that is owned,
			 operated, controlled, or licensed for use by, or on behalf of, the Department
			 of Defense, a military department, or another element of the intelligence
			 community;</text>
				</paragraph><paragraph id="HA24064A45C50473ABA949111423CB340"><enum>(3)</enum><text display-inline="yes-display-inline">a national security system; or</text>
				</paragraph><paragraph id="H41A79B9F64EA4E34969A64ED0FC895F9"><enum>(4)</enum><text display-inline="yes-display-inline">national information infrastructure.</text>
				</paragraph></section><section id="HD4D2E7CC448C495FB529D5C138E8F688"><enum>106.</enum><header>Consultation</header>
				<subsection id="HC239308D8414434B98770F95C6A1FC56"><enum>(a)</enum><header>In
			 general</header><text>The Director may consult and obtain recommendations from,
			 as needed, such Presidential and other advisory entities as the Director
			 determines will assist in carrying out the mission of the Office,
			 including—</text>
					<paragraph id="H7D638555F169427C926A9F38BB05003B"><enum>(1)</enum><text>the National
			 Security Telecommunications Advisory Committee;</text>
					</paragraph><paragraph id="HC64CDA20288248FB9C4D5CF761712DCA"><enum>(2)</enum><text>the National
			 Infrastructure Advisory Council;</text>
					</paragraph><paragraph id="H226E0F5484114C47A3BDD044F8BF22CC"><enum>(3)</enum><text>the Privacy and
			 Civil Liberties Oversight Board;</text>
					</paragraph><paragraph id="H8F13419566B94DF8B8080BF0046821E3"><enum>(4)</enum><text>the President’s
			 Intelligence Advisory Board;</text>
					</paragraph><paragraph id="HB1277C0590C4433E8426501AB40B2087"><enum>(5)</enum><text>the Critical
			 Infrastructure Partnership Advisory Council; and</text>
					</paragraph><paragraph id="H5E62E5976D75474DBFA061DDC7CB83A8"><enum>(6)</enum><text>the National
			 Cybersecurity Advisory Council established under section 239 of the Homeland
			 Security Act of 2002, as added by this Act.</text>
					</paragraph></subsection><subsection id="H2C2D7D2099854DEA8F0B8930916333E3"><enum>(b)</enum><header>National
			 Strategy</header><text>In developing and updating the National Strategy the
			 Director shall consult with the National Cybersecurity Advisory Council and, as
			 appropriate, State and local governments and private entities.</text>
				</subsection></section><section id="H0AF1BF4AC8444AB4B0538B46FD251A0F"><enum>107.</enum><header>Reports to
			 Congress</header>
				<subsection id="H523465EB6CC6495D962C1313AE803605"><enum>(a)</enum><header>In
			 general</header><text>The Director shall submit an annual report to the
			 appropriate congressional committees describing the activities, ongoing
			 projects, and plans of the Federal Government designed to meet the goals and
			 objectives of the National Strategy.</text>
				</subsection><subsection id="H8D156A187C3C406FB9830FE30F875AC5"><enum>(b)</enum><header>Classified
			 annex</header><text>A report submitted under this section shall be submitted in
			 an unclassified form, but may include a classified annex, if necessary.</text>
				</subsection><subsection id="H38F19DD2FDBE4BD4B509ACD8839A325A"><enum>(c)</enum><header>Public
			 report</header><text>An unclassified version of each report submitted under
			 this section shall be made available to the public.</text>
				</subsection></section></title><title id="HC7573B2FC267483FB27572DB418DFF37"><enum>II</enum><header>National Center
			 for Cybersecurity and Communications</header>
			<section id="HF034EDD31D0B45C79AC5464C04B56FE2"><enum>201.</enum><header>Cybersecurity</header><text display-inline="no-display-inline">Title II of the Homeland Security Act of
			 2002 (6 U.S.C. 121 et seq.) is amended by adding at the end the
			 following:</text>
				<quoted-block display-inline="no-display-inline" id="H7FF77828D30246A7952C3F07854A3C26" style="OLC">
					<subtitle id="HB6BADBF5125C4A39870C6C89E22BF5DB"><enum>E</enum><header>Cybersecurity</header>
						<section id="HECE4813D3D1E40BBB11468AFB90049E1"><enum>241.</enum><header>Definitions</header><text display-inline="no-display-inline">In this subtitle—</text>
							<paragraph id="HA947DFCF5B5D47A39DAF6BCFCA0FD621"><enum>(1)</enum><text>the term
				<term>agency information infrastructure</term> means the Federal information
				infrastructure of a particular Federal agency;</text>
							</paragraph><paragraph id="H84730C6428F94558AF39CB5FAB9FA76D"><enum>(2)</enum><text>the term
				<term>appropriate committees of Congress</term> means the Committee on Homeland
				Security and Governmental Affairs of the Senate and the Committee on Homeland
				Security of the House of Representatives;</text>
							</paragraph><paragraph id="H4DF949AA4C2542F0834EC728037747EF"><enum>(3)</enum><text>the term
				<term>Center</term> means the National Center for Cybersecurity and
				Communications established under section 242(a);</text>
							</paragraph><paragraph id="H17D488D0FAC7410A96C28AB48DE61107"><enum>(4)</enum><text>the term
				<term>covered critical infrastructure</term> means a system or asset—</text>
								<subparagraph id="H55D0C2EBE2C848A196BBBACE47B9E21F"><enum>(A)</enum><text>that is on the
				prioritized critical infrastructure list established by the Secretary under
				section 210E(a)(2); and</text>
								</subparagraph><subparagraph id="HE869217FB57F469F9BEF750E94A632CB"><enum>(B)</enum><clause commented="no" display-inline="yes-display-inline" id="H9F8BF8D0A61E40B4A81E9D285CAC5B2A"><enum>(i)</enum><text>that is a component of
				the national information infrastructure; or</text>
									</clause><clause id="H1AE514E9C68A4379911F46AF6399AA3B" indent="up1"><enum>(ii)</enum><text>for which the national information
				infrastructure is essential to the reliable operation of the system or
				asset;</text>
									</clause></subparagraph></paragraph><paragraph id="HE70DB5891ECF44B2AC328706E7DC143B"><enum>(5)</enum><text>the term
				<term>cyber vulnerability</term> means any security vulnerability that, if
				exploited, could pose a significant risk of disruption to the operation of
				information infrastructure essential to the reliable operation of covered
				critical infrastructure;</text>
							</paragraph><paragraph id="H56112896816F4498B81474F725C1981D"><enum>(6)</enum><text>the term
				<term>Director</term> means the Director of the Center appointed under section
				242(b)(1);</text>
							</paragraph><paragraph id="H42CF7A26E1834A9A9BB9F64A2891B25E"><enum>(7)</enum><text>the term
				<term>Federal agency</term>—</text>
								<subparagraph id="H00008C0E5C8E432381D08FC730EBD7E7"><enum>(A)</enum><text>means any
				executive department, military department, Government corporation,
				Government-controlled corporation, or other establishment in the executive
				branch of the Government (including the Executive Office of the President), or
				any independent regulatory agency; and</text>
								</subparagraph><subparagraph id="H16261D3B89EF4E8DA4601F3BE271C9BA"><enum>(B)</enum><text>does not include
				the governments of the District of Columbia and of the territories and
				possessions of the United States and their various subdivisions;</text>
								</subparagraph></paragraph><paragraph id="H1BB7318EC07F4AEB9C14F44B79EAB954"><enum>(8)</enum><text>the term
				<term>Federal information infrastructure</term>—</text>
								<subparagraph id="H7F97C024D25E4C72BA74C972B9C47890"><enum>(A)</enum><text>means information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, any Federal agency, including information systems used or
				operated by another entity on behalf of a Federal agency; and</text>
								</subparagraph><subparagraph id="HE357388F7A584E4C88B82ED5D0B9F2F9"><enum>(B)</enum><text>does not
				include—</text>
									<clause id="H5C24DB2634F940689C78B7D66358944D"><enum>(i)</enum><text>a
				national security system; or</text>
									</clause><clause id="H3F68D0179EAA43BF9536AC7F5F7AC56E"><enum>(ii)</enum><text>information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, the Department of Defense, a military department, or another
				element of the intelligence community;</text>
									</clause></subparagraph></paragraph><paragraph commented="no" id="HBCDDC9E8738B45EBBCCDED6B86ADC724"><enum>(9)</enum><text>the term
				<term>incident</term> means an occurrence that—</text>
								<subparagraph commented="no" id="HDE0EE95CB9BA4827B6FAAEAF95E44792"><enum>(A)</enum><text>actually or
				potentially jeopardizes—</text>
									<clause commented="no" id="H81F43ACB1BC44B6B8D0A63BAA066180B"><enum>(i)</enum><text>the information
				security of information infrastructure; or</text>
									</clause><clause commented="no" id="H3A2ADE9E93254C8C81C7E186331028DE"><enum>(ii)</enum><text>the information
				that information infrastructure processes, stores, receives, or transmits;
				or</text>
									</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H848F546445A4419FA9A92ADAD8443A2F"><enum>(B)</enum><text>constitutes a
				violation or threat of violation of security policies, security procedures, or
				acceptable use policies applicable to information infrastructure.</text>
								</subparagraph></paragraph><paragraph id="H9A884DBFD48846BEAF6B290F872404B1"><enum>(10)</enum><text>the term
				<term>information infrastructure</term> means the underlying framework that
				information systems and assets rely on to process, transmit, receive, or store
				information electronically, including—</text>
								<subparagraph id="HCB42CEBFE0BB4699BFA62FEC68266FC9"><enum>(A)</enum><text>programmable
				electronic devices and communications networks; and</text>
								</subparagraph><subparagraph id="HF50482E0658C43B692E313047E6420FF"><enum>(B)</enum><text>any associated
				hardware, software, or data;</text>
								</subparagraph></paragraph><paragraph id="H3B55F7D69C4C4BC3922804A1857D8659"><enum>(11)</enum><text>the term
				<term>information security</term> means protecting information and information
				systems from disruption or unauthorized access, use, disclosure, modification,
				or destruction in order to provide—</text>
								<subparagraph id="H2165F4EAC69D4D86881B4EA896B3C1A6"><enum>(A)</enum><text>integrity, by
				guarding against improper information modification or destruction, including by
				ensuring information nonrepudiation and authenticity;</text>
								</subparagraph><subparagraph id="H504B32A52662434E88C5333F3D2AB7BD"><enum>(B)</enum><text>confidentiality,
				by preserving authorized restrictions on access and disclosure, including means
				for protecting personal privacy and proprietary information; and</text>
								</subparagraph><subparagraph id="H47148386C5F246FDB6212B3167BBB745"><enum>(C)</enum><text>availability, by
				ensuring timely and reliable access to and use of information;</text>
								</subparagraph></paragraph><paragraph id="H2986EB4FA4704EDC8BFF1D758691EC86"><enum>(12)</enum><text>the term
				<term>information sharing and analysis center</term> means a self-governed
				forum whose members work together within a specific sector of critical
				infrastructure to identify, analyze, and share with other members and the
				Federal Government critical information relating to threats,
				vul­ner­a­bil­i­ties, or incidents to the security and resiliency of the
				critical infrastructure that comprises the specific sector;</text>
							</paragraph><paragraph commented="no" id="H4F8C097624404003987273693885A27A"><enum>(13)</enum><text>the term
				<term>information system</term> has the meaning given that term in section 3502
				of title 44, United States Code;</text>
							</paragraph><paragraph id="HEB87CA48381D4B9DBFCCDA49F89DB026"><enum>(14)</enum><text>the term
				<term>intelligence community</term> has the meaning given that term in section
				3(4) of the National Security Act of 1947 (50 U.S.C. 401a(4));</text>
							</paragraph><paragraph commented="no" id="HFCCEAA951A4D4562914AF6C96B50F194"><enum>(15)</enum><text>the term
				<term>management controls</term> means safeguards or countermeasures for an
				information system that focus on the management of risk and the management of
				information system security;</text>
							</paragraph><paragraph id="H43C542AE930E4F64819606E505EC6F2D"><enum>(16)</enum><text>the term
				<term>National Cybersecurity Advisory Council</term> means the National
				Cybersecurity Advisory Council established under section 239;</text>
							</paragraph><paragraph id="HF31ABFCBB44D44CB998D55E221F1286B"><enum>(17)</enum><text>the term
				<term>national cyber emergency</term> means an actual or imminent action by any
				individual or entity to exploit a cyber vulnerability in a manner that
				disrupts, attempts to disrupt, or poses a significant risk of disruption to the
				operation of the information infrastructure essential to the reliable operation
				of covered critical infrastructure;</text>
							</paragraph><paragraph id="H9819DAA98B2B4F70A54ECE6F9C7E9159"><enum>(18)</enum><text>the term
				<term>national information infrastructure</term> means information
				infrastructure—</text>
								<subparagraph id="HACE493D83BB843A99D090A84A1D9E7DD"><enum>(A)</enum><clause commented="no" display-inline="yes-display-inline" id="HA05BDD4F066B4A75B39B9FDA23F69E6E"><enum>(i)</enum><text>that is owned, operated,
				or controlled within or from the United States; or</text>
									</clause><clause id="HAA233C3D103C472EB4DC25D466D40144" indent="up1"><enum>(ii)</enum><text>if located outside the United
				States, the disruption of which could result in national or regional
				catastrophic damage in the United States; and</text>
									</clause></subparagraph><subparagraph id="HC04F384497BE48FE8E1F5A9128CC3E6E"><enum>(B)</enum><text>that is not owned,
				operated, controlled, or licensed for use by a Federal agency;</text>
								</subparagraph></paragraph><paragraph id="H0EE40661301F4D17AD806B878F79D431"><enum>(19)</enum><text>the term
				<term>national security system</term> has the same meaning given that term in
				section 3551 of title 44, United States Code;</text>
							</paragraph><paragraph id="H239AA1CEA66947508F28776D8CC0E333"><enum>(20)</enum><text>the term
				<term>operational controls</term> means the safeguards and countermeasures for
				an information system that are primarily implemented and executed by
				individuals not systems;</text>
							</paragraph><paragraph id="H7E2A105C40264168AE7D9EB84BD73589"><enum>(21)</enum><text>the term
				<term>sector-specific agency</term> means the relevant Federal agency
				responsible for infrastructure protection activities in a designated critical
				infrastructure sector or key resources category under the National
				Infrastructure Protection Plan, or any other appropriate Federal agency
				identified by the President after the date of enactment of this
				subtitle;</text>
							</paragraph><paragraph commented="no" id="HAC034091C8FA40D1A0683DFBEB297711"><enum>(22)</enum><text>the term
				<term>sector coordinating councils</term> means self-governed councils that are
				composed of representatives of key stakeholders within a specific sector of
				critical infrastructure that serve as the principal private sector policy
				coordination and planning entities with the Federal Government relating to the
				security and resiliency of the critical infrastructure that comprise that
				sector;</text>
							</paragraph><paragraph id="H946A734AAEB74A6CA830F4D75FBBF33A"><enum>(23)</enum><text>the term
				<term>security controls</term> means the management, operational, and technical
				controls prescribed for an information system to protect the information
				security of the system;</text>
							</paragraph><paragraph id="HF30322479BBC4632AA39DC2710716F7A"><enum>(24)</enum><text>the term
				<term>small business concern</term> has the meaning given that term under
				section 3 of the Small Business Act (15 U.S.C. 632);</text>
							</paragraph><paragraph id="HD91DF496B9714AACA4D9C477437F28FE"><enum>(25)</enum><text>the term
				<term>technical controls</term> means the safeguards or countermeasures for an
				information system that are primarily implemented and executed by the
				information system through mechanisms contained in the hardware, software, or
				firmware components of the system;</text>
							</paragraph><paragraph id="H44793371ACF1475BB59575F83789CD91"><enum>(26)</enum><text>the term
				<term>terrorism information</term> has the meaning given that term in section
				1016 of the Intelligence Reform and Terrorism Prevention Act of 2004 (6 U.S.C.
				485);</text>
							</paragraph><paragraph id="H4C0104647E7944678A5E898B74288738"><enum>(27)</enum><text>the term
				<term>United States person</term> has the meaning given that term in section
				101 of the Foreign Intelligence Surveillance Act of 1978 (50 U.S.C. 1801);
				and</text>
							</paragraph><paragraph id="H743F07312BFE40738187F3D6FC18E6F6"><enum>(28)</enum><text>the term
				<term>US–CERT</term> means the United States Computer Readiness Team
				established under section 244.</text>
							</paragraph></section><section id="HF0D13D8C46544A7A9998DC0082A0B780"><enum>242.</enum><header>National Center
				for Cybersecurity and Communications</header>
							<subsection id="HB3E02A7EEC49471397E7A2B245A5758E"><enum>(a)</enum><header>Establishment</header>
								<paragraph id="HBCB43BB8CB744878A931E21C7B4B4861"><enum>(1)</enum><header>In
				general</header><text>There is established within the Department a National
				Center for Cybersecurity and Communications.</text>
								</paragraph><paragraph id="H389710CF81F7495F89E0FEF424EEE8F8"><enum>(2)</enum><header>Operational
				entity</header><text>The Center may—</text>
									<subparagraph id="HCEE0625017684BB28065D584B135F4BB"><enum>(A)</enum><text>enter into
				contracts for the procurement of property and services for the Center;
				and</text>
									</subparagraph><subparagraph id="HEF98BB24D8474CCB92C20AE40BEA9048"><enum>(B)</enum><text>appoint employees
				of the Center in accordance with the civil service laws of the United
				States.</text>
									</subparagraph></paragraph></subsection><subsection id="HAF92E76F9C304307A9BDC8077EC645C0"><enum>(b)</enum><header>Director</header>
								<paragraph id="H9035065C085D4C9DA736C5AC1669F9F8"><enum>(1)</enum><header>In
				general</header><text>The Center shall be headed by a Director, who shall be
				appointed by the President, by and with the advice and consent of the
				Senate.</text>
								</paragraph><paragraph id="H8AA43709B2594A83AB37CD07FC995D24"><enum>(2)</enum><header>Reporting to
				Secretary</header><text>The Director shall report directly to the Secretary and
				serve as the principal advisor to the Secretary on cybersecurity and the
				operations, security, and resiliency of the communications infrastructure of
				the United States.</text>
								</paragraph><paragraph id="H0A5B181F9C8C4C81B72EA601F62899DF"><enum>(3)</enum><header>Presidential
				advice</header><text>The Director shall regularly advise the President on the
				exercise of the authorities provided under this subtitle or any other provision
				of law relating to the security of the Federal information infrastructure or an
				agency information infrastructure.</text>
								</paragraph><paragraph id="H34584AAA3F7644C18F5A38D4FA597779"><enum>(4)</enum><header>Qualifications</header><text>The
				Director shall be appointed from among individuals who have—</text>
									<subparagraph id="HC41A4C43DEE6498ABA96ECF2B1320B8E"><enum>(A)</enum><text>a demonstrated
				ability in and knowledge of information technology, cybersecurity, and the
				operations, security and resiliency of communications networks; and</text>
									</subparagraph><subparagraph id="HBD8789D4F4E84332A168E4435AC0916A"><enum>(B)</enum><text>significant
				executive leadership and management experience in the public or private
				sector.</text>
									</subparagraph></paragraph><paragraph id="HE3237358BF3B448EA75AEB8DCBCB92D3"><enum>(5)</enum><header>Limitation on
				service</header>
									<subparagraph id="H15BB22644E794E2182AAB8B3FD8FD391"><enum>(A)</enum><header>In
				general</header><text>Subject to subparagraph (B), the individual serving as
				the Director may not, while so serving, serve in any other capacity in the
				Federal Government, except to the extent that the individual serving as
				Director is doing so in an acting capacity.</text>
									</subparagraph><subparagraph id="H818E3F47CB3D443EBDB2065EB1B45F79"><enum>(B)</enum><header>Exception</header><text>The
				Director may serve on any commission, board, council, or similar entity with
				responsibilities or duties relating to cybersecurity or the operations,
				security, and resiliency of the communications infrastructure of the United
				States at the direction of the President or as otherwise provided by
				law.</text>
									</subparagraph></paragraph></subsection><subsection id="HE9B261E297254F0B821AE4326C8AFF16"><enum>(c)</enum><header>Deputy
				Directors</header>
								<paragraph id="H6E7A35A93C0E4065ACD0FBE4516B9001"><enum>(1)</enum><header>In
				general</header><text>There shall be not less than 2 Deputy Directors for the
				Center, who shall report to the Director.</text>
								</paragraph><paragraph id="HFB991D7698134522A63520EB749F32A7"><enum>(2)</enum><header>Infrastructure
				protection</header>
									<subparagraph id="H9BA07D1106E740778BFCA57CB7326E36"><enum>(A)</enum><header>Appointment</header><text>There
				shall be a Deputy Director appointed by the Secretary, who shall have expertise
				in infrastructure protection.</text>
									</subparagraph><subparagraph commented="no" id="HCBF7FA62D91E41A4954140BEE044E57D"><enum>(B)</enum><header>Responsibilities</header><text>The
				Deputy Director appointed under subparagraph (A) shall—</text>
										<clause commented="no" id="HAF37FB13E10D45899874D92F4FFA0569"><enum>(i)</enum><text>assist the
				Director and the Assistant Secretary for Infrastructure Protection in
				coordinating, managing, and directing the information, communications, and
				physical infrastructure protection responsibilities and activities of the
				Department, including activities under Homeland Security Presidential
				Directive–7, or any successor thereto, and the National Infrastructure
				Protection Plan, or any successor thereto;</text>
										</clause><clause commented="no" id="H48F064AAC71842A491ED50A1B0D35349"><enum>(ii)</enum><text>review the budget
				for the Center and the Office of Infrastructure Protection before submission of
				the budget to the Secretary to ensure that activities are appropriately
				coordinated;</text>
										</clause><clause commented="no" id="HA5A26D0D82DC45189C1A20D8E27496AC"><enum>(iii)</enum><text>develop, update
				periodically, and submit to the appropriate committees of Congress a strategic
				plan detailing how critical infrastructure protection activities will be
				coordinated between the Center, the Office of Infrastructure Protection, and
				the private sector;</text>
										</clause><clause commented="no" id="HB63FB4C4914748F0BD2B58B8CFC56D57"><enum>(iv)</enum><text>subject to the
				direction of the Director resolve conflicts between the Center and the Office
				of Infrastructure Protection relating to the information, communications, and
				physical infrastructure protection responsibilities of the Center and the
				Office of Infrastructure Protection; and</text>
										</clause><clause id="H98754E497DF343F4B86DBC9F1509D6F9"><enum>(v)</enum><text>perform such other
				duties as the Director may assign.</text>
										</clause></subparagraph><subparagraph id="H877232A8FBF04281A6588457EA0BE994"><enum>(C)</enum><header>Annual
				evaluation</header><text>The Assistant Secretary for Infrastructure Protection
				shall submit annually to the Director an evaluation of the performance of the
				Deputy Director appointed under subparagraph (A).</text>
									</subparagraph></paragraph><paragraph id="HF7D73FA691E040FF92B47ABD57F60E97"><enum>(3)</enum><header>Intelligence
				community</header><text>The Director of National Intelligence shall identify an
				employee of an element of the intelligence community to serve as a Deputy
				Director of the Center. The employee shall be detailed to the Center on a
				reimbursable basis for such period as is agreed to by the Director and the
				Director of National Intelligence, and, while serving as Deputy Director, shall
				report directly to the Director of the Center.</text>
								</paragraph></subsection><subsection id="HABC631AE92634416A8C24ADA466EFB47"><enum>(d)</enum><header>Liaison
				officers</header><text>The Secretary of Defense, the Attorney General, the
				Secretary of Commerce, and the Director of National Intelligence shall detail
				personnel to the Center to act as full-time liaisons with the Department of
				Defense, the Department of Justice, the National Institute of Standards and
				Technology, and elements of the intelligence community to assist in
				coordination between and among the Center, the Department of Defense, the
				Department of Justice, the National Institute of Standards and Technology, and
				elements of the intelligence community.</text>
							</subsection><subsection id="H415C14CF960E4A82AA5B92AB837205A5"><enum>(e)</enum><header>Privacy
				officer</header>
								<paragraph id="H77F66B78D5044290AF4A6271239FA1D5"><enum>(1)</enum><header>In
				general</header><text>The Director, in consultation with the Secretary, shall
				designate a full-time privacy officer, who shall report to the Director.</text>
								</paragraph><paragraph id="H5C9201A87CC342DC8C962C91A15F07E3"><enum>(2)</enum><header>Duties</header><text>The
				privacy officer designated under paragraph (1) shall have primary
				responsibility for implementation by the Center of the privacy policy for the
				Department established by the Privacy Officer appointed under section
				222.</text>
								</paragraph></subsection><subsection id="H8C2229C13D2D4C66843EA7148E570051"><enum>(f)</enum><header>Duties of
				Director</header>
								<paragraph id="H47893E4DA4654C348011C86E41D4D1D9"><enum>(1)</enum><header>In
				general</header><text>The Director shall—</text>
									<subparagraph id="HF989A881ECF5436C8AD7B7DADBFC7B94"><enum>(A)</enum><text>working
				cooperatively with the private sector, lead the Federal effort to secure,
				protect, and ensure the resiliency of the Federal information infrastructure
				and national information infrastructure of the United States, including
				communications networks;</text>
									</subparagraph><subparagraph id="HF87D56988D18451A9EAC3034AC301A37"><enum>(B)</enum><text>assist in the
				identification, remediation, and mitigation of vulnerabilities to the Federal
				information infrastructure and the national information infrastructure;</text>
									</subparagraph><subparagraph id="H06B2F0E892714E98957BF2D0CA3E9396"><enum>(C)</enum><text>provide dynamic,
				comprehensive, and continuous situational awareness of the security status of
				the Federal information infrastructure, national information infrastructure,
				and information infrastructure that is owned, operated, controlled, or licensed
				for use by, or on behalf of, the Department of Defense, a military department,
				or another element of the intelligence community by sharing and integrating
				classified and unclassified information, including information relating to
				threats, vulnerabilities, traffic, trends, incidents, and other anomalous
				activities affecting the infrastructure or systems, on a routine and continuous
				basis with—</text>
										<clause id="H97E0C3F7530C4DE091018981CFE4BF51"><enum>(i)</enum><text>the National
				Threat Operations Center of the National Security Agency;</text>
										</clause><clause id="HB319F155E6A24B97A570D039189F3837"><enum>(ii)</enum><text>the United States
				Cyber Command, including the Joint Task Force-Global Network Operations;</text>
										</clause><clause id="HAEF31818258A4766B49078281BAE7681"><enum>(iii)</enum><text>the Cyber Crime
				Center of the Department of Defense;</text>
										</clause><clause id="H59297EC7820C47C8A6BF97F96D00124B"><enum>(iv)</enum><text>the National
				Cyber Investigative Joint Task Force;</text>
										</clause><clause id="H93E89A47F82243699D788F2A9E17CF83"><enum>(v)</enum><text>the Intelligence
				Community Incident Response Center;</text>
										</clause><clause id="H4969F8E3817041989A9A6E72C27C958E"><enum>(vi)</enum><text>any other Federal
				agency, or component thereof, identified by the Director; and</text>
										</clause><clause id="HA59086D59C554E3495C9DF90BEC475D8"><enum>(vii)</enum><text>any non-Federal
				entity, including, where appropriate, information sharing and analysis centers,
				identified by the Director, with the concurrence of the owner or operator of
				that entity and consistent with applicable law;</text>
										</clause></subparagraph><subparagraph id="H74414383D5194F829FDDDA81000415C8"><enum>(D)</enum><text>work with the
				entities described in subparagraph (C) to establish policies and procedures
				that enable information sharing between and among the entities;</text>
									</subparagraph><subparagraph id="HF9FD4AC88D1F4B66B86273E6F5965F05"><enum>(E)</enum><text>develop, in
				coordination with the Assistant Secretary for Infrastructure Protection, other
				Federal agencies, the private sector, and State and local governments, a
				national incident response plan that details the roles of Federal agencies,
				State and local governments, and the private sector, including plans to be
				executed in response to a declaration of a national cyber emergency by the
				President under section 249;</text>
									</subparagraph><subparagraph id="H46B970B2B918422C81E5A83C1772063C"><enum>(F)</enum><text>conduct risk-based
				assessments of the Federal information infrastructure with respect to acts of
				terrorism, natural disasters, and other large-scale disruptions and provide the
				results of the assessments to the Director of Cyberspace Policy;</text>
									</subparagraph><subparagraph id="HEC64B589E7A347B2875640A7E0BB6702"><enum>(G)</enum><text>develop, oversee
				the implementation of, and enforce policies, principles, and guidelines on
				information security for the Federal information infrastructure, including
				timely adoption of and compliance with standards developed by the National
				Institute of Standards and Technology under section 20 of the National
				Institute of Standards and Technology Act (15 U.S.C. 278g–3);</text>
									</subparagraph><subparagraph id="H9C650FA82656480988B4265ED3F5E98C"><enum>(H)</enum><text>provide assistance
				to the National Institute of Standards and Technology in developing standards
				under section 20 of the National Institute of Standards and Technology Act (15
				U.S.C. 278g–3);</text>
									</subparagraph><subparagraph id="H2D44A964870040B1802FB247972866DB"><enum>(I)</enum><text>provide to Federal
				agencies mandatory security controls to mitigate and remediate vulnerabilities
				of and incidents affecting the Federal information infrastructure;</text>
									</subparagraph><subparagraph id="H043EECFBE86D4194ABB2AECDC9D16A79"><enum>(J)</enum><text>subject to
				paragraph (2), and as needed, assist the Director of the Office of Management
				and Budget and the Director of Cyberspace Policy in conducting analysis and
				prioritization of budgets, relating to the security of the Federal information
				infrastructure;</text>
									</subparagraph><subparagraph id="HFEE7D40653AF4D0981B1BFA8D12C53BD"><enum>(K)</enum><text>in accordance with
				section 253, develop, periodically update, and implement a supply chain risk
				management strategy to enhance, in a risk-based and cost-effective manner, the
				security of the communications and information technology products and services
				purchased by the Federal Government;</text>
									</subparagraph><subparagraph id="H46F42B056A3547AA8C18A08093CEB76B"><enum>(L)</enum><text>notify the
				Director of Cyberspace Policy of any incident involving the Federal information
				infrastructure, information infrastructure that is owned, operated, controlled,
				or licensed for use by, or on behalf of, the Department of Defense, a military
				department, or another element of the intelligence community, or the national
				information infrastructure that could compromise or significantly affect
				economic or national security;</text>
									</subparagraph><subparagraph id="HE8AB15F3D80A4B26BCDB34B1B7E83493"><enum>(M)</enum><text>consult, in
				coordination with the Director of Cyberspace Policy, with appropriate
				international partners to enhance the security of the Federal information
				infrastructure and national information infrastructure;</text>
									</subparagraph><subparagraph id="H9B859AB1E5AA406E9B5E8EE4DEE1CC61"><enum>(N)</enum><clause commented="no" display-inline="yes-display-inline" id="H98D14E1AA5D6494F98366E4EDA4BDE18"><enum>(i)</enum><text>coordinate and integrate
				information to analyze the composite security state of the Federal information
				infrastructure and information infrastructure that is owned, operated,
				controlled, or licensed for use by, or on behalf of, the Department of Defense,
				a military department, or another element of the intelligence community;</text>
										</clause><clause id="H137823075B6C46B2A52C4EAACF073996" indent="up1"><enum>(ii)</enum><text>ensure the information required
				under clause (i) and section 3553(c)(1)(A) of title 44, United States Code,
				including the views of the Director on the adequacy and effectiveness of
				information security throughout the Federal information infrastructure and
				information infrastructure that is owned, operated, controlled, or licensed for
				use by, or on behalf of, the Department of Defense, a military department, or
				another element of the intelligence community, is available on an automated and
				continuous basis through the system maintained under section 3552(a)(3)(D) of
				title 44, United States Code;</text>
										</clause><clause id="H1CBCBCD3A11841FABB85B8B254EF5022" indent="up1"><enum>(iii)</enum><text>in conjunction with the
				quadrennial homeland security review required under section 707, and at such
				other times determined appropriate by the Director, analyze the composite
				security state of the national information infrastructure and submit to the
				President, Congress, and the Secretary a report regarding actions necessary to
				enhance the composite security state of the national information infrastructure
				based on the analysis; and</text>
										</clause><clause id="HDF696CE4901944108054161D823FA375" indent="up1"><enum>(iv)</enum><text>foster collaboration and serve as
				the primary contact between the Federal Government, State and local
				governments, and private entities on matters relating to the security of the
				Federal information infrastructure and the national information
				infrastructure;</text>
										</clause></subparagraph><subparagraph id="H390B2C053451414EA4099D55780FF46A"><enum>(O)</enum><text>oversee the
				development, implementation, and management of security requirements for
				Federal agencies relating to the external access points to or from the Federal
				information infrastructure;</text>
									</subparagraph><subparagraph id="H3624FEBF28B648D29545FEB794B52283"><enum>(P)</enum><text>establish,
				develop, and oversee the capabilities and operations within the US–CERT as
				required by section 244;</text>
									</subparagraph><subparagraph id="H1FDEE1325EC6492A864D8E3CAB80DC65"><enum>(Q)</enum><text>oversee the
				operations of the National Communications System, as described in Executive
				Order 12472 (49 Fed. Reg. 13471; relating to the assignment of national
				security and emergency preparedness telecommunications functions), as amended
				by Executive Order 13286 (68 Fed. Reg. 10619) and Executive Order 13407 (71
				Fed. Reg. 36975), or any successor thereto, including planning for and
				providing communications for the Federal Government under all circumstances,
				including crises, emergencies, attacks, recoveries, and reconstitutions;</text>
									</subparagraph><subparagraph id="HFB294D7EAD784EDEBFFE9B12FB685EA0"><enum>(R)</enum><text>ensure, in
				coordination with the privacy officer designated under subsection (e), the
				Privacy Officer appointed under section 222, and the Director of the Office of
				Civil Rights and Civil Liberties appointed under section 705, that the
				activities of the Center comply with all policies, regulations, and laws
				protecting the privacy and civil liberties of United States persons;</text>
									</subparagraph><subparagraph id="HDBA564235EEC46EAA561173CD627C6EA"><enum>(S)</enum><text>subject to the
				availability of resources, and at the discretion of the Director, provide
				voluntary technical assistance—</text>
										<clause id="HB8C4E31599464D06ABAFBF2E7B501F9C"><enum>(i)</enum><text>at
				the request of an owner or operator of covered critical infrastructure, to
				assist the owner or operator in complying with sections 248 and 249, including
				implementing required security or emergency measures and developing response
				plans for national cyber emergencies declared under section 249; and</text>
										</clause><clause id="HD8F2114E52054A6EA5A5608BC5E29EE9"><enum>(ii)</enum><text>at the request of
				the owner or operator of national information infrastructure that is not
				covered critical infrastructure, and based on risk, to assist the owner or
				operator in implementing best practices, and related standards and guidelines,
				recommended under section 247 and other measures necessary to mitigate or
				remediate vulnerabilities of the information infrastructure and the
				consequences of efforts to exploit the vulnerabilities;</text>
										</clause></subparagraph><subparagraph id="H15822A52C9134704B5CC7A33697E73E4"><enum>(T)</enum><clause commented="no" display-inline="yes-display-inline" id="H483EE44ED3D849C38AC7BF5B06D5E05C"><enum>(i)</enum><text>conduct, in consultation
				with the National Cybersecurity Advisory Council, the head of appropriate
				sector-specific agencies, and any private sector entity determined appropriate
				by the Director, risk-based assessments of national information infrastructure,
				on a sector-by-sector basis, with respect to acts of terrorism, natural
				disasters, and other large-scale disruptions or financial harm, which shall
				identify and prioritize risks to the national information infrastructure,
				including vulnerabilities and associated consequences; and</text>
										</clause><clause id="H1F6B4334735941BB8ECA000587B18C82" indent="up1"><enum>(ii)</enum><text>coordinate and evaluate the
				mitigation or remediation of cyber vulnerabilities and consequences identified
				under clause (i);</text>
										</clause></subparagraph><subparagraph id="H2A962272D3684E778FB17EFDC63343CA"><enum>(U)</enum><text>regularly evaluate
				and assess technologies designed to enhance the protection of the Federal
				information infrastructure and national information infrastructure, including
				an assessment of the cost-effectiveness of the technologies;</text>
									</subparagraph><subparagraph id="H95FAF1FBAFAD4C8DBBB75278F1C7D6D2"><enum>(V)</enum><text>promote the use of
				the best practices recommended under section 247 to State and local governments
				and the private sector;</text>
									</subparagraph><subparagraph id="H722D151E4E7B4AA49C3A53D3C35FDD13"><enum>(W)</enum><text>develop and
				implement outreach and awareness programs on cybersecurity, including—</text>
										<clause id="HEFD8FD7008A24470B2AFDB15EF99CDA7"><enum>(i)</enum><text>a
				public education campaign to increase the awareness of cybersecurity, cyber
				safety, and cyber ethics, which shall include use of the Internet, social
				media, entertainment, and other media to reach the public;</text>
										</clause><clause id="HB0F7B1ABA9D14B68BC5D1262E6E712B5"><enum>(ii)</enum><text>an education
				campaign to increase the understanding of State and local governments and
				private sector entities of the costs of failing to ensure effective security of
				information infrastructure and cost-effective methods to mitigate and remediate
				vulnerabilities; and</text>
										</clause><clause id="HBCF1FD6211B141F88D7B38BE724AF99C"><enum>(iii)</enum><text>outcome-based
				performance measures to determine the success of the programs;</text>
										</clause></subparagraph><subparagraph id="H67B72077B08D430CB27280931E6F64D0"><enum>(X)</enum><text>develop and
				implement a national cybersecurity exercise program that includes—</text>
										<clause id="HF2AC3983125C43D1B6B8105CEE0EC591"><enum>(i)</enum><text>the participation
				of State and local governments, international partners of the United States,
				and the private sector; and</text>
										</clause><clause id="H95CD0A8052034D17AB9757C55BDA203B"><enum>(ii)</enum><text>an after action
				report analyzing lessons learned from exercises and identifying vulnerabilities
				to be remediated or mitigated;</text>
										</clause></subparagraph><subparagraph id="H5EC3C3E18A9A4E379FE297620CA72DF4"><enum>(Y)</enum><text>coordinate with
				the Assistant Secretary for Infrastructure Protection to ensure that—</text>
										<clause id="H19C94DF04F4049B9B8289DCE87CD3389"><enum>(i)</enum><text>cybersecurity is
				appropriately addressed in carrying out the infrastructure protection
				responsibilities described in section 201(d); and</text>
										</clause><clause id="H1FA0FF8BD4FE48A2B1B3C19835C0A621"><enum>(ii)</enum><text>the operations of
				the Center and the Office of Infrastructure Protection avoid duplication and
				use, to the maximum extent practicable, joint mechanisms for information
				sharing and coordination with the private sector;</text>
										</clause></subparagraph><subparagraph id="H870E44A5E8444544BBC3DE179E34AA17"><enum>(Z)</enum><text>oversee the
				activities of the Office of Emergency Communications established under section
				1801; and</text>
									</subparagraph><subparagraph id="H5D2B80EB6F964221A9341A805C1D0AA8"><enum>(AA)</enum><text>perform such
				other duties as the Secretary may direct relating to the security and
				resiliency of the information and communications infrastructure of the United
				States.</text>
									</subparagraph></paragraph><paragraph id="H88EC998A28B14CC8AC20F63DCD4B0636"><enum>(2)</enum><header>Budget
				analysis</header><text>In conducting analysis and prioritization of budgets
				under paragraph (1)(J), the Director—</text>
									<subparagraph id="HCC432217D35547508631A757261CF3BD"><enum>(A)</enum><text>in coordination
				with the Director of the Office of Management and Budget, may access
				information from any Federal agency regarding the finances, budget, and
				programs of the Federal agency relevant to the security of the Federal
				information infrastructure;</text>
									</subparagraph><subparagraph id="HCE3DCBC977F4438488F8D1808FE835D1"><enum>(B)</enum><text>may make
				recommendations to the Director of the Office of Management and Budget and the
				Director of Cyberspace Policy regarding the budget for each Federal agency to
				ensure that adequate funding is devoted to securing the Federal information
				infrastructure, in accordance with policies, principles, and guidelines
				established by the Director under this subtitle; and</text>
									</subparagraph><subparagraph id="HA579A751B4184C79B7C672A32B854FF7"><enum>(C)</enum><text>shall provide
				copies of any recommendations made under subparagraph (B) to—</text>
										<clause id="H06BB54261B1C4E71865C818B031E8009"><enum>(i)</enum><text>the Committee on
				Appropriations of the Senate;</text>
										</clause><clause id="H7E03F35C6A5C4EAF97BFCBF50601208B"><enum>(ii)</enum><text>the Committee on
				Appropriations of the House of Representatives; and</text>
										</clause><clause id="H23C30A368A1C44238382F5BC1F54ACFF"><enum>(iii)</enum><text>the appropriate
				committees of Congress.</text>
										</clause></subparagraph></paragraph></subsection><subsection id="H6B479F5852B64AB7A8BEB80D53D7556F"><enum>(g)</enum><header>Use of
				mechanisms for collaboration</header><text>In carrying out the responsibilities
				and authorities of the Director under this subtitle, to the maximum extent
				practicable, the Director shall use mechanisms for collaboration and
				information sharing (including mechanisms relating to the identification and
				communication of threats, vulnerabilities, and associated consequences)
				established by other components of the Department or other Federal agencies to
				avoid unnecessary duplication or waste.</text>
							</subsection><subsection id="H50E0394F92FD4ED1B8115C1918BE872E"><enum>(h)</enum><header>Sufficiency of
				resources plan</header>
								<paragraph id="H42ACF2A11266492DA24DB453151AF26F"><enum>(1)</enum><header>Report</header><text>Not
				later than 120 days after the date of enactment of this subtitle, the Director
				of the Office of Management and Budget shall submit to the appropriate
				committees of Congress and the Comptroller General of the United States a
				report on the resources and staff necessary to carry out fully the
				responsibilities under this subtitle.</text>
								</paragraph><paragraph id="HFDFD2DCE0D4D47F89EF29DB42CE4D3AC"><enum>(2)</enum><header>Comptroller
				General review</header>
									<subparagraph id="H1E5F563456864C269D3E0D09AD501B5A"><enum>(A)</enum><header>In
				general</header><text>The Comptroller General of the United States shall
				evaluate the reasonableness and adequacy of the report submitted by the
				Director under paragraph (1).</text>
									</subparagraph><subparagraph id="H50672540DCD9478782D9482260A8124E"><enum>(B)</enum><header>Report</header><text>Not
				later than 60 days after the date on which the report is submitted under
				paragraph (1), the Comptroller General shall submit to the appropriate
				committees of Congress a report containing the findings of the review under
				subparagraph (A).</text>
									</subparagraph></paragraph></subsection><subsection id="HA28193B181624BF88921054B59C54E7A"><enum>(i)</enum><header>Functions
				transferred</header><text>There are transferred to the Center the National
				Cyber Security Division, the Office of Emergency Communications, and the
				National Communications System, including all the functions, personnel, assets,
				authorities, and liabilities of the National Cyber Security Division and the
				National Communications System.</text>
							</subsection></section><section id="HB180B04D401F443CAEF1DA81B4CDA0D1"><enum>243.</enum><header>Physical and
				cyber infrastructure collaboration</header>
							<subsection id="H97A3E0BC3D0043A49658AD6C39F4DDC5"><enum>(a)</enum><header>In
				general</header><text>The Director and the Assistant Secretary for
				Infrastructure Protection shall coordinate the information, communications, and
				physical infrastructure protection responsibilities and activities of the
				Center and the Office of Infrastructure Protection.</text>
							</subsection><subsection id="H2ADDF66414564B9A965F4CA53B64DD63"><enum>(b)</enum><header>Oversight</header><text>The
				Secretary shall ensure that the coordination described in subsection (a)
				occurs.</text>
							</subsection></section><section id="HD3C933BFC3F94B96A3164CF036069015"><enum>244.</enum><header>United States
				Computer Emergency Readiness Team</header>
							<subsection id="HCBE6C5A67FCD4896AD816C2D05F6903F"><enum>(a)</enum><header>Establishment of
				office</header><text>There is established within the Center, the United States
				Computer Emergency Readiness Team, which shall be headed by a Director, who
				shall be selected from the Senior Executive Service by the Secretary.</text>
							</subsection><subsection id="H3EAA48D522E3495BB7458168D05E5926"><enum>(b)</enum><header>Responsibilities</header><text>The
				US–CERT shall—</text>
								<paragraph id="HAD9753A3AD8E427B82C775AF01CCFD2B"><enum>(1)</enum><text>collect,
				coordinate, and disseminate information on—</text>
									<subparagraph id="HCC2A0690FEE442F89FEDA94557607F89"><enum>(A)</enum><text>risks to the
				Federal information infrastructure, information infrastructure that is owned,
				operated, controlled, or licensed for use by, or on behalf of, the Department
				of Defense, a military department, or another element of the intelligence
				community, or the national information infrastructure; and</text>
									</subparagraph><subparagraph id="H1D61FCF6E4654A77BAAD51D2BD49A217"><enum>(B)</enum><text>security controls
				to enhance the security of the Federal information infrastructure or the
				national information infrastructure against the risks identified in
				subparagraph (A); and</text>
									</subparagraph></paragraph><paragraph id="H4EDDD6809BEE4D0E81546D4B4D448C96"><enum>(2)</enum><text>establish a
				mechanism for engagement with the private sector.</text>
								</paragraph></subsection><subsection id="H68A80616363E4A9992552D88F6BAE69C"><enum>(c)</enum><header>Monitoring,
				analysis, warning, and response</header>
								<paragraph id="H700C5B2559EF4D5DAE32DB0512F18355"><enum>(1)</enum><header>Duties</header><text>Subject
				to paragraph (2), the US–CERT shall—</text>
									<subparagraph id="HA81CFD9C357742B186F5D9DA26570465"><enum>(A)</enum><text>provide analysis
				and reports to Federal agencies on the security of the Federal information
				infrastructure;</text>
									</subparagraph><subparagraph commented="no" id="HC74910BF98EB43A095479C0BC3DE00AD"><enum>(B)</enum><text>provide
				continuous, automated monitoring of the Federal information infrastructure at
				external Internet access points, which shall include detection and warning of
				threats, vulnerabilities, traffic, trends, incidents, and other anomalous
				activities affecting the information security of the Federal information
				infrastructure;</text>
									</subparagraph><subparagraph id="HC3DFB49F9C5B4F65B919324F50CCF693"><enum>(C)</enum><text>warn Federal
				agencies of threats, vulnerabilities, incidents, and anomalous activities that
				could affect the Federal information infrastructure;</text>
									</subparagraph><subparagraph id="H421EE1A1167D43D9BCEBFCFEF7F2EE5D"><enum>(D)</enum><text>develop,
				recommend, and deploy security controls to mitigate or remediate
				vulnerabilities;</text>
									</subparagraph><subparagraph id="H39BC624FA6744382AC1EBA0B7AE75604"><enum>(E)</enum><text>support Federal
				agencies in conducting risk assessments of the agency information
				infrastructure;</text>
									</subparagraph><subparagraph id="H1929DF9BD782410AA20091DD7E535350"><enum>(F)</enum><text>disseminate to
				Federal agencies risk analyses of incidents that could impair the risk-based
				security of the Federal information infrastructure;</text>
									</subparagraph><subparagraph id="H2F1AC5D8322B4E409553FD9CEF40278E"><enum>(G)</enum><text>develop and
				acquire predictive analytic tools to evaluate threats, vulnerabilities,
				traffic, trends, incidents, and anomalous activities;</text>
									</subparagraph><subparagraph id="HC945E02DF8CF49E685B3899B5E3E3E62"><enum>(H)</enum><text>aid in the
				detection of, and warn owners or operators of national information
				infrastructure regarding, threats, vulnerabilities, and incidents, affecting
				the national information infrastructure, including providing—</text>
										<clause id="H3DA18DB0A29149DDAD91AB05D5894C9C"><enum>(i)</enum><text>timely, targeted,
				and actionable notifications of threats, vulnerabilities, and incidents;
				and</text>
										</clause><clause id="HB486762BCE2843D193DB78E2FA99BCD9"><enum>(ii)</enum><text>recommended
				security controls to mitigate or remediate vulnerabilities; and</text>
										</clause></subparagraph><subparagraph id="H3FEEA3E5F4E84C7D8790013827CEA935"><enum>(I)</enum><text>respond to
				assistance requests from Federal agencies and, subject to the availability of
				resources, owners or operators of the national information infrastructure
				to—</text>
										<clause id="HACA364571864438EA29CA5E59DDADCB1"><enum>(i)</enum><text>isolate, mitigate,
				or remediate incidents;</text>
										</clause><clause id="H55A83A8240004A63B414B28F7D0FF3AD"><enum>(ii)</enum><text>recover from
				damages and mitigate or remediate vulnerabilities; and</text>
										</clause><clause id="H3EA2709B6B574946B108F64A055191E3"><enum>(iii)</enum><text>evaluate
				security controls and other actions taken to secure information infrastructure
				and incorporate lessons learned into best practices, policies, principles, and
				guidelines.</text>
										</clause></subparagraph></paragraph><paragraph id="H53C42A10AFC84581B3829D81C6BAFBBD"><enum>(2)</enum><header>Requirement</header><text>With
				respect to the Federal information infrastructure, the US–CERT shall conduct
				the activities described in paragraph (1) in a manner consistent with the
				responsibilities of the head of a Federal agency described in section 3553 of
				title 44, United States Code.</text>
								</paragraph><paragraph id="H19274E5F544549D8A7E2EEB06A76DE40"><enum>(3)</enum><header>Report</header><text>Not
				later than 1 year after the date of enactment of this subtitle, and every year
				thereafter, the Secretary shall—</text>
									<subparagraph id="H6F47ADB8DD114ECD91BC055CCEF759C0"><enum>(A)</enum><text>in conjunction
				with the Inspector General of the Department, conduct an independent audit or
				review of the activities of the US–CERT under paragraph (1)(B); and</text>
									</subparagraph><subparagraph id="H8DB64F6EC0024A45813043A2DA75945F"><enum>(B)</enum><text>submit to the
				appropriate committees of Congress and the President a report regarding the
				audit or report.</text>
									</subparagraph></paragraph></subsection><subsection id="H1CCA3DA9A6DB4AD692B49D1B823C03D5"><enum>(d)</enum><header>Procedures for
				Federal Government</header><text>Not later than 90 days after the date of
				enactment of this subtitle, the head of each Federal agency shall establish
				procedures for the Federal agency that ensure that the US–CERT can perform the
				functions described in subsection (c) in relation to the Federal agency.</text>
							</subsection><subsection id="H249D7DDECABD41659FA969B3330C393C"><enum>(e)</enum><header>Operational
				updates</header><text>The US–CERT shall provide unclassified and, as
				appropriate, classified updates regarding the composite security state of the
				Federal information infrastructure to the Federal Information Security
				Taskforce.</text>
							</subsection><subsection id="H604B3A33AD4B489BB063B21E8F4CBF68"><enum>(f)</enum><header>Federal points
				of contact</header><text>The Director of the US–CERT shall designate a
				principal point of contact within the US–CERT for each Federal agency
				to—</text>
								<paragraph id="H2A7151D2C6314FE0A02F9B77CBF403E7"><enum>(1)</enum><text>maintain
				communication;</text>
								</paragraph><paragraph id="H760E2B9C3E95425790801CC482F03262"><enum>(2)</enum><text>ensure cooperative
				engagement and information sharing; and</text>
								</paragraph><paragraph id="H096712C6D7E44E80A6818A237EFDED0A"><enum>(3)</enum><text>respond to
				inquiries or requests.</text>
								</paragraph></subsection><subsection id="H789BE703CED141159C5D26B6A5A34F1C"><enum>(g)</enum><header>Requests for
				information or physical access</header>
								<paragraph id="H10AFF00D90AD46C48A72D4B0E86EE822"><enum>(1)</enum><header>Information
				access</header><text>Upon request of the Director of the US–CERT, the head of a
				Federal agency or an Inspector General for a Federal agency shall provide any
				law enforcement information, intelligence information, terrorism information,
				or any other information (including information relating to incidents provided
				under subsections (a)(4) and (c) of section 246) relevant to the security of
				the Federal information infrastructure or the national information
				infrastructure necessary to carry out the duties, responsibilities, and
				authorities under this subtitle.</text>
								</paragraph><paragraph id="HAEF503B4C4EC45E78E11DB6E496550A6"><enum>(2)</enum><header>Physical
				access</header><text>Upon request of the Director, and in consultation with the
				head of a Federal agency, the Federal agency shall provide physical access to
				any facility of the Federal agency necessary to determine whether the Federal
				agency is in compliance with any policies, principles, and guidelines
				established by the Director under this subtitle, or otherwise necessary to
				carry out the duties, responsibilities, and authorities of the Director
				applicable to the Federal information infrastructure.</text>
								</paragraph></subsection></section><section id="H6C6DB48482434F48AC2F4EF0986CFAC6"><enum>245.</enum><header>Additional
				authorities of the Director of the National Center for Cybersecurity and
				Communications</header>
							<subsection id="HA61D337377E84397AD4165775DF501B7"><enum>(a)</enum><header>Access to
				information</header><text>Unless otherwise directed by the President—</text>
								<paragraph id="H9F7FD8EBEA3A42678187F70303BAD87A"><enum>(1)</enum><text>the Director shall
				access, receive, and analyze law enforcement information, intelligence
				information, terrorism information, and any other information (including
				information relating to incidents provided under subsections (a)(4) and (c) of
				section 246) relevant to the security of the Federal information
				infrastructure, information infrastructure that is owned, operated, controlled,
				or licensed for use by, or on behalf of, the Department of Defense, a military
				department, or another element of the intelligence community, or national
				information infrastructure from Federal agencies and, consistent with
				applicable law, State and local governments (including law enforcement
				agencies), and private entities, including information provided by any
				contractor to a Federal agency regarding the security of the agency information
				infrastructure;</text>
								</paragraph><paragraph id="H56B9CE93289B4B14BB543C7289A4B3B3"><enum>(2)</enum><text>any Federal agency
				in possession of law enforcement information, intelligence information,
				terrorism information, or any other information (including information relating
				to incidents provided under subsections (a)(4) and (c) of section 246) relevant
				to the security of the Federal information infrastructure, information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, the Department of Defense, a military department, or another
				element of the intelligence community, or national information infrastructure
				shall provide that information to the Director in a timely manner; and</text>
								</paragraph><paragraph id="H7437CD55262D4A8ABADCF0719B9016A8"><enum>(3)</enum><text>the Director, in
				coordination with the Attorney General, the Privacy and Civil Liberties
				Oversight Board established under section 1061 of the National Security
				Intelligence Reform Act of 2004 (42 U.S.C. 2000ee), the Director of National
				Intelligence, and the Archivist of the United States, shall establish
				guidelines to ensure that information is transferred, stored, and preserved in
				accordance with applicable law and in a manner that protects the privacy and
				civil liberties of United States persons.</text>
								</paragraph></subsection><subsection id="H160217EEFA864EFBB0405F5D42D636E7"><enum>(b)</enum><header>Operational
				evaluations</header>
								<paragraph id="H33F87925ABC54873BCBB88D5C92125DC"><enum>(1)</enum><header>In
				general</header><text>The Director—</text>
									<subparagraph id="HE95CAE92A60A49E2894EE6619FC021A5"><enum>(A)</enum><text>subject to
				paragraph (2), shall develop, maintain, and enhance capabilities to evaluate
				the security of the Federal information infrastructure as described in section
				3554(a)(3) of title 44, United States Code, including the ability to conduct
				risk-based penetration testing and vulnerability assessments;</text>
									</subparagraph><subparagraph id="H41477A51957A490C9F95B9FD381B99EE"><enum>(B)</enum><text>in carrying out
				subparagraph (A), may request technical assistance from the Director of the
				Federal Bureau of Investigation, the Director of the National Security Agency,
				the head of any other Federal agency that may provide support, and any
				nongovernmental entity contracting with the Department or another Federal
				agency; and</text>
									</subparagraph><subparagraph id="HFF4935B672B7475EAF70A9ABC75F4FE9"><enum>(C)</enum><text>in consultation
				with the Attorney General and the Privacy and Civil Liberties Oversight Board
				established under section 1061 of the National Security Intelligence Reform Act
				of 2004 (42 U.S.C. 2000ee), shall develop guidelines to ensure compliance with
				all applicable laws relating to the privacy of United States persons in
				carrying out the operational evaluations under subparagraph (A).</text>
									</subparagraph></paragraph><paragraph id="H3392BDB71A7D494F811F8E0B7AD2ABB3"><enum>(2)</enum><header>Operational
				evaluations</header>
									<subparagraph id="H5ACC77BDB7FA4EF18120601BD13879F4"><enum>(A)</enum><header>In
				general</header><text>The Director may conduct risk-based operational
				evaluations of the agency information infrastructure of any Federal agency, at
				a time determined by the Director, in consultation with the head of the Federal
				agency, using the capabilities developed under paragraph (1)(A).</text>
									</subparagraph><subparagraph id="HCBBDA1635F994778881A0D8E92205BC2"><enum>(B)</enum><header>Annual
				evaluation requirement</header><text>If the Director conducts an operational
				evaluation under subparagraph (A) or an operational evaluation at the request
				of a Federal agency to meet the requirements of section 3554 of title 44,
				United States Code, the operational evaluation shall satisfy the requirements
				of section 3554 for the Federal agency for the year of the evaluation, unless
				otherwise specified by the Director.</text>
									</subparagraph></paragraph></subsection><subsection id="H2652A9569A8B4241B0EF6F0EC88DBB2A"><enum>(c)</enum><header>Corrective
				measures and mitigation plans</header><text>If the Director determines that a
				Federal agency is not in compliance with applicable policies, principles,
				standards, and guidelines applicable to the Federal information
				infrastructure—</text>
								<paragraph id="HFFC62C9EDC8B48D18E1520F99913EE2E"><enum>(1)</enum><text>the Director, in
				consultation with the Director of the Office of Management and Budget, may
				direct the head of the Federal agency to—</text>
									<subparagraph id="H1C0AA6F52C784D8DACE61057FE3A564E"><enum>(A)</enum><text>take corrective
				measures to meet the policies, principles, standards, and guidelines;
				and</text>
									</subparagraph><subparagraph id="H916289C103F14746BC1C378F6854CB19"><enum>(B)</enum><text>develop a plan to
				remediate or mitigate any vulnerabilities addressed by the policies,
				principles, standards, and guidelines;</text>
									</subparagraph></paragraph><paragraph id="H3FEFEFB5255F4450A539B415BAD58B30"><enum>(2)</enum><text>within such time
				period as the Director shall prescribe, the head of the Federal agency
				shall—</text>
									<subparagraph id="HC074067807574B8A89CC08D9F6D90D92"><enum>(A)</enum><text>implement a
				corrective measure or develop a mitigation plan in accordance with paragraph
				(1); or</text>
									</subparagraph><subparagraph id="H1B7D26D0696C431E8145342AE071F8EE"><enum>(B)</enum><text>submit to the
				Director, the Director of the Office of Management and Budget, the Inspector
				General for the Federal agency, and the appropriate committees of Congress a
				report indicating why the Federal agency has not implemented the corrective
				measure or developed a mitigation plan; and</text>
									</subparagraph></paragraph><paragraph id="HB4B1A8CF4B0246619E88ED05777DAB89"><enum>(3)</enum><text>the Director may
				direct the isolation of any component of the agency information infrastructure,
				consistent with the contingency or continuity of operation plans applicable to
				the agency information infrastructure, until corrective measures are taken or
				mitigation plans approved by the Director are put in place, if—</text>
									<subparagraph id="H37E8AE5A3673476B9F96529FCEE549E7"><enum>(A)</enum><text>the head of the
				Federal agency has failed to comply with the corrective measures prescribed
				under paragraph (1); and</text>
									</subparagraph><subparagraph id="H3AA876ACF8C543FDA37666BFC6BD08A6"><enum>(B)</enum><text>the failure to
				comply presents a significant danger to the Federal information
				infrastructure.</text>
									</subparagraph></paragraph></subsection></section><section id="H036FA693FA624DE9A9DBEAC900D36C5A"><enum>246.</enum><header>Information
				sharing</header>
							<subsection id="HBEB667DDAC744308A202164BE989E904"><enum>(a)</enum><header>Federal
				agencies</header>
								<paragraph id="HCA52C91C8B674DF5B98A95D9923E65DA"><enum>(1)</enum><header>Information
				sharing program</header><text>Consistent with the responsibilities described in
				section 242 and 244, the Director, in consultation with the other members of
				the Chief Information Officers Council established under section 3603 of title
				44, United States Code, and the Federal Information Security Taskforce, shall
				establish a program for sharing information with and between the Center and
				other Federal agencies that includes processes and procedures, including
				standard operating procedures—</text>
									<subparagraph id="HC9BB370E88F2486B9ED19D69B1F214B1"><enum>(A)</enum><text>under which the
				Director regularly shares with each Federal agency—</text>
										<clause id="H181C9F85ECAA45CD860F636B4C230377"><enum>(i)</enum><text>analysis and
				reports on the composite security state of the Federal information
				infrastructure and information infrastructure that is owned, operated,
				controlled, or licensed for use by, or on behalf of, the Department of Defense,
				a military department, or another element of the intelligence community, which
				shall include information relating to threats, vul­ner­a­bil­i­ties, incidents,
				or anomalous activities;</text>
										</clause><clause id="HB553D3401DB84517A14048931E225E5B"><enum>(ii)</enum><text>any available
				analysis and reports regarding the security of the agency information
				infrastructure; and</text>
										</clause><clause id="HEA2AC84DFAC94C5DB268EB17E350C389"><enum>(iii)</enum><text>means and
				methods of preventing, responding to, mitigating, and remediating
				vulnerabilities; and</text>
										</clause></subparagraph><subparagraph id="HB0A2F6D9F97F47AB9B001A1773D73409"><enum>(B)</enum><text>under which the
				Director may request information from Federal agencies concerning the security
				of the Federal information infrastructure, information infrastructure that is
				owned, operated, controlled, or licensed for use by, or on behalf of, the
				Department of Defense, a military department, or another element of the
				intelligence community, or the national information infrastructure necessary to
				carry out the duties of the Director under this subtitle or any other provision
				of law.</text>
									</subparagraph></paragraph><paragraph id="HB8A116894441496280C667636800DFFF"><enum>(2)</enum><header>Contents</header><text>The
				program established under this section shall include—</text>
									<subparagraph id="H64FA82A8B6174C508D7ED0483FEBEAF2"><enum>(A)</enum><text>timeframes for the
				sharing of information under paragraph (1);</text>
									</subparagraph><subparagraph id="H44DA2D42CDBB475BB2DCABE9A14D10CA"><enum>(B)</enum><text>guidance on what
				information shall be shared, including information regarding incidents;</text>
									</subparagraph><subparagraph id="HAB36CAC776DC4B8C9F3D579D759E6309"><enum>(C)</enum><text>a tiered structure
				that provides guidance for the sharing of urgent information; and</text>
									</subparagraph><subparagraph id="HD9566C501AA94921A45D0D7CEE87DE6D"><enum>(D)</enum><text>processes and
				procedures under which the Director or the head of a Federal agency may report
				noncompliance with the program to the Director of Cyberspace Policy.</text>
									</subparagraph></paragraph><paragraph id="H35C5282A328549D2A262B98B184D2646"><enum>(3)</enum><header>US–CERT</header><text>The
				Director of the US–CERT shall ensure that the head of each Federal agency has
				continual access to data collected by the US–CERT regarding the agency
				information infrastructure of the Federal agency.</text>
								</paragraph><paragraph id="H5EF6493D295D4598AB7EF1A1523088CE"><enum>(4)</enum><header>Federal
				agencies</header>
									<subparagraph id="H4E2A42027A1E4DE490DBB676A32C2703"><enum>(A)</enum><header>In
				general</header><text>The head of a Federal agency shall comply with all
				processes and procedures established under this subsection regarding
				notification to the Director relating to incidents.</text>
									</subparagraph><subparagraph id="HEE34494FBA054E77BD5B1DF8E0C91005"><enum>(B)</enum><header>Immediate
				notification required</header><text>Unless otherwise directed by the President,
				any Federal agency with a national security system shall immediately notify the
				Director regarding any incident affecting the risk-based security of the
				national security system.</text>
									</subparagraph></paragraph></subsection><subsection id="H5F07A238839B45FDA2BE7439BE53573B"><enum>(b)</enum><header>State and local
				governments, private sector, and international partners</header>
								<paragraph id="H452A71EBFEEA477DA1BD9E102376E071"><enum>(1)</enum><header>In
				general</header><text>The Director, shall establish processes and procedures,
				including standard operating procedures, to promote bidirectional information
				sharing with State and local governments, private entities, and international
				partners of the United States on—</text>
									<subparagraph id="H45E6C41FDF40428E8C38714E54FD4EDA"><enum>(A)</enum><text>threats,
				vulnerabilities, incidents, and anomalous activities affecting the national
				information infrastructure; and</text>
									</subparagraph><subparagraph id="H48358E034A054025B2575F6B2F6C5D1D"><enum>(B)</enum><text>means and methods
				of preventing, responding to, and mitigating and remediating
				vulnerabilities.</text>
									</subparagraph></paragraph><paragraph id="HAF6EA906BB844856827E417319E79211"><enum>(2)</enum><header>Contents</header><text>The
				processes and procedures established under paragraph (1) shall include—</text>
									<subparagraph id="H080FF010C7AA4B2C8FD21229E32E4764"><enum>(A)</enum><text>means or methods
				of accessing classified or unclassified information, as appropriate, that will
				provide situational awareness of the security of the Federal information
				infrastructure and the national information infrastructure relating to threats,
				vulnerabilities, traffic, trends, incidents, and other anomalous activities
				affecting the Federal information infrastructure or the national information
				infrastructure;</text>
									</subparagraph><subparagraph id="HF88D5C79D2DD4B31881095BA881E2AD9"><enum>(B)</enum><text>a mechanism,
				established in consultation with the heads of the relevant sector-specific
				agencies, sector coordinating councils, and information sharing and analysis
				centers, by which owners and operators of covered critical infrastructure shall
				report incidents in the information infrastructure for covered critical
				infrastructure, to the extent the incident might indicate an actual or
				potential cyber vulnerability, or exploitation of that vulnerability;
				and</text>
									</subparagraph><subparagraph id="HE772B7C8111B4E5FB0F64E150247F978"><enum>(C)</enum><text>an evaluation of
				the need to provide security clearances to employees of State and local
				governments, private entities, and international partners to carry out this
				subsection.</text>
									</subparagraph></paragraph><paragraph id="H18F058802E8747B99B983CA63DE62932"><enum>(3)</enum><header>Guidelines</header><text>The
				Director, in consultation with the Attorney General and the Director of
				National Intelligence, shall develop guidelines to protect the privacy and
				civil liberties of United States persons and intelligence sources and methods,
				while carrying out this subsection.</text>
								</paragraph></subsection><subsection id="H6B6133AC2980440CA0F35E6572538C32"><enum>(c)</enum><header>Incidents</header>
								<paragraph id="HB3D975E16F39434E9AE2FBE19C5B92FE"><enum>(1)</enum><header>Non-Federal
				entities</header>
									<subparagraph id="HD5B18888CCEF45FE9175F7C280617D48"><enum>(A)</enum><header>In
				general</header>
										<clause id="H21731DDE93004EBBA7584EB10C0AF748"><enum>(i)</enum><header>Mandatory
				reporting</header><text>Subject to clause (i), the owner or operator of covered
				critical infrastructure shall report any incident affecting the information
				infrastructure of covered critical infrastructure to the extent the incident
				might indicate an actual or potential cyber vulnerability, or exploitation of a
				cyber vulnerability, in accordance with the policies and procedures for the
				mechanism established under subsection (b)(2)(B) and guidelines developed under
				subsection (b)(3).</text>
										</clause><clause id="H43BAD50147814482A19CBF475218BD53"><enum>(ii)</enum><header>Limitation</header><text>Clause
				(i) shall not authorize the Director, the Center, the Department, or any other
				Federal entity to compel the disclosure of information relating to an incident
				or conduct surveillance unless otherwise authorized under chapter 119, chapter
				121, or chapter 206 of title 18, United States Code, the Foreign Intelligence
				Surveillance Act of 1978 (50 U.S.C. 1801 et seq.), or any other provision of
				law.</text>
										</clause></subparagraph><subparagraph id="H0939D5F3A8D04BC389697B20E2DC534F"><enum>(B)</enum><header>Reporting
				procedures</header><text>The Director shall establish procedures that enable
				and encourage the owner or operator of national information infrastructure to
				report to the Director regarding incidents affecting such information
				infrastructure.</text>
									</subparagraph></paragraph><paragraph id="H4FF02F70B21546CFA056FEFEA8F2B0B3"><enum>(2)</enum><header>Information
				protection</header><text>Notwithstanding any other provision of law,
				information reported under paragraph (1) shall be protected from unauthorized
				disclosure, in accordance with section 251.</text>
								</paragraph></subsection><subsection id="HF3E15E7297A34FB89C19C28D745DEE7B"><enum>(d)</enum><header>Additional
				responsibilities</header><text>In accordance with section 251, the Director
				shall—</text>
								<paragraph id="H3F4C29BEEE844270897408C280115E4B"><enum>(1)</enum><text>share data
				collected on the Federal information infrastructure with the National Science
				Foundation and other accredited research institutions for the sole purpose of
				cybersecurity research in a manner that protects privacy and civil liberties of
				United States persons and intelligence sources and methods;</text>
								</paragraph><paragraph id="HDC1FE1B1CACD433AB7FE05F5C3EE56A6"><enum>(2)</enum><text>establish a Web
				site to provide an opportunity for the public to provide—</text>
									<subparagraph id="H624CF571473548D0980136D6AC952716"><enum>(A)</enum><text>input about the
				operations of the Center; and</text>
									</subparagraph><subparagraph id="H46C7CA944EEC4BB8BAA9F7465484BA94"><enum>(B)</enum><text>recommendations
				for improvements of the Center; and</text>
									</subparagraph></paragraph><paragraph id="H26F39D65311A4CB6968095A738E9E644"><enum>(3)</enum><text>in coordination
				with the Secretary of Defense, the Director of National Intelligence, the
				Secretary of State, and the Attorney General, develop information sharing pilot
				programs with international partners of the United States.</text>
								</paragraph></subsection></section><section id="H158EAF78A29E4231B2DC9E11A323CB98"><enum>247.</enum><header>Private sector
				assistance</header>
							<subsection id="H737889C62B6243C3A7DA619E135D619F"><enum>(a)</enum><header>In
				general</header><text>The Director, in consultation with the Director of the
				National Institute of Standards and Technology, the Director of the National
				Security Agency, the head of any relevant sector-specific agency, the National
				Cybersecurity Advisory Council, State and local governments, and any private
				entities the Director determines appropriate, shall establish a program to
				promote, and provide technical assistance authorized under section 242(f)(1)(S)
				relating to the implementation of, best practices and related standards and
				guidelines for securing the national information infrastructure, including the
				costs and benefits associated with the implementation of the best practices and
				related standards and guidelines.</text>
							</subsection><subsection id="H854563C5C02A40D88DBBA3D1C30A2035"><enum>(b)</enum><header>Analysis and
				improvement of standards and guidelines</header><text>For purposes of the
				program established under subsection (a), the Director shall—</text>
								<paragraph id="H6A630213BB4A4F3387551CCDC82D08FC"><enum>(1)</enum><text>regularly assess
				and evaluate cybersecurity standards and guidelines issued by private sector
				organizations, recognized international and domestic standards setting
				organizations, and Federal agencies; and</text>
								</paragraph><paragraph id="H14A606CCAFCC43B789F7A31DCB29E73A"><enum>(2)</enum><text>in coordination
				with the National Institute of Standards and Technology, encourage the
				development of, and recommend changes to, the standards and guidelines
				described in paragraph (1) for securing the national information
				infrastructure.</text>
								</paragraph></subsection><subsection id="H98BE08BDE09748B78C574F3CAC6701CB"><enum>(c)</enum><header>Guidance and
				technical assistance</header>
								<paragraph id="HD5DF1AA5B2724F9BBE6EAA6038F99A3C"><enum>(1)</enum><header>In
				general</header><text>The Director shall promote best practices and related
				standards and guidelines to assist owners and operators of national information
				infrastructure in increasing the security of the national information
				infrastructure and protecting against and mitigating or remediating known
				vul­ner­a­bil­i­ties.</text>
								</paragraph><paragraph id="HD8AE89CB5BB04CE78C2A6548CFA409C8"><enum>(2)</enum><header>Requirement</header><text>Technical
				assistance provided under section 242(f)(1)(S) and best practices promoted
				under this section shall be prioritized based on risk.</text>
								</paragraph></subsection><subsection id="HB6B1A88762F74E958FCB04BDC3711294"><enum>(d)</enum><header>Criteria</header><text>In
				promoting best practices or recommending changes to standards and guidelines
				under this section, the Director shall ensure that best practices, and related
				standards and guidelines—</text>
								<paragraph id="H1A758C4DA36446E6BA2540F8850DD5C4"><enum>(1)</enum><text>address
				cybersecurity in a comprehensive, risk-based manner;</text>
								</paragraph><paragraph id="HC4C6D1355ADD423C9B44728138C29A59"><enum>(2)</enum><text>include
				consideration of the cost of implementing such best practices or of
				implementing recommended changes to standards and guidelines;</text>
								</paragraph><paragraph id="H61171558068E4738A42EBABDA2186048"><enum>(3)</enum><text>increase the
				ability of the owners or operators of national information infrastructure to
				protect against and mitigate or remediate known vul­ner­a­bil­i­ties;</text>
								</paragraph><paragraph id="H97D04ADAC6C145B7A0A6F74D5CA63C99"><enum>(4)</enum><text>are suitable, as
				appropriate, for implementation by small business concerns;</text>
								</paragraph><paragraph id="HE28B9CD062BD467BB13676F0B59AD82A"><enum>(5)</enum><text>as necessary and
				appropriate, are sector specific;</text>
								</paragraph><paragraph id="HF5321BFEEF96451790FD7486046BE512"><enum>(6)</enum><text>to the maximum
				extent possible, incorporate standards and guidelines established by private
				sector organizations, recognized international and domestic standards setting
				organizations, and Federal agencies; and</text>
								</paragraph><paragraph id="H18D33F343C354B46B169DF71F592E2F1"><enum>(7)</enum><text>provide sufficient
				flexibility to permit a range of security solutions.</text>
								</paragraph></subsection></section><section id="H42AC9DE4AFED454CBBC1FB5362C8E755"><enum>248.</enum><header>Cyber
				vulnerabilities to covered critical infrastructure</header>
							<subsection id="H3DF43967F6F9414BAF111BEEDA0972AF"><enum>(a)</enum><header>Identification
				of cyber vul­ner­a­bil­i­ties</header>
								<paragraph id="H32F579AAC6D9492A8EB1F4D199B21CEC"><enum>(1)</enum><header>In
				general</header><text>Based on the risk-based assessments conducted under
				section 242(f)(1)(T)(i), the Director, in coordination with the head of the
				sector-specific agency with responsibility for covered critical infrastructure
				and the head of any Federal agency that is not a sector-specific agency with
				responsibilities for regulating the covered critical infrastructure, and in
				consultation with the National Cybersecurity Advisory Council and any private
				sector entity determined appropriate by the Director, shall, on a continuous
				and sector-by-sector basis, identify and evaluate the cyber vulnerabilities to
				covered critical infrastructure.</text>
								</paragraph><paragraph id="H3DC4F271DCA8478EA1D99DB1E461BECD"><enum>(2)</enum><header>Factors to be
				considered</header><text>In identifying and evaluating cyber vulnerabilities
				under paragraph (1), the Director shall consider—</text>
									<subparagraph id="HD2C24D869E8B48F096AB2DE42A557CE5"><enum>(A)</enum><text>the perceived
				threat, including a consideration of adversary capabilities and intent,
				preparedness, target attractiveness, and deterrence capabilities;</text>
									</subparagraph><subparagraph id="H7DB620F7E3EE4F6BAC9581D342053A03"><enum>(B)</enum><text>the potential
				extent and likelihood of death, injury, or serious adverse effects to human
				health and safety caused by a disruption of the reliable operation of covered
				critical infrastructure;</text>
									</subparagraph><subparagraph id="H2685E12306A34D029919976E1FD2D067"><enum>(C)</enum><text>the threat to or
				potential impact on national security caused by a disruption of the reliable
				operation of covered critical infrastructure;</text>
									</subparagraph><subparagraph id="HCE4C4F2DC49F4C3180DF4C53A813EA61"><enum>(D)</enum><text>the extent to
				which the disruption of the reliable operation of covered critical
				infrastructure will disrupt the reliable operation of other covered critical
				infrastructure;</text>
									</subparagraph><subparagraph id="H91C0014E81074052B013AF5B8F2C388B"><enum>(E)</enum><text>the potential for
				harm to the economy that would result from a disruption of the reliable
				operation of covered critical infrastructure; and</text>
									</subparagraph><subparagraph id="H828ECAAE45CD4CB3B2E9AD5124E8D6F0"><enum>(F)</enum><text>other risk-based
				security factors that the Director, in consultation with the head of the
				sector-specific agency with responsibility for the covered critical
				infrastructure and the head of any Federal agency that is not a sector-specific
				agency with responsibilities for regulating the covered critical
				infrastructure, determine to be appropriate and necessary to protect public
				health and safety, critical infrastructure, or national and economic
				security.</text>
									</subparagraph></paragraph><paragraph id="H7E57940752354789A420138C9659156A"><enum>(3)</enum><header>Report</header>
									<subparagraph id="HD6CD097A37494E69909D8ADB60CDD639"><enum>(A)</enum><header>In
				general</header><text>Not later than 180 days after the date of enactment of
				this subtitle, and annually thereafter, the Director, in coordination with the
				head of the sector-specific agency with responsibility for the covered critical
				infrastructure and the head of any Federal agency that is not a sector-specific
				agency with responsibilities for regulating the covered critical
				infrastructure, shall submit to the appropriate committees of Congress a report
				on the findings of the identification and evaluation of cyber vulnerabilities
				under this subsection. Each report submitted under this paragraph shall be
				submitted in an unclassified form, but may include a classified annex.</text>
									</subparagraph><subparagraph id="H7CF9AF55AC354925BA499A55194EE4C9"><enum>(B)</enum><header>Input</header><text>For
				purposes of the reports required under subparagraph (A), the Director shall
				create a process under which owners and operators of covered critical
				infrastructure may provide input on the findings of the reports.</text>
									</subparagraph></paragraph></subsection><subsection id="H285C384C8BAA4272A6A789B0D686AF30"><enum>(b)</enum><header>Risk-Based
				performance requirements</header>
								<paragraph id="H57FD97F105E14D36AC8F63CF2C955AE9"><enum>(1)</enum><header>In
				general</header><text>Not later than 270 days after the date of the enactment
				of this subtitle, in coordination with the heads of the sector-specific
				agencies with responsibility for covered critical infrastructure and the head
				of any Federal agency that is not a sector-specific agency with
				responsibilities for regulating the covered critical infrastructure, and in
				consultation with the National Cybersecurity Advisory Council and any private
				sector entity determined appropriate by the Director, the Director shall issue
				interim final regulations establishing risk-based security performance
				requirements to secure covered critical infrastructure against cyber
				vul­ner­a­bil­i­ties through the adoption of security measures that satisfy the
				security performance requirements identified by the Director.</text>
								</paragraph><paragraph id="H0402C1431D1F43C9886A3EB78A43F4D0"><enum>(2)</enum><header>Procedures</header><text>The
				regulations issued under this subsection shall—</text>
									<subparagraph id="H9A0A1ADC2D8C49B9B0B29D62536C7240"><enum>(A)</enum><text>include a process
				under which owners and operators of covered critical infrastructure are
				informed of identified cyber vulnerabilities and security performance
				requirements designed to remediate or mitigate the cyber vulnerabilities, in
				combination with best practices recommended under section 247;</text>
									</subparagraph><subparagraph id="HF08630A62B734F1293C3E334DF03E43C"><enum>(B)</enum><text>establish a
				process for owners and operators of covered critical infrastructure to select
				security measures, including any best practices recommended under section 247,
				that, in combination, satisfy the security performance requirements established
				by the Director under this subsection;</text>
									</subparagraph><subparagraph id="HF5684E9DE550414CAC9B349C0C92E2E8"><enum>(C)</enum><text>establish a
				process for owners and operators of covered critical infrastructure to develop
				response plans for a national cyber emergency declared under section 249;
				and</text>
									</subparagraph><subparagraph id="H43C46CB81D7E400DA55BA10D2C473F42"><enum>(D)</enum><text>establish a
				process by which the Director—</text>
										<clause id="H96F06C87319543AB99E90C40A28FF193"><enum>(i)</enum><text>is
				notified of the security measures selected by the owner or operator of covered
				critical infrastructure under subparagraph (B); and</text>
										</clause><clause id="HC2560DEF5830423C90F3EF22C3C60CE9"><enum>(ii)</enum><text>may determine
				whether the proposed security measures satisfy the security performance
				requirements established by the Director under this subsection.</text>
										</clause></subparagraph></paragraph><paragraph id="H41C27981561D4F42BCBB76836F8FACC6"><enum>(3)</enum><header>International
				cooperation on securing covered critical infrastructure</header>
									<subparagraph id="HFDEDC551E4C54F6095230FD081BCE71B"><enum>(A)</enum><header>In
				general</header><text>The Director, in coordination with the head of the
				sector-specific agency with responsibility for covered critical infrastructure
				and the head of any Federal agency that is not a sector-specific agency with
				responsibilities for regulating the covered critical infrastructure,
				shall—</text>
										<clause id="HFFDA37C1D11E4629BCAEC1A288D67DDE"><enum>(i)</enum><text>consistent with
				the protection of intelligence sources and methods and other sensitive matters,
				inform the owner or operator of covered critical infrastructure that is located
				outside the United States and the government of the country in which the
				covered critical infrastructure is located of any cyber vulnerabilities to the
				covered critical infrastructure; and</text>
										</clause><clause id="H8F24181BA8184C459EA35488059E7FAF"><enum>(ii)</enum><text>coordinate with
				the government of the country in which the covered critical infrastructure is
				located and, as appropriate, the owner or operator of the covered critical
				infrastructure, regarding the implementation of security measures or other
				measures to the covered critical infrastructure to mitigate or remediate cyber
				vulnerabilities.</text>
										</clause></subparagraph><subparagraph id="H854515912A574DB18B991A70E97FA3E0"><enum>(B)</enum><header>International
				agreements</header><text>The Director shall carry out the this paragraph in a
				manner consistent with applicable international agreements.</text>
									</subparagraph></paragraph><paragraph id="HB80F1471956B41C1A24AE1A249357284"><enum>(4)</enum><header>Risk-based
				security performance requirements</header>
									<subparagraph id="HFA5E2328DB824F54BAB4E07857FF67FC"><enum>(A)</enum><header>In
				general</header><text>The security performance requirements established by the
				Director under this subsection shall be—</text>
										<clause id="H206989B8D3724F1387F0E664EECE18F1"><enum>(i)</enum><text>based on the
				factors listed in subsection (a)(2); and</text>
										</clause><clause id="HC07E1EA6AC244D4AA5A7DC5205DDE151"><enum>(ii)</enum><text>designed to
				remediate or mitigate identified cyber vulnerabilities and any associated
				consequences of an exploitation based on such vulnerabilities.</text>
										</clause></subparagraph><subparagraph id="H9171236DE5B9491884412B1C1D65E419"><enum>(B)</enum><header>Consultation</header><text>In
				establishing security performance requirements under this subsection, the
				Director shall, to the maximum extent practicable, consult with—</text>
										<clause id="H85D36CC3B0D04AB3A7FE79045DBA9A9F"><enum>(i)</enum><text>the Director of
				the National Security Agency;</text>
										</clause><clause id="HAFB73AC8D0C4423D87EC348C2B8D5ED7"><enum>(ii)</enum><text>the Director of
				the National Institute of Standards and Technology;</text>
										</clause><clause id="HFD87A17CE80F4BE0839F5BD7F6D7892D"><enum>(iii)</enum><text>the National
				Cybersecurity Advisory Council;</text>
										</clause><clause id="H7F356529B304400E83FA797787FD9723"><enum>(iv)</enum><text>the heads of
				sector-specific agencies; and</text>
										</clause><clause id="H6530457F28704CCD9D4390C7BC96D21E"><enum>(v)</enum><text>the heads of
				Federal agencies that are not a sector-specific agency with responsibilities
				for regulating the covered critical infrastructure.</text>
										</clause></subparagraph><subparagraph id="HF7B4A76D8EAD4D15AD33156EB8C95C3A"><enum>(C)</enum><header>Alternative
				measures</header>
										<clause id="H5203559C86BF4283965B8856F9CEE09D"><enum>(i)</enum><header>In
				general</header><text>The owners and operators of covered critical
				infrastructure shall have flexibility to implement any security measure, or
				combination thereof, to satisfy the security performance requirements described
				in subparagraph (A) and the Director may not disapprove under this section any
				proposed security measures, or combination thereof, based on the presence or
				absence of any particular security measure if the proposed security measures,
				or combination thereof, satisfy the security performance requirements
				established by the Director under this section.</text>
										</clause><clause commented="no" id="H1D1431464D9542D1B750193563F496BC"><enum>(ii)</enum><header>Recommended
				security measures</header><text>The Director may recommend to an owner and
				operator of covered critical infrastructure a specific security measure, or
				combination thereof, that will satisfy the security performance requirements
				established by the Director. The absence of the recommended security measures,
				or combination thereof, may not serve as the basis for a disapproval of the
				security measure, or combination thereof, proposed by the owner or operator of
				covered critical infrastructure if the proposed security measure, or
				combination thereof, otherwise satisfies the security performance requirements
				established by the Director under this section.</text>
										</clause></subparagraph></paragraph></subsection></section><section id="HE70DBC99F4154DD0AEEDD1E8DDF0A176"><enum>249.</enum><header>National cyber
				emergencies</header>
							<subsection id="HEF0D3DE0140C4FEA9ED39DC26592D1C6"><enum>(a)</enum><header>Declaration</header>
								<paragraph id="H1C92931961B64A5E8281EEEA0B71C9DF"><enum>(1)</enum><header>In
				general</header><text>The President may issue a declaration of a national cyber
				emergency to covered critical infrastructure. Any declaration under this
				section shall specify the covered critical infrastructure subject to the
				national cyber emergency.</text>
								</paragraph><paragraph id="HFCDAB386DD5D425DAD997AF9059C69CD"><enum>(2)</enum><header>Notification</header><text>Upon
				issuing a declaration under paragraph (1), the President shall, consistent with
				the protection of intelligence sources and methods, notify the owners and
				operators of the specified covered critical infrastructure of the nature of the
				national cyber emergency.</text>
								</paragraph><paragraph id="HF9C320338B1A4D99A6310A2F01184E88"><enum>(3)</enum><header>Authorities</header><text>If
				the President issues a declaration under paragraph (1), the Director
				shall—</text>
									<subparagraph id="H9F38D4E1A27D46FFB0DB430137ADDC97"><enum>(A)</enum><text>immediately direct
				the owners and operators of covered critical infrastructure subject to the
				declaration under paragraph (1) to implement response plans required under
				section 248(b)(2)(C);</text>
									</subparagraph><subparagraph id="H5C01BE03830445B487358181223F8988"><enum>(B)</enum><text>develop and
				coordinate emergency measures or actions necessary to preserve the reliable
				operation, and mitigate or remediate the consequences of the potential
				disruption, of covered critical infrastructure;</text>
									</subparagraph><subparagraph id="H0A1A052668D0474C8D827C850A1682DE"><enum>(C)</enum><text>ensure that
				emergency measures or actions directed under this section represent the least
				disruptive means feasible to the operations of the covered critical
				infrastructure;</text>
									</subparagraph><subparagraph id="HBFB3D73C2B5B4887A57EB03167FDE509"><enum>(D)</enum><text>subject to
				subsection (f), direct actions by other Federal agencies to respond to the
				national cyber emergency;</text>
									</subparagraph><subparagraph id="H4F02E9E0E61A477D8B5D56CE51ECDBA5"><enum>(E)</enum><text>coordinate with
				officials of State and local governments, international partners of the United
				States, and private owners and operators of covered critical infrastructure
				specified in the declaration to respond to the national cyber emergency;</text>
									</subparagraph><subparagraph id="H97402D70D19C4ECDAF36C905E6AF0A97"><enum>(F)</enum><text>initiate a process
				under section 248 to address the cyber vulnerability that may be exploited by
				the national cyber emergency; and</text>
									</subparagraph><subparagraph id="H6A65068D166345C18F474E51C41D30E3"><enum>(G)</enum><text>provide voluntary
				technical assistance, if requested, under section 242(f)(1)(S).</text>
									</subparagraph></paragraph><paragraph id="H39DF5A89CF004225B4A4378BA30B9C2F"><enum>(4)</enum><header>Reimbursement</header><text>A
				Federal agency shall be reimbursed for expenditures under this section from
				funds appropriated for the purposes of this section. Any funds received by a
				Federal agency as reimbursement for services or supplies furnished under the
				authority of this section shall be deposited to the credit of the appropriation
				or appropriations available on the date of the deposit for the services or
				supplies.</text>
								</paragraph><paragraph id="H2211E73AE27B40C28836C8A0F715BB09"><enum>(5)</enum><header>Consultation</header><text>In
				carrying out this section, the Director shall consult with the Secretary, the
				Secretary of Defense, the Director of the National Security Agency, the
				Director of the National Institute of Standards and Technology, and any other
				official, as directed by the President.</text>
								</paragraph><paragraph id="HADA5952C92814FAB81A33A37C376043E"><enum>(6)</enum><header>Privacy</header><text>In
				carrying out this section, the Director shall ensure that the privacy and civil
				liberties of United States persons are protected.</text>
								</paragraph></subsection><subsection id="H9D19136850EB430F8F96317DAC7204B1"><enum>(b)</enum><header>Discontinuance
				of emergency measures</header>
								<paragraph id="H1066792E71EC45E5927727B9AD31B796"><enum>(1)</enum><header>In
				general</header><text>Any emergency measure or action developed under this
				section shall cease to have effect not later than 30 days after the date on
				which the President issued the declaration of a national cyber emergency,
				unless—</text>
									<subparagraph id="H66B59C539E494B1F95D8D8AE45949016"><enum>(A)</enum><text>the Director
				affirms in writing that the emergency measure or action remains necessary to
				address the identified national cyber emergency; and</text>
									</subparagraph><subparagraph id="HFACD8A6F946C4EC199C2F75A3FBC4FCC"><enum>(B)</enum><text>the President
				issues a written order or directive reaffirming the national cyber emergency,
				the continuing nature of the national cyber emergency, or the need to continue
				the adoption of the emergency measure or action.</text>
									</subparagraph></paragraph><paragraph id="HA1806A558C3C47D986E8EE31ECDBA7F4"><enum>(2)</enum><header>Extensions</header><text>An
				emergency measure or action extended in accordance with paragraph (1)
				may—</text>
									<subparagraph id="H7F535B8B2F894108BEAFCF280FBC27C5"><enum>(A)</enum><text>remain in effect
				for not more than 30 days after the date on which the emergency measure or
				action was to cease to have effect; and</text>
									</subparagraph><subparagraph id="H710B38BE59824FB4AF2C75235E35B1F9"><enum>(B)</enum><text>be extended for
				additional 30-day periods, if the requirements of paragraph (1) and subsection
				(d) are met.</text>
									</subparagraph></paragraph></subsection><subsection id="H20C1D2BBDECA421BAAEA8ED6C60FF23A"><enum>(c)</enum><header>Compliance with
				emergency measures</header>
								<paragraph id="H6349AEEE17A844C3AB7B21486F7842EF"><enum>(1)</enum><header>In
				general</header><text>Subject to paragraph (2), the owner or operator of
				covered critical infrastructure shall immediately comply with any emergency
				measure or action developed by the Director under this section during the
				pendency of any declaration by the President under subsection (a)(1) or an
				extension under subsection (b)(2).</text>
								</paragraph><paragraph id="H246314C54C4C40C89F2E78DBBC0942D3"><enum>(2)</enum><header>Alternative
				measures</header><text>If the Director determines that a proposed security
				measure, or any combination thereof, submitted by the owner or operator of
				covered critical infrastructure in accordance with the process established
				under section 248(b)(2) addresses the cyber vulnerability associated with the
				national cyber emergency that is the subject of the declaration under this
				section, the owner or operator may comply with paragraph (1) of this subsection
				by implementing the proposed security measure, or combination thereof, approved
				by the Director under the process established under section 248. Before
				submission of a proposed security measure, or combination thereof, and during
				the pendency of any review by the Director under the process established under
				section 248, the owner or operator of covered critical infrastructure shall
				remain in compliance with any emergency measure or action developed by the
				Director under this section during the pendency of any declaration by the
				President under subsection (a)(1) or an extension under subsection (b)(2),
				until such time as the Director has approved an alternative proposed security
				measure, or combination thereof, under this paragraph.</text>
								</paragraph><paragraph id="H5B9001B51C0B4F5FB747732E07FE3188"><enum>(3)</enum><header>International
				cooperation on national cyber emergencies</header>
									<subparagraph id="H2376FF4DBC4248DFAD54534AD6A3BF1A"><enum>(A)</enum><header>In
				general</header><text>The Director, in coordination with the head of the
				sector-specific agency with responsibility for covered critical infrastructure
				and the head of any Federal agency that is not a sector-specific agency with
				responsibilities for regulating the covered critical infrastructure,
				shall—</text>
										<clause id="H2D3A83EC49D344C0BA77124E58954558"><enum>(i)</enum><text>consistent with
				the protection of intelligence sources and methods and other sensitive matters,
				inform the owner or operator of covered critical infrastructure that is located
				outside of the United States and the government of the country in which the
				covered critical infrastructure is located of any national cyber emergency
				affecting the covered critical infrastructure; and</text>
										</clause><clause id="H9621676531B84007AAA08DFF9776629D"><enum>(ii)</enum><text>coordinate with
				the government of the country in which the covered critical infrastructure is
				located and, as appropriate, the owner or operator of the covered critical
				infrastructure, regarding the implementation of emergency measures or actions
				necessary to preserve the reliable operation, and mitigate or remediate the
				consequences of the potential disruption, of the covered critical
				infrastructure.</text>
										</clause></subparagraph><subparagraph id="H4A8FCFA8D59F4F4691AB44F53653BAA1"><enum>(B)</enum><header>International
				agreements</header><text>The Director shall carry out this paragraph in a
				manner consistent with applicable international agreements.</text>
									</subparagraph></paragraph><paragraph id="H43A4B5B7BE7C4414AADFE99B91F66422"><enum>(4)</enum><header>Limitation on
				compliance authority</header><text>The authority to direct compliance with an
				emergency measure or action under this section shall not authorize the
				Director, the Center, the Department, or any other Federal entity to compel the
				disclosure of information or conduct surveillance unless otherwise authorized
				under chapter 119, chapter 121, or chapter 206 of title 18, United States Code,
				the Foreign Intelligence Surveillance Act of 1978 (50 U.S.C. 1801 et seq.), or
				any other provision of law.</text>
								</paragraph></subsection><subsection id="H05E4D1BB72674349850FB63BFBD0877B"><enum>(d)</enum><header>Reporting</header>
								<paragraph id="HA0C794B8DCFF476C87C9B2661BCC5927"><enum>(1)</enum><header>In
				general</header><text>Except as provided in paragraph (2), the President shall
				ensure that any declaration under subsection (a)(1) or any extension under
				subsection (b)(2) is reported to the appropriate committees of Congress before
				the Director mandates any emergency measure or actions under subsection
				(a)(3).</text>
								</paragraph><paragraph id="HFCF76CDD26A8495FA2D6F1388ADA2761"><enum>(2)</enum><header>Exception</header><text>If
				notice cannot be given under paragraph (1) before mandating any emergency
				measure or actions under subsection (a)(3), the President shall provide the
				report required under paragraph (1) as soon as possible, along with a statement
				of the reasons for not providing notice in accordance with paragraph
				(1).</text>
								</paragraph><paragraph id="H35B8A376C09544138F5B086E524F3076"><enum>(3)</enum><header>Contents</header><text>Each
				report under this subsection shall describe—</text>
									<subparagraph id="HE62187B690B045319FCD69505681F3B2"><enum>(A)</enum><text>the nature of the
				national cyber emergency;</text>
									</subparagraph><subparagraph id="H9E1A1B1FB6A04498B0C4B51E7A90DB90"><enum>(B)</enum><text>the reasons that
				risk-based security requirements under section 248 are not sufficient to
				address the national cyber emergency; and</text>
									</subparagraph><subparagraph id="H7D72241B2ABD40A8B2C8F0F8A6F21447"><enum>(C)</enum><text>the actions
				necessary to preserve the reliable operation and mitigate the consequences of
				the potential disruption of covered critical infrastructure.</text>
									</subparagraph></paragraph></subsection><subsection id="HD1FB2F16820F46FB8DA42DB7B95A1955"><enum>(e)</enum><header>Statutory
				defenses and civil liability limitations for compliance with emergency
				measures</header>
								<paragraph id="HE7B91D7DF7974A96B6C0BAC3491B8CD2"><enum>(1)</enum><header>Definitions</header><text>In
				this subsection—</text>
									<subparagraph id="HD034747A102448939C52EC6C44DD0B96"><enum>(A)</enum><text>the term
				<term>covered civil action</term>—</text>
										<clause id="H5C73E1305B58455C9D3BA70A89C384DC"><enum>(i)</enum><text>means a civil
				action filed in a Federal or State court against a covered entity; and</text>
										</clause><clause id="HA71FA56EC37E4130B012084C26E7E0A6"><enum>(ii)</enum><text>does not include
				an action brought under section 2520 or 2707 of title 18, United States Code,
				or section 110 or 308 of the Foreign Intelligence Surveillance Act of 1978 (50
				U.S.C. 1810 and 1828);</text>
										</clause></subparagraph><subparagraph id="H513FCD34D02A49EDB92C030B7F2C4218"><enum>(B)</enum><text>the term
				<term>covered entity</term> means any entity that owns or operates covered
				critical infrastructure, including any owner, operator, officer, employee,
				agent, landlord, custodian, or other person acting for or on behalf of that
				entity with respect to the covered critical infrastructure; and</text>
									</subparagraph><subparagraph id="HEE12F82846C84E238B4D422E12F6F31F"><enum>(C)</enum><text>the term
				<term>noneconomic damages</term> means damages for losses for physical and
				emotional pain, suffering, inconvenience, physical impairment, mental anguish,
				disfigurement, loss of enjoyment of life, loss of society and companionship,
				loss of consortium, hedonic damages, injury to reputation, and any other
				nonpecuniary losses.</text>
									</subparagraph></paragraph><paragraph id="HCF3422FDE5C94845B8A50F5A66A3481C"><enum>(2)</enum><header>Application of
				limitations on civil liability</header><text>The limitations on civil liability
				under paragraph (3) apply if—</text>
									<subparagraph id="HCD047EE46CD047DF9275FD76BF73B4DF"><enum>(A)</enum><text>the President has
				issued a declaration of national cyber emergency under subsection
				(a)(1);</text>
									</subparagraph><subparagraph id="HE5B85DA62A85429D8C635CCE8700811F"><enum>(B)</enum><text>the Director
				has—</text>
										<clause id="H7942A52F97F2492E9E659B8D85CE9E13"><enum>(i)</enum><text>issued emergency
				measures or actions for which compliance is required under subsection (c)(1);
				or</text>
										</clause><clause id="H654A02A793674E38AD8682F8BA6EF1D6"><enum>(ii)</enum><text>approved security
				measures under subsection (c)(2);</text>
										</clause></subparagraph><subparagraph id="H315F6D94B37548DF91D3B1B9FB596A2D"><enum>(C)</enum><text>the covered entity
				is in compliance with—</text>
										<clause id="H78890ED6D6DA4E43A3A9897970360F35"><enum>(i)</enum><text>the emergency
				measures or actions required under subsection (c)(1); or</text>
										</clause><clause id="H93A53247E6E24BC283EDCF5AD869A6C6"><enum>(ii)</enum><text>security measures
				which the Director has approved under subsection (c)(2); and</text>
										</clause></subparagraph><subparagraph id="H0D585D617E4641589DB2CA9732667424"><enum>(D)</enum><clause commented="no" display-inline="yes-display-inline" id="H47D1D666C1534588B6A69841962FE7B0"><enum>(i)</enum><text>the Director certifies
				to the court in which the covered civil action is pending that the actions
				taken by the covered entity during the period covered by the declaration under
				subsection (a)(1) were consistent with—</text>
											<subclause id="H9A79B254235D4838919032CB1902E9B0" indent="up1"><enum>(I)</enum><text>emergency measures or actions for which
				compliance is required under subsection (c)(1); or</text>
											</subclause><subclause id="HB8758A11B3F7493A9225436084698D68" indent="up1"><enum>(II)</enum><text>security measures which the Director has
				approved under subsection (c)(2); or</text>
											</subclause></clause><clause id="H555923F1B6D14450AF5765D456737F65" indent="up1"><enum>(ii)</enum><text>notwithstanding the lack of a
				certification, the covered entity demonstrates by a preponderance of the
				evidence that the actions taken during the period covered by the declaration
				under subsection (a)(1) are consistent with the implementation of—</text>
											<subclause id="HE983EED9E5D64BCFA95D802B157D5359"><enum>(I)</enum><text>emergency measures or actions for which
				compliance is required under subsection (c)(1); or</text>
											</subclause><subclause id="H5F69B2C3AA77430F9B0B44364A887B42"><enum>(II)</enum><text>security measures which the Director has
				approved under subsection (c)(2).</text>
											</subclause></clause></subparagraph></paragraph><paragraph id="H539F08B4011C490D8ECB560AB3E397B5"><enum>(3)</enum><header>Limitations on
				civil liability</header><text>In any covered civil action that is related to
				any incident associated with a cyber vulnerability covered by a declaration of
				a national cyber emergency and for which Director has issued emergency measures
				or actions for which compliance is required under subsection (c)(1) or for
				which the Director has approved security measures under subsection (c)(2), or
				that is the direct consequence of actions taken in good faith for the purpose
				of implementing security measures or actions which the Director has approved
				under subsection (c)(2)—</text>
									<subparagraph id="HAAD9EAF798DF44AC9DAA894E9EAF9593"><enum>(A)</enum><text>the covered entity
				shall not be liable for any punitive damages intended to punish or deter,
				exemplary damages, or other damages not intended to compensate a plaintiff for
				actual losses; and</text>
									</subparagraph><subparagraph commented="no" id="H7B8348ACED2148C3BD8260E609E88B21"><enum>(B)</enum><text>noneconomic
				damages may be awarded against a defendant only in an amount directly
				proportional to the percentage of responsibility of such defendant for the harm
				to the plaintiff, and no plaintiff may recover noneconomic damages unless the
				plaintiff suffered physical harm.</text>
									</subparagraph></paragraph><paragraph id="H53ADE1705DDC4C389D8E7C9CD5B47BA1"><enum>(4)</enum><header>Civil actions
				arising out of implementation of emergency measures or actions</header><text>A
				covered civil action may not be maintained against a covered entity that is the
				direct consequence of actions taken in good faith for the purpose of
				implementing specific emergency measures or actions for which compliance is
				required under subsection (c)(1), if—</text>
									<subparagraph id="HEC5621F4A5294D0FBAEAE5D4DCA214F6"><enum>(A)</enum><text>the President has
				issued a declaration of national cyber emergency under subsection (a)(1) and
				the action was taken during the period covered by that declaration;</text>
									</subparagraph><subparagraph id="HA806524847414C7A85784EEB297796EE"><enum>(B)</enum><text>the Director has
				issued emergency measures or actions for which compliance is required under
				subsection (c)(1);</text>
									</subparagraph><subparagraph id="HE5AB572908F94BD58B5E1A1A85C806E9"><enum>(C)</enum><text>the covered entity
				is in compliance with the emergency measures required under subsection (c)(1);
				and</text>
									</subparagraph><subparagraph id="H892E1CBB1E9B4413A2D9880DFDE6B3CC"><enum>(D)</enum><clause commented="no" display-inline="yes-display-inline" id="HBAB82416DC734C858F7BEDDDDC9152EA"><enum>(i)</enum><text>the Director certifies
				to the court in which the covered civil action is pending that the actions
				taken by the entity during the period covered by the declaration under
				subsection (a)(1) were consistent with the implementation of emergency measures
				or actions for which compliance is required under subsection (c)(1); or</text>
										</clause><clause id="H596F4F49098C4A0E95B1FBA8B409908D" indent="up1"><enum>(ii)</enum><text>notwithstanding the lack of a
				certification, the entity demonstrates by a preponderance of the evidence that
				the actions taken during the period covered by the declaration under subsection
				(a)(1) are consistent with the implementation of emergency measures or actions
				for which compliance is required under subsection (c)(1).</text>
										</clause></subparagraph></paragraph><paragraph id="H5135C07C4351487BA350E7BCAB4A34D8"><enum>(5)</enum><header>Certain actions
				not subject to limitations on liability</header>
									<subparagraph id="H7B00251834EB4C50ACB26619AD476AF3"><enum>(A)</enum><header>Additional or
				intervening acts</header><text>Paragraphs (2) through (4) shall not apply to a
				civil action relating to any additional or intervening acts or omissions by any
				covered entity.</text>
									</subparagraph><subparagraph commented="no" id="H49820531606C436FB1528213787399AC"><enum>(B)</enum><header>Serious or
				substantial damage</header><text>Paragraph (4) shall not apply to any civil
				action brought by an individual—</text>
										<clause commented="no" id="H300A1927533944218C70CFF049492A76"><enum>(i)</enum><text>whose recovery is
				otherwise precluded by application of paragraph (4); and</text>
										</clause><clause commented="no" id="HDDE2C4B286D04F779179D1742D518D3E"><enum>(ii)</enum><text>who has
				suffered—</text>
											<subclause commented="no" id="H716B218B63574E009AE2BC8F3E31C895"><enum>(I)</enum><text>serious physical
				injury or death; or</text>
											</subclause><subclause commented="no" id="HAC50DC04602B4EC3A5C8C5DFC7160ED5"><enum>(II)</enum><text>substantial
				damage or destruction to his primary residence.</text>
											</subclause></clause></subparagraph><subparagraph id="HF37343FEE2814B418A8DEDBD9466BE75"><enum>(C)</enum><header>Rule of
				construction</header><text>Recovery available under subparagraph (B) shall be
				limited to those damages available under subparagraphs (A) and (B) of paragraph
				(3), except that neither reasonable and necessary medical benefits nor lifetime
				total benefits for lost employment income due to permanent and total disability
				shall be limited herein.</text>
									</subparagraph><subparagraph id="H1B19F96AECD6458C98380E6B5144A905"><enum>(D)</enum><header>Indemnification</header><text>In
				any civil action brought under subparagraph (B), the United States shall defend
				and indemnify any covered entity. Any covered entity defended and indemnified
				under this subparagraph shall fully cooperate with the United States in the
				defense by the United States in any proceeding and shall be reimbursed the
				reasonable costs associated with such cooperation.</text>
									</subparagraph></paragraph></subsection><subsection id="H62062C444A0B4C319688E22367E61CDB"><enum>(f)</enum><header>Rule of
				construction</header><text>Nothing in this section shall be construed
				to—</text>
								<paragraph id="HE7CE7FB50F40419298FEE180F9A27177"><enum>(1)</enum><text>alter or supersede
				the authority of the Secretary of Defense, the Attorney General, or the
				Director of National Intelligence in responding to a national cyber emergency;
				or</text>
								</paragraph><paragraph id="H08D31278B7874BA99D6C8DE5B29E94DD"><enum>(2)</enum><text>limit the
				authority of the Director under section 248, after a declaration issued under
				this section expires.</text>
								</paragraph></subsection></section><section id="H5D2EB9B53BCC44789F63FC8A543B400D"><enum>250.</enum><header>Enforcement</header>
							<subsection id="H75EB4CD0E20E4A5AAF7F964A50D562A5"><enum>(a)</enum><header>Annual
				certification of compliance</header>
								<paragraph id="HAF230E3BE8CD4A76BED881CBFC539D8B"><enum>(1)</enum><header>In
				general</header><text>Not later than 6 months after the date on which the
				Director promulgates regulations under section 248(b), and every year
				thereafter, each owner or operator of covered critical infrastructure shall
				certify in writing to the Director whether the owner or operator has developed
				and implemented, or is implementing, security measures approved by the Director
				under section 248 and any applicable emergency measures or actions required
				under section 249 for any cyber vulnerabilities and national cyber
				emergencies.</text>
								</paragraph><paragraph id="H103A5E1AA6C140C7A1FB43DC5B374015"><enum>(2)</enum><header>Failure to
				comply</header><text>If an owner or operator of covered critical infrastructure
				fails to submit a certification in accordance with paragraph (1), or if the
				certification indicates the owner or operator is not in compliance, the
				Director may issue an order requiring the owner or operator to submit proposed
				security measures under section 248 or comply with specific emergency measures
				or actions under section 249.</text>
								</paragraph></subsection><subsection id="H5C50ED7C94414609A5DA66CFE53E7871"><enum>(b)</enum><header>Risk-Based
				evaluations</header>
								<paragraph id="H24F18212DEFD4E7E8219A2C28211F4D7"><enum>(1)</enum><header>In
				general</header><text>Consistent with the factors described in paragraph (3),
				the Director may perform an evaluation of the information infrastructure of any
				specific system or asset constituting covered critical infrastructure to assess
				the validity of a certification of compliance submitted under subsection
				(a)(1).</text>
								</paragraph><paragraph id="H7CC3C48D0B894BA4B4CAF09417C0C9A9"><enum>(2)</enum><header>Document review
				and inspection</header><text>An evaluation performed under paragraph (1) may
				include—</text>
									<subparagraph id="HC75C67F018974952A822818C92F1EF12"><enum>(A)</enum><text>a review of all
				documentation submitted to justify an annual certification of compliance
				submitted under subsection (a)(1); and</text>
									</subparagraph><subparagraph id="HF70F643764864AC3AC2AFF81D4664E2D"><enum>(B)</enum><text>a physical or
				electronic inspection of relevant information infrastructure to which the
				security measures required under section 248 or the emergency measures or
				actions required under section 249 apply.</text>
									</subparagraph></paragraph><paragraph id="H3667E4E66E334BFF8AF479C37C092AA3"><enum>(3)</enum><header>Evaluation
				selection factors</header><text>In determining whether sufficient risk exists
				to justify an evaluation under this subsection, the Director shall
				consider—</text>
									<subparagraph id="H030EE729AD2B4324AC8FA7487BA7C019"><enum>(A)</enum><text>the specific cyber
				vulnerabilities affecting or potentially affecting the information
				infrastructure of the specific system or asset constituting covered critical
				infrastructure;</text>
									</subparagraph><subparagraph id="H05059AB796F84977B83E3FA785E05E62"><enum>(B)</enum><text>any reliable
				intelligence or other information indicating a cyber vulnerability or credible
				national cyber emergency to the information infrastructure of the specific
				system or asset constituting covered critical infrastructure;</text>
									</subparagraph><subparagraph id="H9BDA5A2FE1274E1DA1F18D54D1BF7F7C"><enum>(C)</enum><text>actual knowledge
				or reasonable suspicion that the certification of compliance submitted by a
				specific owner or operator of covered critical infrastructure is false or
				otherwise inaccurate;</text>
									</subparagraph><subparagraph id="H30112B25483F4AB5986DCA7DEDEE4AA4"><enum>(D)</enum><text>a request by a
				specific owner or operator of covered critical infrastructure for such an
				evaluation; and</text>
									</subparagraph><subparagraph id="H45C52290DFAD428395F1C6C946F61EAD"><enum>(E)</enum><text>such other
				risk-based factors as identified by the Director.</text>
									</subparagraph></paragraph><paragraph id="H879DAD0E3716433DA5BA602321500D88"><enum>(4)</enum><header>Sector-specific
				agencies</header><text>To carry out the risk-based evaluation authorized under
				this subsection, the Director may use the resources of a sector-specific agency
				with responsibility for the covered critical infrastructure or any Federal
				agency that is not a sector-specific agency with responsibilities for
				regulating the covered critical infrastructure with the concurrence of the head
				of the agency.</text>
								</paragraph><paragraph id="HA4FA738E60F14201A980D17850EDBF92"><enum>(5)</enum><header>Information
				protection</header><text>Information provided to the Director during the course
				of an evaluation under this subsection shall be protected from disclosure in
				accordance with section 251.</text>
								</paragraph></subsection><subsection commented="no" id="H0AD62084212141258B3E2A6DC7D184EE"><enum>(c)</enum><header>Civil
				penalties</header>
								<paragraph commented="no" id="H1A2F1F982E8543D8BA550B151BAB4194"><enum>(1)</enum><header>In
				general</header><text>Any person who violates section 248 or 249 shall be
				liable for a civil penalty.</text>
								</paragraph><paragraph commented="no" id="H02ACBCBABF9B46C6BF8E3767A6DDAE87"><enum>(2)</enum><header>No private right
				of action</header><text>Nothing in this section confers upon any person, except
				the Director, a right of action against an owner or operator of covered
				critical infrastructure to enforce any provision of this subtitle.</text>
								</paragraph></subsection><subsection id="H7E279F65529E40DEB9102CB1928F794F"><enum>(d)</enum><header>Limitation on
				civil liability</header>
								<paragraph id="H48E5F34BB3324A6A95EA65F5865663B2"><enum>(1)</enum><header>Definition</header><text>In
				this subsection—</text>
									<subparagraph id="H6B69D25FC04E4307B57EAF22AC007AF3"><enum>(A)</enum><text>the term
				<term>covered civil action</term>—</text>
										<clause id="H6DE0B56D0E2B4F9EB9A1481566B6AAF7"><enum>(i)</enum><text>means a civil
				action filed in a Federal or State court against a covered entity; and</text>
										</clause><clause id="H7B73610E0BE44CDD8FC185F663EF5822"><enum>(ii)</enum><text>does not include
				an action brought under section 2520 or 2707 of title 18, United States Code,
				or section 110 or 308 of the Foreign Intelligence Surveillance Act of 1978 (50
				U.S.C. 1810 and 1828);</text>
										</clause></subparagraph><subparagraph id="H621DFD9348184DA1A7FBAB1F3B85C16B"><enum>(B)</enum><text>the term
				<term>covered entity</term> means any entity that owns or operates covered
				critical infrastructure, including any owner, operator, officer, employee,
				agent, landlord, custodian, or other person acting for or on behalf of that
				entity with respect to the covered critical infrastructure; and</text>
									</subparagraph><subparagraph id="HFA0BE3C225FD40F08B62AA7A0C696DCC"><enum>(C)</enum><text>the term
				<term>noneconomic damages</term> means damages for losses for physical and
				emotional pain, suffering, inconvenience, physical impairment, mental anguish,
				disfigurement, loss of enjoyment of life, loss of society and companionship,
				loss of consortium, hedonic damages, injury to reputation, and any other
				nonpecuniary losses.</text>
									</subparagraph></paragraph><paragraph id="HD0B4F89775974BAF8B95219EC50C2F31"><enum>(2)</enum><header>Limitations on
				civil liability</header><text>If a covered entity experiences an incident
				related to a cyber vulnerability identified under section 248(a), in any
				covered civil action for damages directly caused by the incident related to
				that cyber vulnerability—</text>
									<subparagraph id="H403DC1AC78CF49B4B973C7F9F00B7E85"><enum>(A)</enum><text>the covered entity
				shall not be liable for any punitive damages intended to punish or deter,
				exemplary damages, or other damages not intended to compensate a plaintiff for
				actual losses; and</text>
									</subparagraph><subparagraph id="HB313824B5B81414B87E345A9525CFEAA"><enum>(B)</enum><text>noneconomic
				damages may be awarded against a defendant only in an amount directly
				proportional to the percentage of responsibility of such defendant for the harm
				to the plaintiff, and no plaintiff may recover noneconomic damages unless the
				plaintiff suffered physical harm.</text>
									</subparagraph></paragraph><paragraph id="HA771FF000C0F4301B6834D32B26B1CA6"><enum>(3)</enum><header>Application</header><text>This
				subsection shall apply to claims made by any individual or nongovernmental
				entity, including claims made by a State or local government agency on behalf
				of such individuals or nongovernmental entities, against a covered
				entity—</text>
									<subparagraph id="H45A44AC7DE334FCB853C142AC2439622"><enum>(A)</enum><text>whose proposed
				security measures, or combination thereof, satisfy the security performance
				requirements established under subsection 248(b) and have been approved by the
				Director;</text>
									</subparagraph><subparagraph id="H658F1F0FD42A4F83AC7EB1DEBF0521D3"><enum>(B)</enum><text>that has been
				evaluated under subsection (b) and has been found by the Director to have
				implemented the proposed security measures approved under section 248;
				and</text>
									</subparagraph><subparagraph id="HABE99DFBE1CF4B58A9A087D183B72A1F"><enum>(C)</enum><text>that is in actual
				compliance with the approved security measures at the time of the incident
				related to that cyber vulnerability.</text>
									</subparagraph></paragraph><paragraph id="H7C23CBBF1E0049E982542FCE2E0587D8"><enum>(4)</enum><header>Limitation</header><text>This
				subsection shall only apply to harm directly caused by the incident related to
				the cyber vulnerability and shall not apply to damages caused by any additional
				or intervening acts or omissions by the covered entity.</text>
								</paragraph><paragraph id="H48F02309A57E46BDA5B35A8C130C8C6D"><enum>(5)</enum><header>Rule of
				construction</header><text>Except as provided under paragraph (3), nothing in
				this subsection shall be construed to abrogate or limit any right, remedy, or
				authority that the Federal Government or any State or local government, or any
				entity or agency thereof, may possess under any law, or that any individual is
				authorized by law to bring on behalf of the government.</text>
								</paragraph></subsection><subsection id="HF2AB129232C24B0C9E525509E698F15A"><enum>(e)</enum><header>Report to
				Congress</header><text>The Director shall submit an annual report to the
				appropriate committees of Congress on the implementation and enforcement of the
				risk-based performance requirements of covered critical infrastructure under
				subsection 248(b) and this section including—</text>
								<paragraph id="H9A35E6ACB4514570924D797A6543FDD7"><enum>(1)</enum><text>the level of
				compliance of covered critical infrastructure with the risk-based security
				performance requirements issued under section 248(b);</text>
								</paragraph><paragraph id="HE903252DCDF5458987515758DC196245"><enum>(2)</enum><text>how frequently the
				evaluation authority under subsection (b) was utilized and a summary of the
				aggregate results of the evaluations; and</text>
								</paragraph><paragraph id="HD8ABA5FD7AF1407D839504F91D04DE97"><enum>(3)</enum><text>any civil
				penalties imposed on covered critical infrastructure.</text>
								</paragraph></subsection></section><section commented="no" id="H6E76753D531C44299BEBB30F38434162"><enum>251.</enum><header>Protection of
				information</header>
							<subsection commented="no" id="HB722C85097C847E98B46A8478812347E"><enum>(a)</enum><header>Definition</header><text>In
				this section, the term <term>covered information</term>—</text>
								<paragraph commented="no" id="H0FA32C95373F4322A7D23FDA19DDA547"><enum>(1)</enum><text>means—</text>
									<subparagraph id="H93D090D39A1C45A6AA2F79D03FE3114D"><enum>(A)</enum><text>any information
				required to be submitted under sections 246, 248, and 249 to the Center by the
				owners and operators of covered critical infrastructure; and</text>
									</subparagraph><subparagraph id="H922964DF8A4E44FAB2166492E1BD7E0A"><enum>(B)</enum><text>any information
				submitted to the Center under the processes and procedures established under
				section 246 by State and local governments, private entities, and international
				partners of the United States regarding threats, vulnerabilities, and incidents
				affecting—</text>
										<clause id="H415892A97E0042AE8AB61993E4A6E07B"><enum>(i)</enum><text>the Federal
				information infrastructure;</text>
										</clause><clause id="HC4C9339050334E5093D01CA62FE4B492"><enum>(ii)</enum><text>information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, the Department of Defense, a military department, or another
				element of the intelligence community; or</text>
										</clause><clause id="H89017AD1E694414DAA68BDA310017F3F"><enum>(iii)</enum><text>the national
				information infrastructure; and</text>
										</clause></subparagraph></paragraph><paragraph id="HE1F4A5398D0244D99159C8CB55CDA060"><enum>(2)</enum><text>shall not include
				any information described under paragraph (1), if that information is submitted
				to—</text>
									<subparagraph id="HE9709173CC4A44A1BC363255FDD2CE4F"><enum>(A)</enum><text>conceal violations
				of law, inefficiency, or administrative error;</text>
									</subparagraph><subparagraph id="HC436BF6EC3264067AAC6E1F1F453B9C4"><enum>(B)</enum><text>prevent
				embarrassment to a person, organization, or agency; or</text>
									</subparagraph><subparagraph id="H062D8A2EB3FD450BAB27C23D80CF0772"><enum>(C)</enum><text>interfere with
				competition in the private sector.</text>
									</subparagraph></paragraph></subsection><subsection id="H5D46C4E0FB3147A09977073FF127151B"><enum>(b)</enum><header>Voluntarily
				shared critical infrastructure information</header><text>Covered information
				submitted in accordance with this section shall be treated as voluntarily
				shared critical infrastructure information under section 214, except that the
				requirement of section 214 that the information be voluntarily submitted,
				including the requirement for an express statement, shall not be required for
				submissions of covered information.</text>
							</subsection><subsection id="H483721C744A14B63AED714FA439B5137"><enum>(c)</enum><header>Guidelines</header>
								<paragraph id="H6C2D3B734EAC4681B60FA162608707FB"><enum>(1)</enum><header>In
				general</header><text>Subject to paragraph (2), the Director shall develop and
				issue guidelines, in consultation with the Secretary, Attorney General, and the
				National Cybersecurity Advisory Council, as necessary to implement this
				section.</text>
								</paragraph><paragraph id="H2C2AE7EF63404EB39309C2F9EC036BCC"><enum>(2)</enum><header>Requirements</header><text>The
				guidelines developed under this section shall—</text>
									<subparagraph id="H732852B107364BABB110735BE9F28140"><enum>(A)</enum><text>consistent with
				section 214(e)(2)(D) and (g) and the guidelines developed under section
				246(b)(3), include provisions for information sharing among Federal, State, and
				local and officials, private entities, or international partners of the United
				States necessary to carry out the authorities and responsibilities of the
				Director;</text>
									</subparagraph><subparagraph id="HDA6B0BC41C7F4AA4B07E6C06C0465199"><enum>(B)</enum><text>be consistent, to
				the maximum extent possible, with policy guidance and implementation standards
				developed by the National Archives and Records Administration for controlled
				unclassified information, including with respect to marking, safeguarding,
				dissemination and dispute resolution; and</text>
									</subparagraph><subparagraph id="H260B2E24F090401FAB244C2D6F9EAC90"><enum>(C)</enum><text>describe, with as
				much detail as possible, the categories and type of information entities should
				voluntarily submit under subsections (b) and (c)(1)(B) of section 246.</text>
									</subparagraph></paragraph></subsection><subsection id="HAB48CE0466D147FFAD69B62F97ACDB98"><enum>(d)</enum><header>Process for
				reporting security problems</header>
								<paragraph id="H0A01CBCBAA754498B82DC65662619F7B"><enum>(1)</enum><header>Establishment of
				process</header><text>The Director shall establish through regulation, and
				provide information to the public regarding, a process by which any person may
				submit a report to the Secretary regarding cybersecurity threats,
				vul­ner­a­bil­i­ties, and incidents affecting—</text>
									<subparagraph id="H159D9DE8B3B446BD8475D42F80494049"><enum>(A)</enum><text>the Federal
				information infrastructure;</text>
									</subparagraph><subparagraph id="HEBD0DED166BF4948B76E21BF98137EAF"><enum>(B)</enum><text>information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, the Department of Defense, a military department, or another
				element of the intelligence community; or</text>
									</subparagraph><subparagraph id="H922C4B175A60430483FFEFFA2B6D02DC"><enum>(C)</enum><text>national
				information infrastructure.</text>
									</subparagraph></paragraph><paragraph id="HDE899BC6DD3B4A8B88F82A3A9C2349DE"><enum>(2)</enum><header>Acknowledgment
				of receipt</header><text>If a report submitted under paragraph (1) identifies
				the person making the report, the Director shall respond promptly to such
				person and acknowledge receipt of the report.</text>
								</paragraph><paragraph id="H9A051DF6674E47F1B76199E27742AC02"><enum>(3)</enum><header>Steps to address
				problem</header><text>The Director shall review and consider the information
				provided in any report submitted under paragraph (1) and, at the sole,
				unreviewable discretion of the Director, determine what, if any, steps are
				necessary or appropriate to address any problems or deficiencies
				identified.</text>
								</paragraph><paragraph id="HB215EFBA663F45909D585622702EA153"><enum>(4)</enum><header>Disclosure of
				identity</header>
									<subparagraph id="HCFC37E066CDE4A46A65B9E293A40CC9F"><enum>(A)</enum><header>In
				general</header><text>Except as provided in subparagraph (B), or with the
				written consent of the person, the Secretary may not disclose the identity of a
				person who has provided information described in paragraph (1).</text>
									</subparagraph><subparagraph id="H73E5786CADD24F3E901C5BB6AAD5E8A8"><enum>(B)</enum><header>Referral to the
				Attorney General</header><text>The Secretary shall disclose to the Attorney
				General the identity of a person described under subparagraph (A) if the matter
				is referred to the Attorney General for enforcement. The Director shall provide
				reasonable advance notice to the affected person if disclosure of that person’s
				identity is to occur, unless such notice would risk compromising a criminal or
				civil enforcement investigation or proceeding.</text>
									</subparagraph></paragraph></subsection><subsection id="H13CE5F6A30F94358A9A1E145D25426E6"><enum>(e)</enum><header>Rules of
				construction</header><text>Nothing in this section shall be construed
				to—</text>
								<paragraph id="H92F55751FE484292BCDE2C69A4DEDFDB"><enum>(1)</enum><text>limit or otherwise
				affect the right, ability, duty, or obligation of any entity to use or disclose
				any information of that entity, including in the conduct of any judicial or
				other proceeding;</text>
								</paragraph><paragraph id="H948279C93F764737AB1A3532D9A77450"><enum>(2)</enum><text>prevent the
				classification of information submitted under this section if that information
				meets the standards for classification under Executive Order 12958 or any
				successor of that order;</text>
								</paragraph><paragraph id="H0AFD3AF041DE4B119DB5A832E2BFEEC9"><enum>(3)</enum><text>limit the right of
				an individual to make any disclosure—</text>
									<subparagraph id="HBE4C5805C26E4854AE9A90A5A35741AD"><enum>(A)</enum><text>protected or
				authorized under section 2302(b)(8) or 7211 of title 5, United States
				Code;</text>
									</subparagraph><subparagraph id="H8E84C849F6134377A358A1A97EDDB08F"><enum>(B)</enum><text>to an appropriate
				official of information that the individual reasonably believes evidences a
				violation of any law, rule, or regulation, gross mismanagement, or substantial
				and specific danger to public health, safety, or security, and that is
				protected under any Federal or State law (other than those referenced in
				subparagraph (A)) that shields the disclosing individual against retaliation or
				discrimination for having made the disclosure if such disclosure is not
				specifically prohibited by law and if such information is not specifically
				required by Executive order to be kept secret in the interest of national
				defense or the conduct of foreign affairs; or</text>
									</subparagraph><subparagraph id="H2D0434DF6FA24A8E9BAB1E242D9699AF"><enum>(C)</enum><text>to the Special
				Counsel, the inspector general of an agency, or any other employee designated
				by the head of an agency to receive similar disclosures;</text>
									</subparagraph></paragraph><paragraph id="H71FE5166381B47BDB551CD4F85520722"><enum>(4)</enum><text>prevent the
				Director from using information required to be submitted under sections 246,
				248, or 249 for enforcement of this subtitle, including enforcement proceedings
				subject to appropriate safeguards;</text>
								</paragraph><paragraph id="HC765FBBC7806406588DC83D533140DD9"><enum>(5)</enum><text>authorize
				information to be withheld from Congress, the Government Accountability Office,
				or Inspector General of the Department; or</text>
								</paragraph><paragraph id="H6F8C7CF3986B4F88A65A6CB1E483B411"><enum>(6)</enum><text>create a private
				right of action for enforcement of any provision of this section.</text>
								</paragraph></subsection><subsection id="H1C7BDD73B8FD483D94B1AF14FF1AA00C"><enum>(f)</enum><header>Audit</header>
								<paragraph id="H903B32280E8F4327BE396E7DF697ADCC"><enum>(1)</enum><header>In
				general</header><text>Not later than 1 year after the date of enactment of the
				<short-title>Protecting Cyberspace as a National Asset Act
				of 2010</short-title>, the Inspector General of the Department shall conduct an
				audit of the management of information submitted under subsection (b) and
				report the findings to appropriate committees of Congress.</text>
								</paragraph><paragraph id="HF80ABDBFFE5749BE96B1930B6522C163"><enum>(2)</enum><header>Contents</header><text>The
				audit under paragraph (1) shall include assessments of—</text>
									<subparagraph id="H384B141525CD473CBD7DF1A23DE1B790"><enum>(A)</enum><text>whether the
				information is adequately safeguarded against inappropriate disclosure;</text>
									</subparagraph><subparagraph id="H5876060211B8432C9EA5A49AEADCB58B"><enum>(B)</enum><text>the processes for
				marking and disseminating the information and resolving any disputes;</text>
									</subparagraph><subparagraph id="H9E94FB32B1EA4BB39F7FADA37C507FAA"><enum>(C)</enum><text>how the
				information is used for the purposes of this section, and whether that use is
				effective;</text>
									</subparagraph><subparagraph id="H418BAC763D7B4DAC9E3A0FBBAB8C0AE2"><enum>(D)</enum><text>whether
				information sharing has been effective to fulfill the purposes of this
				section;</text>
									</subparagraph><subparagraph id="H604DB87DFF004CAB873134C0CF21AD1D"><enum>(E)</enum><text>whether the kinds
				of information submitted have been appropriate and useful, or overbroad or
				overnarrow;</text>
									</subparagraph><subparagraph id="H702EDA501E8B43FEA6905EC8F53EC174"><enum>(F)</enum><text>whether the
				information protections allow for adequate accountability and transparency of
				the regulatory, enforcement, and other aspects of implementing this subtitle;
				and</text>
									</subparagraph><subparagraph id="H205921F5D9B544A7B2C9B3745976A10A"><enum>(G)</enum><text>any other factors
				at the discretion of the Inspector General.</text>
									</subparagraph></paragraph></subsection></section><section id="HFC2C85C5E09C492AAFB3BCF1D30CF29C"><enum>252.</enum><header>Sector-specific
				agencies</header>
							<subsection id="H32C88F0D3D504B3B9874689612DD957B"><enum>(a)</enum><header>In
				general</header><text>The head of each sector-specific agency and the head of
				any Federal agency that is not a sector-specific agency with responsibilities
				for regulating covered critical infrastructure shall coordinate with the
				Director on any activities of the sector-specific agency or Federal agency that
				relate to the efforts of the agency regarding security or resiliency of the
				national information infrastructure, including critical infrastructure and
				covered critical infrastructure, within or under the supervision of the
				agency.</text>
							</subsection><subsection id="H79DDACC3FE96489C84D122DE210BDA41"><enum>(b)</enum><header>Duplicative
				reporting requirements</header><text>The head of each sector-specific agency
				and the head of any Federal agency that is not a sector-specific agency with
				responsibilities for regulating covered critical infrastructure shall
				coordinate with the Director to eliminate and avoid the creation of duplicate
				reporting or compliance requirements relating to the security or resiliency of
				the national information infrastructure, including critical infrastructure and
				covered critical infrastructure, within or under the supervision of the
				agency.</text>
							</subsection><subsection id="HC197003AE528497A9CEA06E62B055A41"><enum>(c)</enum><header>Requirements</header>
								<paragraph id="H2536C58E5C824795BBE24750CC7128F6"><enum>(1)</enum><header>In
				general</header><text>To the extent that the head of each sector-specific
				agency and the head of any Federal agency that is not a sector-specific agency
				with responsibilities for regulating covered critical infrastructure has the
				authority to establish regulations, rules, or requirements or other required
				actions that are applicable to the security of national information
				infrastructure, including critical infrastructure and covered critical
				infrastructure, the head of that agency shall—</text>
									<subparagraph id="HB94B1B20AE48443B8A2F1D79995480AF"><enum>(A)</enum><text>notify the
				Director in a timely fashion of the intent to establish the regulations, rules,
				requirements, or other required actions;</text>
									</subparagraph><subparagraph id="H8210BAC2B29D4522AA3926222F264073"><enum>(B)</enum><text>coordinate with
				the Director to ensure that the regulations, rules, requirements, or other
				required actions are consistent with, and do not conflict or impede, the
				activities of the Director under sections 247, 248, and 249; and</text>
									</subparagraph><subparagraph id="H141B98A546DA4924B19AEDAE665796A6"><enum>(C)</enum><text>in coordination
				with the Director, ensure that the regulations, rules, requirements, or other
				required actions are implemented, as they relate to covered critical
				infrastructure, in accordance with subsection (a).</text>
									</subparagraph></paragraph><paragraph id="H68D1DB434AF940698AC25050CDB9AF6F"><enum>(2)</enum><header>Coordination</header><text>Coordination
				under paragraph (1)(B) shall include the active participation of the Director
				in the process for developing regulations, rules, requirements, or other
				required actions.</text>
								</paragraph><paragraph id="H6265F038C9984DEBA2DB6196E8AE9FE3"><enum>(3)</enum><header>Rule of
				construction</header><text>Nothing in this section shall be construed to
				provide additional authority for any sector-specific agency or any Federal
				agency that is not a sector-specific agency with responsibilities for
				regulating national information infrastructure, including critical
				infrastructure or covered critical infrastructure, to establish standards or
				other measures that are applicable to the security of national information
				infrastructure not otherwise authorized by law.</text>
								</paragraph></subsection></section><section id="H8C0B8422662B42749910F5893800535A"><enum>253.</enum><header>Strategy for
				Federal cybersecurity supply chain management</header>
							<subsection id="H4B34FB6329D047E5A219AEDD7AAF424C"><enum>(a)</enum><header>In
				general</header><text>The Secretary, in consultation with the Director of
				Cyberspace Policy, the Director, the Secretary of Defense, the Secretary of
				Commerce, the Secretary of State, the Director of National Intelligence, the
				Administrator of General Services, the Administrator for Federal Procurement
				Policy, the other members of the Chief Information Officers Council established
				under section 3603 of title 44, United States Code, the Chief Acquisition
				Officers Council established under section 16A of the Office of Federal
				Procurement Policy Act (41 U.S.C. 414b), the Chief Financial Officers Council
				established under section 302 of the Chief Financial Officers Act of 1990 (31
				U.S.C. 901 note), and the private sector, shall develop, periodically update,
				and implement a supply chain risk management strategy designed to ensure the
				security of the Federal information infrastructure, including protection
				against unauthorized access to, alteration of information in, disruption of
				operations of, interruption of communications or services of, and insertion of
				malicious software, engineering vulnerabilities, or otherwise corrupting
				software, hardware, services, or products intended for use in Federal
				information infrastructure.</text>
							</subsection><subsection id="H1BA4ABBD5A3C4509ABE9635FD8BA3BC0"><enum>(b)</enum><header>Contents</header><text>The
				supply chain risk management strategy developed under subsection (a)
				shall—</text>
								<paragraph id="H92D7241F5CC24226B323D89B79B74936"><enum>(1)</enum><text>address risks in
				the supply chain during the entire life cycle of any part of the Federal
				information infrastructure;</text>
								</paragraph><paragraph id="H35DA988AA6B84FD5B00C2EDEBE87176D"><enum>(2)</enum><text>place particular
				emphasis on—</text>
									<subparagraph id="H91B1290AFBCF44059253DAEDC3A7A0A7"><enum>(A)</enum><text>securing critical
				information systems and the Federal information infrastructure;</text>
									</subparagraph><subparagraph id="HE71DE296346F4400AEF78C1ED89917CC"><enum>(B)</enum><text>developing
				processes that—</text>
										<clause id="H4E7E4B98EB624700920761BC28F1A380"><enum>(i)</enum><text>incorporate
				all-source intelligence analysis into assessments of the supply chain for the
				Federal information infrastructure;</text>
										</clause><clause id="H22EC1B4AA1D14350A4239D01B7512E1C"><enum>(ii)</enum><text>assess risks from
				potential suppliers providing critical components or services of the Federal
				information infrastructure;</text>
										</clause><clause id="HDFE6010205E04392AA3375D01386411B"><enum>(iii)</enum><text>assess risks
				from individual components, including all subcomponents, or software used in or
				affecting the Federal information infrastructure;</text>
										</clause><clause id="H7DE0BE36165A4D08A44BC0578B9B096A"><enum>(iv)</enum><text>manage the
				quality, configuration, and security of software, hardware, and systems of the
				Federal information infrastructure throughout the life cycle of the software,
				hardware, or system, including components or subcomponents from secondary and
				tertiary sources;</text>
										</clause><clause id="H0F0840AC74B44A53B34B69516C926EE7"><enum>(v)</enum><text>detect the
				occurrence, reduce the likelihood of occurrence, and mitigate or remediate the
				risks associated with products containing counterfeit components or malicious
				functions;</text>
										</clause><clause commented="no" id="HE934DA6069CD43168EBA912338DE1611"><enum>(vi)</enum><text>enhance
				developmental and operational test and evaluation capabilities, including
				software vulnerability detection methods and automated tools that shall be
				integrated into acquisition policy practices by Federal agencies and, where
				appropriate, make the capabilities available for use by the private sector;
				and</text>
										</clause><clause commented="no" id="H53C1D0190D4A4058817A81BF5FCFEDE9"><enum>(vii)</enum><text>protect the
				intellectual property and trade secrets of suppliers of information and
				communications technology products and services;</text>
										</clause></subparagraph><subparagraph id="H32E50241381F4BF1B43F6080B59154FD"><enum>(C)</enum><text>the use of
				internationally recognized standards and standards developed by the private
				sector and developing a process, with the National Institute for Standards and
				Technology, to make recommendations for improvements of the standards;</text>
									</subparagraph><subparagraph id="H8E0A5CCDF669427F93556F210354072F"><enum>(D)</enum><text>identifying
				acquisition practices of Federal agencies that increase risks in the supply
				chain and developing a process to provide recommendations for revisions to
				those processes; and</text>
									</subparagraph><subparagraph id="H9B39A9E5E38A4CA48F34AD827DBFFDC9"><enum>(E)</enum><text>sharing with the
				private sector, to the fullest extent possible, the threats identified in the
				supply chain and working with the private sector to develop responses to those
				threats as identified; and</text>
									</subparagraph></paragraph><paragraph id="H3AFB469672DA444FAEF59012851CFC35"><enum>(3)</enum><text>to the extent
				practicable, promote the ability of Federal agencies to procure commercial off
				the shelf information and communications technology products and services from
				a diverse pool of suppliers.</text>
								</paragraph></subsection><subsection id="H7551B9D2AC944CAEB2D1BDF6150D0A60"><enum>(c)</enum><header>Implementation</header><text>The
				Federal Acquisition Regulatory Council established under section 25(a) of the
				Office of Federal Procurement Policy Act (41 U.S.C. 421(a)) shall—</text>
								<paragraph id="HC60AE6EC14584D86A01740A61757ECFD"><enum>(1)</enum><text>amend the Federal
				Acquisition Regulation issued under section 25 of that Act to—</text>
									<subparagraph id="H071C5B5C4E394C8685C45FD64F880381"><enum>(A)</enum><text>incorporate, where
				relevant, the supply chain risk management strategy developed under subsection
				(a) to improve security throughout the acquisition process; and</text>
									</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="HAE96CBF3B4A444D3B54CF222EFCD024F"><enum>(B)</enum><text>direct that all
				software and hardware purchased by the Federal Government shall comply with
				standards developed or be interoperable with automated tools approved by the
				National Institute of Standards and Technology, to continually enhance
				security; and</text>
									</subparagraph></paragraph><paragraph id="HD65D8D00A5A94DCA9EA431E05749620B"><enum>(2)</enum><text>develop a clause
				or set of clauses for inclusion in solicitations, contracts, and task and
				delivery orders that sets forth the responsibility of the contractor under the
				Federal Acquisition Regulation provisions implemented under this
				subsection.</text>
								</paragraph></subsection></section></subtitle><after-quoted-block>.</after-quoted-block></quoted-block>
			</section></title><title id="H5268324ED6EA4DA6B757D49BE5BAFDFA"><enum>III</enum><header>Federal
			 information security management</header>
			<section id="HECA0217A83A24DA7889295CD1E8BC848"><enum>301.</enum><header>Coordination of
			 Federal information policy</header>
				<subsection id="H0FE3083E0AFB4F3F87D7916F5AF2FF6B"><enum>(a)</enum><header>Findings</header><text>Congress
			 finds that—</text>
					<paragraph commented="no" id="H207EB274F0C243F396BE52CAA6D6E41D"><enum>(1)</enum><text>since 2002 the
			 Federal Government has experienced multiple high-profile incidents that
			 resulted in the theft of sensitive information amounting to more than the
			 entire print collection contained in the Library of Congress, including
			 personally identifiable information, advanced scientific research, and
			 prenegotiated United States diplomatic positions; and</text>
					</paragraph><paragraph commented="no" id="HAE165AE9CA58472CBC573B8C350FBEF0"><enum>(2)</enum><text>chapter 35 of
			 title 44, United States Code, must be amended to increase the coordination of
			 Federal agency activities and to enhance situational awareness throughout the
			 Federal Government using more effective enterprise-wide automated monitoring,
			 detection, and response capabilities.</text>
					</paragraph></subsection><subsection id="H5B6789636377452DA69B1B2C72EECB45"><enum>(b)</enum><header>In
			 general</header><text>Chapter 35 of title 44, United States Code, is amended by
			 striking subchapters II and III and inserting the following:</text>
					<quoted-block display-inline="no-display-inline" id="H589C9D2323B844BCA82058403442F3F6" style="USC">
						<subchapter id="H65F7FF0A148F498E9BB1F552D7100791"><enum>II</enum><header>Information
				security</header>
							<section commented="no" id="H02C8A01C3F8D471AA319D31EFF173CCD"><enum>3550.</enum><header>Purposes</header><text display-inline="no-display-inline">The purposes of this subchapter are
				to—</text>
								<paragraph commented="no" id="HD247FCC0B8A44A35BDB76D1E83F680B9"><enum>(1)</enum><text>provide a
				comprehensive framework for ensuring the effectiveness of information security
				controls over information resources that support the Federal information
				infrastructure and the operations and assets of agencies;</text>
								</paragraph><paragraph commented="no" id="H5011FE4042F7470CA33F5EBC64AC8112"><enum>(2)</enum><text>recognize the
				highly networked nature of the current Federal information infrastructure and
				provide effective Government-wide management and oversight of the related
				information security risks, including coordination of information security
				efforts throughout the civilian, national security, and law enforcement
				communities;</text>
								</paragraph><paragraph commented="no" id="H0A0C6C0756FD4D9E908C738E966C25D9"><enum>(3)</enum><text>provide for
				development and maintenance of prioritized and risk-based security controls
				required to protect Federal information infrastructure and information
				systems;</text>
								</paragraph><paragraph commented="no" id="HBEA3CDF6C17942F78B53B7865EE405AA"><enum>(4)</enum><text>provide a
				mechanism for improved oversight of Federal agency information security
				programs;</text>
								</paragraph><paragraph id="H9AE5B41CC33F497193A95AE1FB00FE54"><enum>(5)</enum><text>acknowledge that
				commercially developed information security products offer advanced, dynamic,
				robust, and effective information security solutions, reflecting market
				solutions for the protection of critical information infrastructures important
				to the national defense and economic security of the Nation that are designed,
				built, and operated by the private sector; and</text>
								</paragraph><paragraph id="H2D3DC159177E4064A24CB0E1CFB913A8"><enum>(6)</enum><text>recognize that the
				selection of specific technical hardware and software information security
				solutions should be left to individual agencies from among commercially
				developed products.</text>
								</paragraph></section><section id="H4763D7F327CA4395AE4EC42F40956891"><enum>3551.</enum><header>Definitions</header>
								<subsection id="HCCA5AE2D1E164B66BF6FE3B0DEB9C04A"><enum>(a)</enum><header>In
				general</header><text>Except as provided under subsection (b), the definitions
				under section 3502 shall apply to this subchapter.</text>
								</subsection><subsection id="HDA57B83A75154F418AC5F6C247660F83"><enum>(b)</enum><header>Additional
				definitions</header><text>In this subchapter:</text>
									<paragraph commented="no" id="H7E5A2D51BCE84A64966866647A5E2DF6"><enum>(1)</enum><text>The term
				<term>agency information infrastructure</term>—</text>
										<subparagraph commented="no" id="H99F62D134B624FE0B7682FF456843404"><enum>(A)</enum><text>means information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, an agency, including information systems used or operated by
				another entity on behalf of the agency; and</text>
										</subparagraph><subparagraph commented="no" id="H7B668E70326F4FE98A2C286A9EDFE9B2"><enum>(B)</enum><text>does not include
				national security systems.</text>
										</subparagraph></paragraph><paragraph id="H38DCC1E707344E8799FCB13BE0A17BDC"><enum>(2)</enum><text>The term
				<term>automated and continuous monitoring</term> means monitoring at a
				frequency and sufficiency such that the data exchange requires little to no
				human involvement and is not interrupted;</text>
									</paragraph><paragraph id="HD1F595621AE64D178915B3555BE712DC"><enum>(3)</enum><text>The term
				<term>incident</term> means an occurrence that—</text>
										<subparagraph id="HF81F7AC94AC14157A75408044E99CC87"><enum>(A)</enum><text>actually or
				potentially jeopardizes—</text>
											<clause id="H1A0691A653624E0CB40D1E633B396CE4"><enum>(i)</enum><text>the information
				security of an information system; or</text>
											</clause><clause id="H194363067B8B45B7A6E8FCF3CDE86933"><enum>(ii)</enum><text>the information
				the system processes, stores, or transmits; or</text>
											</clause></subparagraph><subparagraph id="H063A684356AB40E59EDDAB4039723EF1"><enum>(B)</enum><text>constitutes a
				violation or threat of violation of security policies, security procedures, or
				acceptable use policies.</text>
										</subparagraph></paragraph><paragraph id="HF630463722054EE8A2505A704F7EF8E3"><enum>(4)</enum><text>The term
				<term>information infrastructure</term> means the underlying framework that
				information systems and assets rely on to process, transmit, receive, or store
				information electronically, including programmable electronic devices and
				communications networks and any associated hardware, software, or data.</text>
									</paragraph><paragraph id="H7B6B828EC49E420E9ECF8C7FE3412F3D"><enum>(5)</enum><text>The term
				<term>information security</term> means protecting information and information
				systems from disruption or unauthorized access, use, disclosure, modification,
				or destruction in order to provide—</text>
										<subparagraph id="HFBBBFD04D34F4EB88A98F5360B4BBB16"><enum>(A)</enum><text>integrity, by
				guarding against improper information modification or destruction, including by
				ensuring information nonrepudiation and authenticity;</text>
										</subparagraph><subparagraph id="H80DB46404BED4FAE8F662607FF06BA79"><enum>(B)</enum><text>confidentiality,
				by preserving authorized restrictions on access and disclosure, including means
				for protecting personal privacy and proprietary information; and</text>
										</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H8FBDE06CC84C4AF5A0AE079E79FDDA87"><enum>(C)</enum><text>availability, by
				ensuring timely and reliable access to and use of information.</text>
										</subparagraph></paragraph><paragraph id="H7256FF9929EC45D98B11930AF9500BE1"><enum>(6)</enum><text>The term
				<term>information technology</term> has the meaning given that term in section
				11101 of title 40.</text>
									</paragraph><paragraph id="HE80B9325577F493AA321A0096BC01E67"><enum>(7)</enum><text>The term
				<term>management controls</term> means safeguards or countermeasures for an
				information system that focus on the management of risk and the management of
				information system security.</text>
									</paragraph><paragraph id="HA5A4756E97DC4E9A976B3DE3FD162B60"><enum>(8)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="HC758FC22845D45EE9F491C6861C68654"><enum>(A)</enum><text>The term <term>national
				security system</term> means any information system (including any
				telecommunications system) used or operated by an agency or by a contractor of
				an agency, or other organization on behalf of an agency—</text>
											<clause id="HDEBED665564948DABE6ABC58150CEDA4" indent="up1"><enum>(i)</enum><text>the function, operation, or use of
				which—</text>
												<subclause id="H70362BC5F1BE49C9B14F210DC1BB16E3"><enum>(I)</enum><text>involves intelligence activities;</text>
												</subclause><subclause id="HCF2B05963520403CB911652D257D3596"><enum>(II)</enum><text>involves cryptologic activities related
				to national security;</text>
												</subclause><subclause id="H3AAA53F1A88D4E4EBE8AD1C83832AEDD"><enum>(III)</enum><text>involves command and control of
				military forces;</text>
												</subclause><subclause id="H864F945CB7A640D787D2BD3D0A3C2B70"><enum>(IV)</enum><text>involves equipment that is an integral
				part of a weapon or weapons system; or</text>
												</subclause><subclause id="HD8868B1A9B5A41AE9E790B0E69F13DC2"><enum>(V)</enum><text>subject to subparagraph (B), is critical
				to the direct fulfillment of military or intelligence missions; or</text>
												</subclause></clause><clause id="HEB9B0A71E5F44D408238BDDED8D1F1D7" indent="up1"><enum>(ii)</enum><text>that is protected at all times by
				procedures established for information that have been specifically authorized
				under criteria established by an Executive order or an Act of Congress to be
				kept classified in the interest of national defense or foreign policy.</text>
											</clause></subparagraph><subparagraph id="H60610956002542AD8E66770FC98387AD" indent="up1"><enum>(B)</enum><text>Subparagraph (A)(i)(V) does not
				include a system that is to be used for routine administrative and business
				applications (including payroll, finance, logistics, and personnel management
				applications).</text>
										</subparagraph></paragraph><paragraph id="H603BF5AF1C264A0894D800B1DFDFF93D"><enum>(9)</enum><text>The term
				<term>operational controls</term> means the safeguards and countermeasures for
				an information system that are primarily implemented and executed by
				individuals, not systems.</text>
									</paragraph><paragraph id="HDC35B6E05D1540A98C75057D71AAC42B"><enum>(10)</enum><text>The term
				<term>risk</term> means the potential for an unwanted outcome resulting from an
				incident, as determined by the likelihood of the occurrence of the incident and
				the associated consequences, including potential for an adverse outcome
				assessed as a function of threats, vulnerabilities, and consequences associated
				with an incident.</text>
									</paragraph><paragraph id="H49CA9DD9D42D489E99173201B3331434"><enum>(11)</enum><text>The term
				<term>risk-based security</term> means security commensurate with the risk and
				magnitude of harm resulting from the loss, misuse, or unauthorized access to,
				or modification, of information, including assuring that systems and
				applications used by the agency operate effectively and provide appropriate
				confidentiality, integrity, and availability.</text>
									</paragraph><paragraph id="H4CD051F6C7D34060B5C8833956DE5644"><enum>(12)</enum><text>The term
				<term>security controls</term> means the management, operational, and technical
				controls prescribed for an information system to protect the information
				security of the system.</text>
									</paragraph><paragraph id="H09DBED8AE0C34876B48DE00C1F2B8A6F"><enum>(13)</enum><text>The term
				<term>technical controls</term> means the safeguards or countermeasures for an
				information system that are primarily implemented and executed by the
				information system through mechanism contained in the hardware, software, or
				firmware components of the system.</text>
									</paragraph></subsection></section><section id="HD8F7E73B3462454C8B098214865C4B20"><enum>3552.</enum><header>Authority and
				functions of the National Center for Cybersecurity and Communications</header>
								<subsection id="H857E678EF22746B2A1EB49E9717A3ADE"><enum>(a)</enum><header>In
				general</header><text>The Director of the National Center for Cybersecurity and
				Communications shall—</text>
									<paragraph id="H3B81F174A55A44FDA8CF6FB6ADC02AB5"><enum>(1)</enum><text>develop, oversee
				the implementation of, and enforce policies, principles, and guidelines on
				information security, including through ensuring timely agency adoption of and
				compliance with standards developed under section 20 of the National Institute
				of Standards and Technology Act (15 U.S.C. 278g–3) and subtitle E of title II
				of the Homeland Security Act of 2002;</text>
									</paragraph><paragraph id="HB08BAD6D07754DC8AEA47FD83A948F58"><enum>(2)</enum><text>provide to
				agencies security controls that agencies shall be required to be implemented to
				mitigate and remediate vulnerabilities, attacks, and exploitations discovered
				as a result of activities required under this subchapter or subtitle E of title
				II of the Homeland Security Act of 2002;</text>
									</paragraph><paragraph id="HF61436DFBA9C4D8EB51C00808879BA0D"><enum>(3)</enum><text>to the extent
				practicable—</text>
										<subparagraph id="HE4F3F60ED29D4C6381719A3FC312ADDC"><enum>(A)</enum><text>prioritize the
				policies, principles, standards, and guidelines promulgated under section 20 of
				the National Institute of Standards and Technology Act (15 U.S.C. 278g–3),
				paragraph (1), and subtitle E of title II of the Homeland Security Act of 2002,
				based upon the risk of an incident; and</text>
										</subparagraph><subparagraph id="H25A93A6586534C89ACAC4EDC03EB0C0E"><enum>(B)</enum><text>develop guidance
				that requires agencies to monitor, including automated and continuous
				monitoring of, the effective implementation of policies, principles, standards,
				and guidelines developed under section 20 of the National Institute of
				Standards and Technology Act (15 U.S.C. 278g–3), paragraph (1), and subtitle E
				of title II of the Homeland Security Act of 2002;</text>
										</subparagraph><subparagraph id="H72A77BFB18AE44B9B2ABBA25A4C29691"><enum>(C)</enum><text>ensure the
				effective operation of technical capabilities within the National Center for
				Cybersecurity and Communications to enable automated and continuous monitoring
				of any information collected as a result of the guidance developed under
				subparagraph (B) and use the information to enhance the risk-based security of
				the Federal information infrastructure; and</text>
										</subparagraph><subparagraph id="H2AB5BFA31AE54D9C93696137C59DA3F0"><enum>(D)</enum><text>ensure the
				effective operation of a secure system that satisfies information reporting
				requirements under sections 3553(c) and 3556(c);</text>
										</subparagraph></paragraph><paragraph id="H7375A62645DF4768AF39EC3A496A9FF8"><enum>(4)</enum><text>require agencies,
				consistent with the standards developed under section 20 of the National
				Institute of Standards and Technology Act (15 U.S.C. 278g–3) or paragraph (1)
				and the requirements of this subchapter, to identify and provide information
				security protections commensurate with the risk resulting from the disruption
				or unauthorized access, use, disclosure, modification, or destruction
				of—</text>
										<subparagraph id="H08536519DAC94C478DD90AE011520443"><enum>(A)</enum><text>information
				collected or maintained by or on behalf of an agency; or</text>
										</subparagraph><subparagraph id="HA084765D1F7247A882C2C57B7B7BE80C"><enum>(B)</enum><text>information
				systems used or operated by an agency or by a contractor of an agency or other
				organization on behalf of an agency;</text>
										</subparagraph></paragraph><paragraph id="H96A208DC31CA47A5912A05C6556197D2"><enum>(5)</enum><text>oversee agency
				compliance with the requirements of this subchapter, including coordinating
				with the Office of Management and Budget to use any authorized action under
				section 11303 of title 40 to enforce accountability for compliance with such
				requirements;</text>
									</paragraph><paragraph id="HE4C405C3E229436893AC174FCD52F9B2"><enum>(6)</enum><text>review, at least
				annually, and approve or disapprove, agency information security programs
				required under section 3553(b); and</text>
									</paragraph><paragraph id="H918A522DDE4A499A8D5A6362F8261BB0"><enum>(7)</enum><text>coordinate
				information security policies and procedures with the Administrator for
				Electronic Government and the Administrator for the Office of Information and
				Regulatory Affairs with related information resources management policies and
				procedures.</text>
									</paragraph></subsection><subsection id="HD435D38E66F643E0B54A7B03B35F3F0E"><enum>(b)</enum><header>National
				security systems</header><text>The authorities of the Director under this
				section shall not apply to national security systems.</text>
								</subsection></section><section id="H51415E316A044F708CE044FB4DD106D3"><enum>3553.</enum><header>Agency
				responsibilities</header>
								<subsection id="H15627E27D86D4569BC89278C1D1BB013"><enum>(a)</enum><header>In
				general</header><text>The head of each agency shall—</text>
									<paragraph id="HCC852389BD34441DA764CA5BA16113EB"><enum>(1)</enum><text>be responsible
				for—</text>
										<subparagraph id="H87F874BFCEC24CC4BF672B35F3714246"><enum>(A)</enum><text>providing
				information security protections commensurate with the risk and magnitude of
				the harm resulting from unauthorized access, use, disclosure, disruption,
				modification, or destruction of—</text>
											<clause id="HD4D399BC69D541FB8C5AE29438E91262"><enum>(i)</enum><text>information
				collected or maintained by or on behalf of the agency; and</text>
											</clause><clause id="H3DFD11FEA4334C9DA58EF9E2C5322049"><enum>(ii)</enum><text>agency
				information infrastructure;</text>
											</clause></subparagraph><subparagraph id="H54A3C1B4450942238FE93CC3639738F2"><enum>(B)</enum><text>complying with the
				requirements of this subchapter and related policies, procedures, standards,
				and guidelines, including—</text>
											<clause id="H2B12E1205A4242BCB3F18B0F51B8AA9A"><enum>(i)</enum><text>information
				security requirements, including security controls, developed by the Director
				of the National Center for Cybersecurity and Communications under section 3552,
				subtitle E of title II of the Homeland Security Act of 2002, or any other
				provision of law;</text>
											</clause><clause id="H645E086CE7644C6595EF4F9CEA094413"><enum>(ii)</enum><text>information
				security policies, principles, standards, and guidelines promulgated under
				section 20 of the National Institute of Standards and Technology Act (15 U.S.C.
				278g–3) and section 3552(a)(1);</text>
											</clause><clause id="H36A6865FE14641F69B2861A323B3F751"><enum>(iii)</enum><text>information
				security standards and guidelines for national security systems issued in
				accordance with law and as directed by the President; and</text>
											</clause><clause id="H5AFD815299E146EEB0B1F829F44846FC"><enum>(iv)</enum><text>ensuring the
				standards implemented for information systems and national security systems of
				the agency are complementary and uniform, to the extent practicable;</text>
											</clause></subparagraph><subparagraph id="HDCD02553FA134652A5E4E0E19BC81602"><enum>(C)</enum><text>ensuring that
				information security management processes are integrated with agency strategic
				and operational planning processes, including policies, procedures, and
				practices described in subsection (c)(1)(C);</text>
										</subparagraph><subparagraph id="H65DA7A5E06E24FD4B1A3F3D69BAA8CC0"><enum>(D)</enum><text>as appropriate,
				maintaining secure facilities that have the capability of accessing, sending,
				receiving, and storing classified information;</text>
										</subparagraph><subparagraph id="H345035D97E2249F7AF1FC33874C13AC1"><enum>(E)</enum><text>maintaining a
				sufficient number of personnel with security clearances, at the appropriate
				levels, to access, send, receive and analyze classified information to carry
				out the responsibilities of this subchapter; and</text>
										</subparagraph><subparagraph id="H77B163BD798943C79EC83D94DC5ED464"><enum>(F)</enum><text>ensuring that
				information security performance indicators and measures are included in the
				annual performance evaluations of all managers, senior managers, senior
				executive service personnel, and political appointees;</text>
										</subparagraph></paragraph><paragraph id="H8F7F5AD102CA42618FBC66A0AAA17EF8"><enum>(2)</enum><text>ensure that senior
				agency officials provide information security for the information and
				information systems that support the operations and assets under the control of
				those officials, including through—</text>
										<subparagraph id="H5623CD1297114B8884616F017516AF9A"><enum>(A)</enum><text>assessing the risk
				and magnitude of the harm that could result from the disruption or unauthorized
				access, use, disclosure, modification, or destruction of such information or
				information systems;</text>
										</subparagraph><subparagraph id="HCEF6020922E844E9B3DE86DD083BA9CF"><enum>(B)</enum><text>determining the
				levels of information security appropriate to protect such information and
				information systems in accordance with policies, principles, standards, and
				guidelines promulgated under section 20 of the National Institute of Standards
				and Technology Act (15 U.S.C. 278g–3), section 3552(a)(1), and subtitle E of
				title II of the Homeland Security Act of 2002, for information security
				categorizations and related requirements;</text>
										</subparagraph><subparagraph id="HE43A877BAFCE4FF6B51F36C5FF290DEF"><enum>(C)</enum><text>implementing
				policies and procedures to cost effectively reduce risks to an acceptable
				level;</text>
										</subparagraph><subparagraph id="H922C21E6FCF34E00A35257E77F74D9CB"><enum>(D)</enum><text>periodically
				testing and evaluating information security controls and techniques to ensure
				that such controls and techniques are operating effectively; and</text>
										</subparagraph><subparagraph id="H1E08B2DAA3CA43699A207D85AC4CB367"><enum>(E)</enum><text>withholding all
				bonus and cash awards to senior agency officials accountable for the operation
				of such agency information infrastructure that are recognized by the Chief
				Information Security Officer as impairing the risk-based security information,
				information system, or agency information infrastructure;</text>
										</subparagraph></paragraph><paragraph id="H9FAB12F35918442A8537B1E89B487BA3"><enum>(3)</enum><text>delegate to a
				senior agency officer designated as the Chief Information Security Officer the
				authority and budget necessary to ensure and enforce compliance with the
				requirements imposed on the agency under this subchapter, subtitle E of title
				II of the Homeland Security Act of 2002, or any other provision of law,
				including—</text>
										<subparagraph id="H4FA20828D5704606BB7C59443487DEC6"><enum>(A)</enum><text>overseeing the
				establishment, maintenance, and management of a security operations center that
				has technical capabilities that can, through automated and continuous
				monitoring—</text>
											<clause id="H18650E965E3C4D99BD52051088952307"><enum>(i)</enum><text>detect, report,
				respond to, contain, remediate, and mitigate incidents that impair risk-based
				security of the information, information systems, and agency information
				infrastructure, in accordance with policy provided by the National Center for
				Cybersecurity and Communications;</text>
											</clause><clause id="H8C5052A91D364DDC8B0BE90A953A6F1D"><enum>(ii)</enum><text>monitor and, on a
				risk-based basis, mitigate and remediate the vul­ner­a­bil­i­ties of every
				information system within the agency information infrastructure;</text>
											</clause><clause id="HAECEF773CAA1434E855050667B2D2C46"><enum>(iii)</enum><text>continually
				evaluate risks posed to information collected or maintained by or on behalf of
				the agency and information systems and hold senior agency officials accountable
				for ensuring the risk-based security of such information and information
				systems;</text>
											</clause><clause id="HA4C557C1F5804A66A694FC4926BBD772"><enum>(iv)</enum><text>collaborate with
				the National Center for Cybersecurity and Communications and appropriate public
				and private sector security operations centers to address incidents that impact
				the security of information and information systems that extend beyond the
				control of the agency; and</text>
											</clause><clause id="H1128A488D2FB4C0BA837DCBBC8976FEA"><enum>(v)</enum><text>report any
				incident described under clauses (i) and (ii), as directed by the policy of the
				National Center for Cybersecurity and Communications or the Inspector General
				of the agency;</text>
											</clause></subparagraph><subparagraph id="H60C91AF6F7A247F39686166F5967CB60"><enum>(B)</enum><text>collaborating with
				the Administrator for E–Government and the Chief Information Officer to
				establish, maintain, and update an enterprise network, system, storage, and
				security architecture, that can be accessed by the National Cybersecurity
				Communications Center and includes—</text>
											<clause id="H64EBD436BE364B05AFB722EF8973B5DD"><enum>(i)</enum><text>information on how
				security controls are implemented throughout the agency information
				infrastructure; and</text>
											</clause><clause id="H59380BA3BBAE4644AEEC0C0BEB71CF0B"><enum>(ii)</enum><text>information on
				how the controls described under subparagraph (A) maintain the appropriate
				level of confidentiality, integrity, and availability of information and
				information systems based on—</text>
												<subclause id="H878FEC8178DA4D9386E20EE4B0B0DF63"><enum>(I)</enum><text>the policy of the
				National Center for Cybersecurity and Communications; and</text>
												</subclause><subclause id="HD0D2C0ECE62A429FA880826F87F33599"><enum>(II)</enum><text>the standards or
				guidance developed by the National Institute of Standards and
				Technology;</text>
												</subclause></clause></subparagraph><subparagraph id="HF636DDA9A38E4DE989D3CAC52B8AD274"><enum>(C)</enum><text>developing,
				maintaining, and overseeing an agency-wide information security program as
				required by subsection (b);</text>
										</subparagraph><subparagraph id="H0F996153EF5D4849AA470A17A168F7A9"><enum>(D)</enum><text>developing,
				maintaining, and overseeing information security policies, procedures, and
				control techniques to address all applicable requirements, including those
				issued under section 3552;</text>
										</subparagraph><subparagraph id="HBB6EC3B3DF62474FAC1F313C4595B8A7"><enum>(E)</enum><text>training,
				consistent with the requirements of section 406 of the
				<short-title>Protecting Cyberspace as a National Asset Act
				of 2010</short-title>, and overseeing personnel with significant
				responsibilities for information security with respect to such
				responsibilities; and</text>
										</subparagraph><subparagraph id="HAC94CB673180479EA30072915F33C773"><enum>(F)</enum><text>assisting senior
				agency officers concerning their responsibilities under paragraph (2);</text>
										</subparagraph></paragraph><paragraph id="HE7FF798B9D5244FB88BBBB7FA82F8CE2"><enum>(4)</enum><text>ensure that the
				Chief Information Security Officer has a sufficient number of cleared and
				trained personnel with technical skills identified by the National Center for
				Cybersecurity and Communications as critical to maintaining the risk-based
				security of agency information infrastructure as required by the subchapter and
				other applicable laws;</text>
									</paragraph><paragraph id="H377AC4128FD94ABD984E071C60B09DF7"><enum>(5)</enum><text>ensure that the
				agency Chief Information Security Officer, in coordination with appropriate
				senior agency officials, reports not less than annually to the head of the
				agency on the effectiveness of the agency information security program,
				including progress of remedial actions;</text>
									</paragraph><paragraph id="H9277E25EE64948CA973479AD963CD401"><enum>(6)</enum><text>ensure that the
				Chief Information Security Officer—</text>
										<subparagraph id="H60D3C04AA655486596EC2F3442C41A25"><enum>(A)</enum><text>possesses
				necessary qualifications, including education, professional certifications,
				training, experience, and the security clearance required to administer the
				functions described under this subchapter; and</text>
										</subparagraph><subparagraph id="H7FCA8E9F074E4385A9026B2737FA89BE"><enum>(B)</enum><text>has information
				security duties as the primary duty of that officer; and</text>
										</subparagraph></paragraph><paragraph id="H5E353EA5D1B3401AAFB924A1F40A08A6"><enum>(7)</enum><text>ensure that
				components of that agency establish and maintain an automated reporting
				mechanism that allows the Chief Information Security Officer with
				responsibility for the entire agency, and all components thereof, to implement,
				monitor, and hold senior agency officers accountable for the implementation of
				appropriate security policies, procedures, and controls of agency
				components.</text>
									</paragraph></subsection><subsection id="H7C5C2C2A535841478DAE88EFD31E1232"><enum>(b)</enum><header>Agency-Wide
				information security program</header><text>Each agency shall develop, document,
				and implement an agency-wide information security program, approved by the
				National Center for Cybersecurity and Communications under section 3552(a)(6)
				and consistent with components across and within agencies, to provide
				information security for the information and information systems that support
				the operations and assets of the agency, including those provided or managed by
				another agency, contractor, or other source, that includes—</text>
									<paragraph id="HCD1631A7F3B14A59821151126819D887"><enum>(1)</enum><text>frequent
				assessments, at least twice each month—</text>
										<subparagraph id="HEEA7B4BD1D394807B4F9533FAEEC102D"><enum>(A)</enum><text>of the risk and
				magnitude of the harm that could result from the disruption or unauthorized
				access, use, disclosure, modification, or destruction of information and
				information systems that support the operations and assets of the agency;
				and</text>
										</subparagraph><subparagraph id="H2CCAF5CACE3E4F769E9822C9BAC9CFC8"><enum>(B)</enum><text>that assess
				whether information or information systems should be removed or migrated to
				more secure networks or standards and make recommendations to the head of the
				agency and the Director of the National Center for Cybersecurity and
				Communications based on that assessment;</text>
										</subparagraph></paragraph><paragraph id="H697CE803ECBC43F5B840E1C432AE9FBD"><enum>(2)</enum><text>consistent with
				guidance developed under section 3554, vulnerability assessments and
				penetration tests commensurate with the risk posed to an agency information
				infrastructure;</text>
									</paragraph><paragraph id="H301B3FC21185471FAE36F3F6896A9006"><enum>(3)</enum><text>ensure that
				information security vul­ner­a­bil­i­ties are remediated or mitigated based on
				the risk posed to the agency;</text>
									</paragraph><paragraph id="H5DD6E16F27C34584B4C637C8488D916B"><enum>(4)</enum><text>policies and
				procedures that—</text>
										<subparagraph id="H5F005EFC8962456E85994960F1C4133D"><enum>(A)</enum><text>are informed and
				revised by the assessments required under paragraphs (1) and (2);</text>
										</subparagraph><subparagraph id="H573AD91A0FF34C9292E5028F06159A18"><enum>(B)</enum><text>cost effectively
				reduce information security risks to an acceptable level;</text>
										</subparagraph><subparagraph id="HA977B23F86C7430B932687C567B3B3B3"><enum>(C)</enum><text>ensure that
				information security is addressed throughout the life cycle of each agency
				information system; and</text>
										</subparagraph><subparagraph id="HAFF3000AA96F45648C624483EAAC9335"><enum>(D)</enum><text>ensure compliance
				with—</text>
											<clause id="HB4941D2F49F54560A0B86FC0DF4A1774"><enum>(i)</enum><text>the requirements
				of this subchapter;</text>
											</clause><clause id="H40B20AC898324CB0B6F7FFE53A266566"><enum>(ii)</enum><text>policies and
				procedures prescribed by the National Center for Cybersecurity and
				Communications;</text>
											</clause><clause id="H549B1DDC1D5A4D0CB6FB2C0F66D92DF7"><enum>(iii)</enum><text>minimally
				acceptable system configuration requirements, as determined by the National
				Center for Cybersecurity and Communications; and</text>
											</clause><clause id="H2C75F0701D8745F4A7D75D6C6D35F1C6"><enum>(iv)</enum><text>any other
				applicable requirements, including standards and guidelines for national
				security systems issued in accordance with law and as directed by the
				President;</text>
											</clause></subparagraph></paragraph><paragraph id="H7AEF9352850843449BB88001014A920A"><enum>(5)</enum><text>subordinate plans
				for providing risk-based information security for networks, facilities, and
				systems or groups of information systems, as appropriate;</text>
									</paragraph><paragraph id="HAFB547C9DCE842B28FC8073E2447E9E9"><enum>(6)</enum><text>role-based
				security awareness training, consistent with the requirements of section 406 of
				the <short-title>Protecting Cyberspace as a National Asset
				Act of 2010</short-title>, to inform personnel with access to the agency
				network, including contractors and other users of information systems that
				support the operations and assets of the agency, of—</text>
										<subparagraph id="HC018B439477740BFAFD1FF8DB00A975C"><enum>(A)</enum><text>information
				security risks associated with agency activities; and</text>
										</subparagraph><subparagraph id="HE1A330607EDE461B9291058133111EE0"><enum>(B)</enum><text>agency
				responsibilities in complying with agency policies and procedures designed to
				reduce those risks;</text>
										</subparagraph></paragraph><paragraph id="H1D79023EF09449BE9CFA607151DF4F31"><enum>(7)</enum><text>periodic testing
				and evaluation of the effectiveness of information security policies,
				procedures, and practices, to be performed with a rigor and frequency depending
				on risk, which shall include—</text>
										<subparagraph id="H536C0461A0AD4F2D9319E0E85354BC12"><enum>(A)</enum><text>testing and
				evaluation not less than twice each year of security controls of information
				collected or maintained by or on behalf of the agency and every information
				system identified in the inventory required under section 3505(c);</text>
										</subparagraph><subparagraph id="H3B6AB4EFFEB14FD0A1AF56D09EB078B8"><enum>(B)</enum><text>the effectiveness
				of ongoing monitoring, including automated and continuous monitoring,
				vulnerability scanning, and intrusion detection and prevention of incidents
				posed to the risk-based security of information and information systems as
				required under subsection (a)(3); and</text>
										</subparagraph><subparagraph id="HC5D0F42E8EB04A47B0A72FEE71D4DB47"><enum>(C)</enum><text>testing relied on
				in—</text>
											<clause id="HC7C32C9C683B4373B684C92F82864D36"><enum>(i)</enum><text>an
				operational evaluation under section 3554;</text>
											</clause><clause id="HFB48C21BFFBA42C195063274B72C526A"><enum>(ii)</enum><text>an independent
				assessment under section 3556; or</text>
											</clause><clause id="H3A2EC30C4D9F45999773649F9A25B420"><enum>(iii)</enum><text>another
				evaluation, to the extent specified by the Director;</text>
											</clause></subparagraph></paragraph><paragraph id="H718D0A79AFCB43128D8B2F244818B3D3"><enum>(8)</enum><text>a process for
				planning, implementing, evaluating, and documenting remedial action to address
				any deficiencies in the information security policies, procedures, and
				practices of the agency;</text>
									</paragraph><paragraph id="H52BE6EA92AC646AA8288457E8A836A09"><enum>(9)</enum><text>procedures for
				detecting, reporting, and responding to incidents, consistent with requirements
				issued under section 3552, that include—</text>
										<subparagraph id="HE01094612C004F9C98B00486469B124E"><enum>(A)</enum><text>to the extent
				practicable, automated and continuous monitoring of the use of information and
				information systems;</text>
										</subparagraph><subparagraph id="HB47C715D5E434525928C78017E81B5BA"><enum>(B)</enum><text>requirements for
				mitigating risks and remediating vulnerabilities associated with such incidents
				systemically within the agency information infrastructure before substantial
				damage is done; and</text>
										</subparagraph><subparagraph id="H9AC24668CE684BCE898DD9C30A9D55C9"><enum>(C)</enum><text>notifying and
				coordinating with the National Center for Cybersecurity and Communications, as
				required by this subchapter, subtitle E of title II of the Homeland Security
				Act of 2002, and any other provision of law; and</text>
										</subparagraph></paragraph><paragraph id="H69F2443B27464E4DB9FE47F8E05F710F"><enum>(10)</enum><text>plans and
				procedures to ensure continuity of operations for information systems that
				support the operations and assets of the agency.</text>
									</paragraph></subsection><subsection id="HED1C4F99F0714E5392EDABF7EDDED453"><enum>(c)</enum><header>Agency
				reporting</header>
									<paragraph id="H25324F71A40342529B35242BE85B3577"><enum>(1)</enum><header>In
				general</header><text>Each agency shall—</text>
										<subparagraph id="H900AABADA47641C59392689B069C93CC"><enum>(A)</enum><text>ensure that
				information relating to the adequacy and effectiveness of information security
				policies, procedures, and practices, is available to the entities identified
				under paragraph (2) through the system developed under section 3552(a)(3),
				including information relating to—</text>
											<clause id="H702FE18F165246FBA4555AAFC0141BCD"><enum>(i)</enum><text>compliance with
				the requirements of this subchapter;</text>
											</clause><clause id="H71D0682B2C9440F0A32E0C894EDCC58E"><enum>(ii)</enum><text>the effectiveness
				of the information security policies, procedures, and practices of the agency
				based on a determination of the aggregate effect of identified deficiencies and
				vulnerabilities;</text>
											</clause><clause id="H1E70E69FFCFC47458132599780F40504"><enum>(iii)</enum><text>an
				identification and analysis of any significant deficiencies identified in such
				policies, procedures, and practices;</text>
											</clause><clause id="HCB75CE5382E9484983387E0D49DE042F"><enum>(iv)</enum><text>an identification
				of any vulnerability that could impair the risk-based security of the agency
				information infrastructure; and</text>
											</clause><clause id="HB1C2825B25EE4E6C80E6AF31057C7100"><enum>(v)</enum><text>results of any
				operational evaluation conducted under section 3554 and plans of action to
				address the deficiencies and vulnerabilities identified as a result of such
				operational evaluation;</text>
											</clause></subparagraph><subparagraph id="H2A8325E3A3174C1DAC4EA838973683D6"><enum>(B)</enum><text>follow the policy,
				guidance, and standards of the National Center for Cybersecurity and
				Communications, in consultation with the Federal Information Security
				Taskforce, to continually update, and ensure the electronic availability of
				both a classified and unclassified version of the information required under
				subparagraph (A);</text>
										</subparagraph><subparagraph id="H51F2E7B169894A0883DFD7D744FBA350"><enum>(C)</enum><text>ensure the
				information under subparagraph (A) addresses the adequacy and effectiveness of
				information security policies, procedures, and practices in plans and reports
				relating to—</text>
											<clause id="H8FE8356F197041E5B8FF11A0078959B3"><enum>(i)</enum><text>annual agency
				budgets;</text>
											</clause><clause id="H6FB5CBC2DA0F481AAD58869959B7854F"><enum>(ii)</enum><text>information
				resources management of this subchapter;</text>
											</clause><clause id="HC3C6DA4C38014194A593E55CC75F69DA"><enum>(iii)</enum><text>information
				technology management and procurement under this chapter or any other
				applicable provision of law;</text>
											</clause><clause id="HFF23F337020D43AF978FCFF1FA8A9DE2"><enum>(iv)</enum><text>subtitle E of
				title II of the Homeland Security Act of 2002;</text>
											</clause><clause id="H377B50C06A9045AC8EDB3567B4B22DBA"><enum>(v)</enum><text>program
				performance under sections 1105 and 1115 through 1119 of title 31, and sections
				2801 and 2805 of title 39;</text>
											</clause><clause id="HF1DCC940327E490BA89713E8939B31BC"><enum>(vi)</enum><text>financial
				management under chapter 9 of title 31, and the Chief Financial Officers Act of
				1990 (31 U.S.C. 501 note; Public Law 101–576) (and the amendments made by that
				Act);</text>
											</clause><clause id="HE33D03D6583C48F1AE3127828D7E84EF"><enum>(vii)</enum><text>financial
				management systems under the Federal Financial Management Improvement Act (31
				U.S.C. 3512 note);</text>
											</clause><clause id="H260B419F7D7440E7B2236354251666CB"><enum>(viii)</enum><text>internal
				accounting and administrative controls under section 3512 of title 31;
				and</text>
											</clause><clause id="HE5DAA3BBF6AA40B2951D5859B46FC326"><enum>(ix)</enum><text>performance
				ratings, salaries, and bonuses provided to the senior managers and supporting
				personnel taking into account program performance as it relates to complying
				with this subchapter; and</text>
											</clause></subparagraph><subparagraph id="H55113929107F47BFB18663D0E68587D4"><enum>(D)</enum><text>report any
				significant deficiency in a policy, procedure, or practice identified under
				subparagraph (A) or (B)—</text>
											<clause id="H3D95EB26452D4EF8860AEFCA070EDB8C"><enum>(i)</enum><text>as
				a material weakness in reporting under section 3512 of title 31; and</text>
											</clause><clause id="H0CA4FEA3FD704CA499A6FCF8E8EDC8CF"><enum>(ii)</enum><text>if relating to
				financial management systems, as an instance of a lack of substantial
				compliance under the Federal Financial Management Improvement Act (31 U.S.C.
				3512 note).</text>
											</clause></subparagraph></paragraph><paragraph id="H449090371446486BAF1CD5868FD60770"><enum>(2)</enum><header>Adequacy and
				effectiveness information</header><text>Information required under paragraph
				(1)(A) shall, to the extent possible and in accordance with applicable law,
				policy, guidance, and standards, be available on an automated and continuous
				basis to—</text>
										<subparagraph id="HDDE6ED711DAD49DC8D6DE40A18399BC2"><enum>(A)</enum><text>the National
				Center for Cybersecurity and Communications;</text>
										</subparagraph><subparagraph id="H66A6BB31E4B9461D9A6CD7FC0D0BC9BD"><enum>(B)</enum><text>the Committee on
				Homeland Security and Governmental Affairs of the Senate;</text>
										</subparagraph><subparagraph id="H9D24982FEE8F4C10AB0C4E72CA2BB931"><enum>(C)</enum><text>the Committee on
				Government Oversight and Reform of the House of Representatives;</text>
										</subparagraph><subparagraph id="H865FADB1F13F47D3AE1D5DADC0715138"><enum>(D)</enum><text>the Committee on
				Homeland Security of the House of Representatives;</text>
										</subparagraph><subparagraph id="H5E82B22C6000406D86BE93D2C74FB35A"><enum>(E)</enum><text>other appropriate
				authorization and appropriations committees of Congress;</text>
										</subparagraph><subparagraph id="H162A7E0210CD4777AD2C1E7E77F47F09"><enum>(F)</enum><text>the Inspector
				General of the Federal agency; and</text>
										</subparagraph><subparagraph id="H78001D06C89A48BA818046D5203F09B8"><enum>(G)</enum><text>the Comptroller
				General.</text>
										</subparagraph></paragraph></subsection><subsection id="H039ED602A1B745E18BEB80B0D4182A71"><enum>(d)</enum><header>Inclusions in
				performance plans</header>
									<paragraph id="HB8F60E621BC24916A086A266A509830D"><enum>(1)</enum><header>In
				General</header><text>In addition to the requirements of subsection (c), each
				agency, in consultation with the National Center for Cybersecurity and
				Communications, shall include as part of the performance plan required under
				section 1115 of title 31 a description of the time periods the resources,
				including budget, staffing, and training, that are necessary to implement the
				program required under subsection (b).</text>
									</paragraph><paragraph id="H5D25D59BC9DB4EB09B087388AB525E7C"><enum>(2)</enum><header>Risk
				assessments</header><text>The description under paragraph (1) shall be based on
				the risk and vulnerability assessments required under subsection (b) and
				evaluations required under section 3554.</text>
									</paragraph></subsection><subsection id="H3B081BC188F34FB6A8DB23249D4FB6AE"><enum>(e)</enum><header>Notice and
				comment</header><text>Each agency shall provide the public with timely notice
				and opportunities for comment on proposed information security policies and
				procedures to the extent that such policies and procedures affect communication
				with the public.</text>
								</subsection><subsection id="H5BDBA881427E4D66B8D8CF4AA7E28A25"><enum>(f)</enum><header>More stringent
				standards</header><text>The head of an agency may employ standards for the cost
				effective information security for information systems within or under the
				supervision of that agency that are more stringent than the standards the
				Director of the National Center for Cybersecurity and Communications prescribes
				under this subchapter, subtitle E of title II of the Homeland Security Act of
				2002, or any other provision of law, if the more stringent standards—</text>
									<paragraph id="HDDFB180E0EBD49F382997C52EAD3B3BC"><enum>(1)</enum><text>contain at least
				the applicable standards made compulsory and binding by the Director of the
				National Center for Cybersecurity and Communications; and</text>
									</paragraph><paragraph id="HB65AA5C045544520B7A2DABE341794B3"><enum>(2)</enum><text>are otherwise
				consistent with policies and guidelines issued under section 3552.</text>
									</paragraph></subsection></section><section commented="no" id="H88A61F4926C9426CB8F703BD6603C249"><enum>3554.</enum><header>Annual
				operational evaluation</header>
								<subsection commented="no" id="HA3F842105A3C4A67ACEA8D4218666F75"><enum>(a)</enum><header>Guidance</header>
									<paragraph commented="no" id="H17A0B5E73F834376B72A39A20BC93FF8"><enum>(1)</enum><header>In
				general</header><text>Each year the National Center for Cybersecurity and
				Communications shall oversee, coordinate, and develop guidance for the
				effective implementation of operational evaluations of the Federal information
				infrastructure and agency information security programs and practices to
				determine the effectiveness of such program and practices.</text>
									</paragraph><paragraph commented="no" id="H7CBFC3B1237B4C209ECDD996B0E02DEB"><enum>(2)</enum><header>Collaboration in
				development</header><text>In developing guidance for the operational
				evaluations described under this section, the National Center for Cybersecurity
				and Communications shall collaborate with the Federal Information Security
				Taskforce and the Council of Inspectors General on Integrity and Efficiency,
				and other agencies as necessary, to develop and update risk-based performance
				indicators and measures that assess the adequacy and effectiveness of
				information security of an agency and the Federal information
				infrastructure.</text>
									</paragraph><paragraph commented="no" id="H760F3DB3D44448418B5DCD6F30E1C54C"><enum>(3)</enum><header>Contents of
				operational evaluation</header><text>Each operational evaluation under this
				section—</text>
										<subparagraph commented="no" id="HA9101AA05C6142E495C8FF5F5A16C66F"><enum>(A)</enum><text>shall be
				prioritized based on risk; and</text>
										</subparagraph><subparagraph commented="no" id="H513FD6E5ED404BE8AEC4408A83885AF3"><enum>(B)</enum><text>shall—</text>
											<clause commented="no" id="H0B6F75F96FE44911A411CFD9492A1421"><enum>(i)</enum><text>test the
				effectiveness of agency information security policies, procedures, and
				practices of the information systems of the agency, or a representative subset
				of those information systems;</text>
											</clause><clause commented="no" id="H8707058C3AFA4D8DAA13CDB8C9007FE3"><enum>(ii)</enum><text>assess (based on
				the results of the testing) compliance with—</text>
												<subclause commented="no" id="H28736539657B48A0A3028EF763A3CD11"><enum>(I)</enum><text>the requirements
				of this subchapter; and</text>
												</subclause><subclause commented="no" id="HFF0298B7BB9E44019C7C4A68AC82B90D"><enum>(II)</enum><text>related
				information security policies, procedures, standards, and guidelines;</text>
												</subclause></clause><clause commented="no" id="H995D1F3D02734128950909F038C292C2"><enum>(iii)</enum><text>evaluate whether
				agencies—</text>
												<subclause commented="no" id="HB0CBC30D24FF4C6491ADF685776A2E53"><enum>(I)</enum><text>effectively
				monitor, detect, analyze, protect, report, and respond to vulnerabilities and
				incidents;</text>
												</subclause><subclause commented="no" id="H5C99310E28AC43A688221965C8D2ED3F"><enum>(II)</enum><text>report to and
				collaborate with the appropriate public and private security operation centers,
				the National Center for Cybersecurity and Communications, and law enforcement
				agencies; and</text>
												</subclause><subclause commented="no" id="H3F84951FE9B84F4B88F9DA26BE8DD1FF"><enum>(III)</enum><text>remediate or
				mitigate the risk posed by attacks and exploitations in a timely fashion in
				order to prevent future vulnerabilities and incidents; and</text>
												</subclause></clause><clause commented="no" id="H36446CC449B648789776FB7A13838679"><enum>(iv)</enum><text>identify
				deficiencies of agency information security policies, procedures, and controls
				on the agency information infrastructure.</text>
											</clause></subparagraph></paragraph></subsection><subsection commented="no" id="HF483FA2542134DC891EB344BFA3680DC"><enum>(b)</enum><header>Conduct an
				operational evaluation</header>
									<paragraph commented="no" id="H7FCCAD9F647F4E64A0D08B038EC1B9E9"><enum>(1)</enum><header>In
				general</header><text>Except as provided under paragraph (2), and in
				consultation with the Chief Information Officer and senior officials
				responsible for the affected systems, the Chief Information Security Officer of
				each agency shall not less than annually—</text>
										<subparagraph commented="no" id="HF94370E739BE49A1BE1E2839A240B3BA"><enum>(A)</enum><text>conduct an
				operational evaluation of the agency information infrastructure for
				vulnerabilities, attacks, and exploitations of the agency information
				infrastructure;</text>
										</subparagraph><subparagraph commented="no" id="HBAC8F243FA0E41A7ADEA8BAB42F5DF6F"><enum>(B)</enum><text>evaluate the
				ability of the agency to monitor, detect, correlate, analyze, report, and
				respond to incidents; and</text>
										</subparagraph><subparagraph commented="no" id="HEB970F864FB94B5FAAE3254421305F74"><enum>(C)</enum><text>report to the head
				of the agency, the National Center for Cybersecurity and Communications, the
				Chief Information Officer, and the Inspector General for the agency the
				findings of the operational evaluation.</text>
										</subparagraph></paragraph><paragraph commented="no" id="H3D626C83838A4826B2DAC77F749C5EA0"><enum>(2)</enum><header>Satisfaction of
				requirements by other evaluation</header><text>Unless otherwise specified by
				the Director of the National Center for Cybersecurity and Communications, if
				the National Center for Cybersecurity and Communications conducts an
				operational evaluation of the agency information infrastructure under section
				245(b)(2)(A) of the Homeland Security Act of 2002, the Chief Information
				Security Officer may deem the requirements of paragraph (1) satisfied for the
				year in which the operational evaluation described under this paragraph is
				conducted.</text>
									</paragraph></subsection><subsection id="H1A9F3749D7C14E52A5A0787A6C2E906C"><enum>(c)</enum><header>Corrective
				measures mitigation and remediation plans</header>
									<paragraph id="H3F36A966753540869C0383D04FBBAC78"><enum>(1)</enum><header>In
				general</header><text>In consultation with the National Center for
				Cybersecurity and Communications and the Chief Information Officer, Chief
				Information Security Officers shall remediate or mitigate vulnerabilities in
				accordance with this subsection.</text>
									</paragraph><paragraph id="H2D96C6EB0552491387E42B92FE9841EE"><enum>(2)</enum><header>Risk-based
				plan</header><text>After an operational evaluation is conducted under this
				section or under section 245(b) of the Homeland Security Act of 2002, the
				agency shall submit to the National Center for Cybersecurity and Communications
				in a timely fashion a risk-based plan for addressing recommendations and
				mitigating and remediating vulnerabilities identified as a result of such
				operational evaluation, including a timeline and budget for implementing such
				plan.</text>
									</paragraph><paragraph id="H6DC67797BBDF44458BB567FCB0F2D9FB"><enum>(3)</enum><header>Approval or
				disapproval</header><text>Not later than 15 days after receiving a plan
				submitted under paragraph (2), the National Center for Cybersecurity and
				Communications shall—</text>
										<subparagraph id="HE9BE2EE0C77748419A238A02591320DF"><enum>(A)</enum><text>approve or
				disprove the agency plan; and</text>
										</subparagraph><subparagraph id="H41B30B91915F44A5B19C32901E78F8B6"><enum>(B)</enum><text>comment on the
				adequacy and effectiveness of the plan.</text>
										</subparagraph></paragraph><paragraph commented="no" id="HCDC9BB3C01D4417EABE1FAB8D3346A92"><enum>(4)</enum><header>Isolation from
				infrastructure</header>
										<subparagraph commented="no" id="H7517B2C6F29E44759E4CC0F96C466DDC"><enum>(A)</enum><header>In
				general</header><text>The Director of the National Center for Cybersecurity and
				Communications may, consistent with the contingency or continuity of operation
				plans applicable to such agency information infrastructure, order the isolation
				of any component of the Federal information infrastructure from any other
				Federal information infrastructure, if—</text>
											<clause commented="no" id="H0B7F7644AC25497EA3B16376F68EA071"><enum>(i)</enum><text>an agency does not
				implement measures in a risk-based plan approved under this subsection;
				and</text>
											</clause><clause commented="no" id="H4CE7F20FCDA343349C07CA0BFB4D0F46"><enum>(ii)</enum><text>the failure to
				comply presents a significant danger to the Federal information
				infrastructure.</text>
											</clause></subparagraph><subparagraph commented="no" id="H20AE6EE6A2F548CA83A8138C11EED548"><enum>(B)</enum><header>Duration</header><text>An
				isolation under subparagraph (A) shall remain in effect until—</text>
											<clause commented="no" id="H848F549AEB204DF0BDA170400ADCE845"><enum>(i)</enum><text>the Director of
				the National Center for Cybersecurity and Communications determines that
				corrective measures have been implemented; or</text>
											</clause><clause commented="no" id="H24992DE01C434C56A2E3052231D8D8C1"><enum>(ii)</enum><text>an updated
				risk-based plan is approved by the National Center for Cybersecurity and
				Communications and implemented by the agency.</text>
											</clause></subparagraph></paragraph></subsection><subsection id="H0EBCB276BC8A42F5903A772A44933C1F"><enum>(d)</enum><header>Operational
				guidance</header><text>The Director of the National Center for Cybersecurity
				and Communications shall—</text>
									<paragraph id="H2F07B97EE1B74AC4A443BF671475C6CD"><enum>(1)</enum><text>not later than 180
				days after the date of enactment of the <short-title>Protecting Cyberspace as a National Asset Act of
				2010</short-title>, develop operational guidance for operational evaluations as
				required under this section that are risk-based and cost effective; and</text>
									</paragraph><paragraph id="H1834EC805B5448A5A59213577F6BCC05"><enum>(2)</enum><text>periodically
				evaluate and ensure information is available on an automated and continuous
				basis through the system required under section 3552(a)(3)(D) to Congress
				on—</text>
										<subparagraph id="HC4279731A78648C6B61F1D5AB45FEBB3"><enum>(A)</enum><text>the adequacy and
				effectiveness of the operational evaluations conducted under this section or
				section 245(b) of the Homeland Security Act of 2002; and</text>
										</subparagraph><subparagraph id="H60074CAEC528478797058DA983FC919E"><enum>(B)</enum><text>possible executive
				and legislative actions for cost-effectively managing the risks to the Federal
				information infrastructure.</text>
										</subparagraph></paragraph></subsection></section><section id="H19853BFF76FA4868B6A81CE0FB621C5C"><enum>3555.</enum><header>Federal
				Information Security Taskforce</header>
								<subsection id="H385B16A3CF5349A2BDD34084FC9283AF"><enum>(a)</enum><header>Establishment</header><text>There
				is established in the executive branch a Federal Information Security
				Taskforce.</text>
								</subsection><subsection id="HF3B4916952324DA8B32C1A34565BF63C"><enum>(b)</enum><header>Membership</header><text>The
				members of the Federal Information Security Taskforce shall be full-time senior
				Government employees and shall be as follows:</text>
									<paragraph id="H48224E2E24A94EAAA71B9AE0FB599885"><enum>(1)</enum><text>The Director of
				the National Center for Cybersecurity and Communications.</text>
									</paragraph><paragraph id="H4E57988840C3494CA191CBBE8158F69B"><enum>(2)</enum><text>The Administrator
				of the Office of Electronic Government of the Office of Management and
				Budget.</text>
									</paragraph><paragraph id="HB411FE722CC148B4B8015BC5065F8B8F"><enum>(3)</enum><text>The Chief
				Information Security Officer of each agency described under section 901(b) of
				title 31.</text>
									</paragraph><paragraph id="H62A7CA017F4C4DA2A32B7D2DEC3F7779"><enum>(4)</enum><text>The Chief
				Information Security Officer of the Department of the Army, the Department of
				the Navy, and the Department of the Air Force.</text>
									</paragraph><paragraph id="H5D7668A307A742818D590C38B76D09CB"><enum>(5)</enum><text>A representative
				from the Office of Cyberspace Policy.</text>
									</paragraph><paragraph id="H3713936B4EA64E90B601955DADC04C39"><enum>(6)</enum><text>A representative
				from the Office of the Director of National Intelligence.</text>
									</paragraph><paragraph id="H1D58A59295914AD5BC03CC34185B111D"><enum>(7)</enum><text>A representative
				from the United States Cyber Command.</text>
									</paragraph><paragraph id="HC5255D69D5A24609A3E8D02BCF2D31A6"><enum>(8)</enum><text>A representative
				from the National Security Agency.</text>
									</paragraph><paragraph id="H6FE276A8B65A4F6286A62890E954094C"><enum>(9)</enum><text>A representative
				from the United States Computer Emergency Readiness Team.</text>
									</paragraph><paragraph id="H7E0C0CD2976B421DB14307135EC89799"><enum>(10)</enum><text>A representative
				from the Intelligence Community Incident Response Center.</text>
									</paragraph><paragraph id="H7FABD87BB2A94CF9A4055413CE533A9D"><enum>(11)</enum><text>A representative
				from the Committee on National Security Systems.</text>
									</paragraph><paragraph id="HB5DC4443E08F4D3FBA44F9C689DC2775"><enum>(12)</enum><text>A representative
				from the National Institute for Standards and Technology.</text>
									</paragraph><paragraph id="HBA46210C2AC94CE4827C45391894DEEC"><enum>(13)</enum><text>A representative
				from the Council of Inspectors General on Integrity and Efficiency.</text>
									</paragraph><paragraph id="HC4357C92D9FC495795BA4196DE51F9E3"><enum>(14)</enum><text>A representative
				from State and local government.</text>
									</paragraph><paragraph id="H0140F4245EF84651948AD30042D79AB0"><enum>(15)</enum><text>Any other officer
				or employee of the United States designated by the chairperson.</text>
									</paragraph></subsection><subsection id="HAD5F7CCB1B6841E8832003254EFF987F"><enum>(c)</enum><header>Chairperson and
				Vice-Chairperson</header>
									<paragraph id="HE6B9971AB7A5482B86A84E7E583F989F"><enum>(1)</enum><header>Chairperson</header><text>The
				Director of the National Center for Cybersecurity and Communications shall act
				as chairperson of the Federal Information Security Taskforce.</text>
									</paragraph><paragraph id="H85EF6ECC87194CC5947E6F950973969E"><enum>(2)</enum><header>Vice-chairperson</header><text>The
				vice chairperson of the Federal Information Security Taskforce shall—</text>
										<subparagraph id="H2080A5F35CEC4FA8AFCA77838507156D"><enum>(A)</enum><text>be selected by the
				Federal Information Security Taskforce from among its members;</text>
										</subparagraph><subparagraph id="H4C900E59FB6A4E8EBEB2F41D92C8BA19"><enum>(B)</enum><text>serve a 1-year
				term and may serve multiple terms; and</text>
										</subparagraph><subparagraph id="HB41F7580A80A4AE6B5054AFB42FFBC6E"><enum>(C)</enum><text>serve as a liaison
				to the Chief Information Officer, Council of the Inspectors General on
				Integrity and Efficiency, Committee on National Security Systems, and other
				councils or committees as appointed by the chairperson.</text>
										</subparagraph></paragraph></subsection><subsection id="HD85BCB25C8EF4865B5FBE871E8F40BBB"><enum>(d)</enum><header>Functions</header><text>The
				Federal Information Security Taskforce shall—</text>
									<paragraph id="HD816CE0C856B41AAA562DFB110B21D5F"><enum>(1)</enum><text>be the principal
				interagency forum for collaboration regarding best practices and
				recommendations for agency information security and the security of the Federal
				information infrastructure;</text>
									</paragraph><paragraph id="H45DBB1C072BC411F91F50AE43BD03A64"><enum>(2)</enum><text>assist in the
				development of and annually evaluate guidance to fulfill the requirements under
				sections 3554 and 3556;</text>
									</paragraph><paragraph id="H34944064944E4197A5278FB45400A6D6"><enum>(3)</enum><text>share experiences
				and innovative approaches relating to threats against the Federal information
				infrastructure, information sharing and information security best practices,
				penetration testing regimes, and incident response, mitigation, and
				remediation;</text>
									</paragraph><paragraph id="H827237CB1A8A46CA9EA324B8B70E027C"><enum>(4)</enum><text>promote the
				development and use of standard performance indicators and measures for agency
				information security that—</text>
										<subparagraph id="HE1C139B345AC4563AF9E05E620D46750"><enum>(A)</enum><text>are
				outcome-based;</text>
										</subparagraph><subparagraph id="H46AB483D0201422FB870042F6E2243B1"><enum>(B)</enum><text>focus on risk
				management;</text>
										</subparagraph><subparagraph id="H63446E7B65064A0A877AC28AEA014646"><enum>(C)</enum><text>align with the
				business and program goals of the agency;</text>
										</subparagraph><subparagraph id="H7A730BF6C0AE45C7BBD2DB3525549E17"><enum>(D)</enum><text>measure
				improvements in the agency security posture over time; and</text>
										</subparagraph><subparagraph id="HF1EF75677E40467DB206B497C7454B46"><enum>(E)</enum><text>reduce burdensome
				and efficient performance indicators and measures;</text>
										</subparagraph></paragraph><paragraph id="H7CAF49AECE534B7AB4543FCAB5CC800B"><enum>(5)</enum><text>recommend to the
				Office of Personnel Management the necessary qualifications to be established
				for Chief Information Security Officers to be capable of administering the
				functions described under this subchapter including education, training, and
				experience;</text>
									</paragraph><paragraph id="H3E9B5FB853814D6EB114130C5E446EDB"><enum>(6)</enum><text>enhance
				information system processes by establishing a prioritized baseline of
				information security measures and controls that can be continuously monitored
				through automated mechanisms;</text>
									</paragraph><paragraph id="H1048B8E69F534D7BBA143124DAFBF747"><enum>(7)</enum><text>evaluate the
				effectiveness and efficiency of any reporting and compliance requirements that
				are required by law related to the information security of Federal information
				infrastructure; and</text>
									</paragraph><paragraph id="H80DF53402A424F87A3C069B803EBFADF"><enum>(8)</enum><text>submit proposed
				enhancements developed under paragraphs (1) through (7) to the Director of the
				National Center for Cybersecurity and Communications.</text>
									</paragraph></subsection><subsection id="H0455240304A1410A8F002C66D350D0AC"><enum>(e)</enum><header>Termination</header>
									<paragraph id="H1481BDBDC3184D47B6EE43F8888993BF"><enum>(1)</enum><header>In
				general</header><text>Except as provided under paragraph (2), the Federal
				Information Security Taskforce shall terminate 4 years after the date of
				enactment of the <short-title>Protecting Cyberspace as a
				National Asset Act of 2010</short-title>.</text>
									</paragraph><paragraph id="HF1F48C38ED304F85AB59CDFC8E0DA6E8"><enum>(2)</enum><header>Extension</header><text>The
				President may—</text>
										<subparagraph id="H2EEBCA72BE9745B2A9ED80DFEAE2AFE5"><enum>(A)</enum><text>extend the Federal
				Information Security Taskforce by executive order; and</text>
										</subparagraph><subparagraph id="HC7BA1F900BB3409DA795B5DF3D317F9E"><enum>(B)</enum><text>make more than 1
				extension under this paragraph for any period as the President may
				determine.</text>
										</subparagraph></paragraph></subsection></section><section id="HF0D5DE7B396544BCBC13BB60012A27F9"><enum>3556.</enum><header>Independent
				assessments</header>
								<subsection id="HF78259170C3A4C1BAA02371908BC065B"><enum>(a)</enum><header>In
				general</header>
									<paragraph id="HF94DFF66D33343329ABA867423CDEA8D"><enum>(1)</enum><header>Inspectors
				General assessments</header><text>Not less than every 2 years, each agency with
				an Inspector General appointed under the Inspector General Act of 1978 (5
				U.S.C. App.) shall assess the adequacy and effectiveness of the information
				security program developed under section 3553(b) and (c), and evaluations
				conducted under section 3554.</text>
									</paragraph><paragraph id="H4E5BE9DFD4B54FED8E17D0CF44D8AC43"><enum>(2)</enum><header>Independent
				assessments</header><text>For each agency to which paragraph (1) does not
				apply, the head of the agency shall engage an independent external auditor to
				perform the assessment.</text>
									</paragraph></subsection><subsection id="H82288F2A3C614421954D060AD386C938"><enum>(b)</enum><header>Existing
				assessments</header><text>The assessments required by this section may be based
				in whole or in part on an audit, evaluation, or report relating to programs or
				practices of the applicable agency.</text>
								</subsection><subsection id="H27B4523282164D5A930C543FCDB8BF10"><enum>(c)</enum><header>Inspectors
				General reporting</header><text>Inspectors General shall ensure information
				obtained as a result of the assessment required under this section, or any
				other relevant information, is available through the system required under
				section 3552(a)(3)(D) to Congress and the National Center for Cybersecurity and
				Communications.</text>
								</subsection></section><section id="HE7B30D3238DA4B62AC0B3768159F1F4E"><enum>3557.</enum><header>Protection of
				information</header>
								<subsection id="HAFF0810643D04AEE9872CEC7CE8FF5EC"><enum></enum><text>In complying
				with this subchapter, agencies, evaluators, and Inspectors General shall take
				appropriate actions to ensure the protection of information which, if
				disclosed, may adversely affect information security. Protections under this
				chapter shall be commensurate with the risk and comply with all applicable laws
				and
				regulations.</text>
								</subsection></section></subchapter><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="HCD6E0C0629D840779ED8973589DFB458"><enum>(c)</enum><header>Technical and
			 conforming amendments</header>
					<paragraph id="H4C6D4EBC3EFF4181A49C1B5EBD61F1EE"><enum>(1)</enum><header>Table of
			 sections</header><text>The table of sections for chapter 35 of title 44, United
			 States Code, is amended by striking the matter relating to subchapters II and
			 III and inserting the following:</text>
						<quoted-block id="HCFFACCC7F3164E00ACAD7A38F2075CFB" style="USC">
							<toc>
								<toc-entry idref="H65F7FF0A148F498E9BB1F552D7100791" level="subchapter">SUBCHAPTER II—Information security</toc-entry>
								<toc-entry idref="H02C8A01C3F8D471AA319D31EFF173CCD" level="section">3550. Purposes.</toc-entry>
								<toc-entry idref="H4763D7F327CA4395AE4EC42F40956891" level="section">3551. Definitions.</toc-entry>
								<toc-entry idref="HD8F7E73B3462454C8B098214865C4B20" level="section">3552. Authority and functions of the National Center for
				Cybersecurity and Communications.</toc-entry>
								<toc-entry idref="H51415E316A044F708CE044FB4DD106D3" level="section">3553. Agency responsibilities.</toc-entry>
								<toc-entry idref="H88A61F4926C9426CB8F703BD6603C249" level="section">3554. Annual operational evaluation.</toc-entry>
								<toc-entry idref="H19853BFF76FA4868B6A81CE0FB621C5C" level="section">3555. Federal Information Security Taskforce.</toc-entry>
								<toc-entry bold="off" idref="H19853BFF76FA4868B6A81CE0FB621C5C" level="section">3556. Independent
				assessments.</toc-entry>
								<toc-entry bold="off" idref="H19853BFF76FA4868B6A81CE0FB621C5C" level="section">3557. Protection of
				information.</toc-entry>
							</toc>
							<after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph><paragraph commented="no" id="H93D49163C0FF4BA7ACBE1E70F8DE2D40"><enum>(2)</enum><header>Other
			 references</header>
						<subparagraph id="HB9BA84F92BC64A72BF686FB193D05777"><enum>(A)</enum><text>Section
			 1001(c)(1)(A) of the Homeland Security Act of 2002 (6 U.S.C. 511(c)(1)(A)) is
			 amended by striking <quote>section 3532(3)</quote> and inserting <quote>section
			 3551(b)</quote>.</text>
						</subparagraph><subparagraph id="HDCFBD9EB67714106B53B2926F5DDF6A4"><enum>(B)</enum><text>Section 2222(j)(6)
			 of title 10, United States Code, is amended by striking <quote>section
			 3542(b)(2))</quote> and inserting <quote>section 3551(b)</quote>.</text>
						</subparagraph><subparagraph id="H235666496BA145D0BF1A92E5214533D1"><enum>(C)</enum><text>Section 2223(c)(3)
			 of title 10, United States Code, is amended, by striking <quote>section
			 3542(b)(2))</quote> and inserting <quote>section 3551(b)</quote>.</text>
						</subparagraph><subparagraph id="H96D9B479410747388A8C2211EADCFA4F"><enum>(D)</enum><text>Section 2315 of
			 title 10, United States Code, is amended by striking <quote>section
			 3542(b)(2))</quote> and inserting <quote>section 3551(b)</quote>.</text>
						</subparagraph><subparagraph id="H78C35D84A50B4A4E96A7C7347AD59A81"><enum>(E)</enum><text>Section 20(a)(2)
			 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) is
			 amended by striking <quote>section 3532(b)(2)</quote> and inserting
			 <quote>section 3551(b)</quote>.</text>
						</subparagraph><subparagraph commented="no" id="H012397D1A37A470682158309718E34E4"><enum>(F)</enum><text>Section 21(b)(2)
			 of the National Institute of Standards and Technology Act (15 U.S.C.
			 278g–4(b)(2)) is amended by striking <quote>Institute and</quote> and inserting
			 <quote>Institute, the Director of the National Center on Cybersecurity and
			 Communications, and</quote>.</text>
						</subparagraph><subparagraph commented="no" id="H77B991CD421F47A3993AAE7DC8B85CE0"><enum>(G)</enum><text>Section 21(b)(3)
			 of the National Institute of Standards and Technology Act (15 U.S.C.
			 278g–4(b)(3)) is amended by inserting <quote>the Director of the National
			 Center on Cybersecurity and Communications,</quote> after <quote>the Director
			 of the National Security Agency,</quote>.</text>
						</subparagraph><subparagraph id="H4BF71A2E27B94C0FA13C80C6DB4C3C75"><enum>(H)</enum><text>Section 8(d)(1) of
			 the Cyber Security Research and Development Act (15 U.S.C. 7406(d)(1)) is
			 amended by striking <quote>section 3534(b)</quote> and inserting <quote>section
			 3553(b)</quote>.</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="H22E18437022E4232B02E08EC1FEE2C64"><enum>(3)</enum><header>Homeland
			 Security Act of 2002</header>
						<subparagraph commented="no" display-inline="no-display-inline" id="H5E40EB985B294A85A242AA7B828D3B24"><enum>(A)</enum><header>Title
			 X</header><text>The Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is
			 amended by striking title X.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H8A779D3497C944AC985AFB2EEF1C2234"><enum>(B)</enum><header>Table of
			 contents</header><text>The table of contents in section 1(b) of the Homeland
			 Security Act of 2002 (6 U.S.C. 101 et seq.) is amended by striking the matter
			 relating to title X.</text>
						</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="H32BA38E4FA64431BB32A92739A69E5BF"><enum>(d)</enum><header>Repeal of other
			 standards</header>
					<paragraph commented="no" display-inline="no-display-inline" id="H32B0508AAA514E6BB3838FF51F234C25"><enum>(1)</enum><header>In
			 general</header><text>Section 11331 of title 40, United States Code, is
			 repealed.</text>
					</paragraph><paragraph id="H9AA17909B6A64D01ADABAC65FBDB44F0"><enum>(2)</enum><header>Technical and
			 conforming amendments</header>
						<subparagraph id="H2AB34DDE9AC64D0F9063B2D697EB7155"><enum>(A)</enum><text>Section 20(c)(3)
			 of the National Institute of Standards and Technology Act (15 U.S.C.
			 278g–3(c)(3)) is amended by striking <quote>under section 11331 of title 40,
			 United States Code</quote>.</text>
						</subparagraph><subparagraph id="H99BAA270C1CA4A3D800D4F199DE03B6B"><enum>(B)</enum><text>Section 20(d)(1)
			 of the National Institute of Standards and Technology Act (15 U.S.C.
			 278g–3(d)(1)) is amended by striking <quote>the Director of the Office of
			 Management and Budget for promulgation under section 11331 of title 40, United
			 States Code</quote> and inserting <quote>the Secretary of Commerce for
			 promulgation</quote>.</text>
						</subparagraph><subparagraph id="HA11224B5B1A54F1D9C926BA9B35E95C4"><enum>(C)</enum><text>Section 11302(d)
			 of title 40, United States Code, is amended by striking <quote>under section
			 11331 of this title and</quote>.</text>
						</subparagraph><subparagraph id="HAE4F35D7496B4611BE490C6C5E315A06"><enum>(D)</enum><text>Section 1874A
			 (e)(2)(A)(ii) of the Social Security Act (42 U.S.C.1395kk–1 (e)(2)(A)(ii)) is
			 amended by striking <quote>section 11331 of title 40, United States
			 Code</quote> and inserting <quote>section 3552 of title 44, United States
			 Code</quote>.</text>
						</subparagraph><subparagraph id="HC0C8EF8A693342849EFB0B1C781F39DA"><enum>(E)</enum><text>Section 3504(g)(2)
			 of title 44, United States Code, is amended by striking <quote>section 11331 of
			 title 40</quote> and inserting <quote>section 3552 of title 44</quote>.</text>
						</subparagraph><subparagraph id="H09A7A5AABB394796B382009F52BDA379"><enum>(F)</enum><text>Section 3504(h)(1)
			 of title 44, United States Code, is amended by inserting “, the Director of the
			 National Center for Cybersecurity and Communications,” after <quote>the
			 National Institute of Standards and Technology</quote>.</text>
						</subparagraph><subparagraph id="H568E825D5670474382B9CDE4B478C324"><enum>(G)</enum><text>Section
			 3504(h)(1)(B) of title 44, United States Code, is amended by striking
			 <quote>under section 11331 of title 40</quote> and inserting <quote>section
			 3552 of title 44</quote>.</text>
						</subparagraph><subparagraph id="H1120450472094BED8D3DBBEAC9A20F76"><enum>(H)</enum><text>Section 3518(d) of
			 title 44, United States Code, is amended by striking <quote>sections 11331 and
			 11332</quote> and inserting <quote>section 11332</quote>.</text>
						</subparagraph><subparagraph id="H1E33DDD3C2BE488D960760C989910757"><enum>(I)</enum><text>Section 3602(f)(8)
			 of title 44, United States Code, is amended by striking “under section 11331 of
			 title 40.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H7B5BCCDB925B42D59B9CD83A2944A62C"><enum>(J)</enum><text>Section 3603(f)(5)
			 of title 44, United States Code, is amended by striking <quote>and promulgated
			 under section 11331 of title 40,</quote>.</text>
						</subparagraph></paragraph></subsection></section></title><title id="HC968D53EDBFE4A039B162AD6761CE7AA"><enum>IV</enum><header>Recruitment and
			 professional development</header>
			<section id="H226D9E15AF224164BD408FA0A41207B4"><enum>401.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text>
				<paragraph id="HD66EBCCB12FD41FCA6AC21C86F4B5C7D"><enum>(1)</enum><header>Cybersecurity
			 mission</header><text display-inline="yes-display-inline">The term
			 <term>cybersecurity mission</term> means the activities of the Federal
			 Government that encompass the full range of threat reduction, vulnerability
			 reduction, deterrence, international engagement, incident response, resiliency,
			 and recovery policies and activities, including computer network operations,
			 information assurance, law enforcement, diplomacy, military, and intelligence
			 missions as such activities relate to the security and stability of
			 cyberspace.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="HF1864D189A3843AB88A06382E6FE32D1"><enum>(2)</enum><header display-inline="yes-display-inline">Federal agency’s cybersecurity
			 mission</header><text display-inline="yes-display-inline">The term
			 <term>Federal agency's cybersecurity mission</term> means, with respect to any
			 Federal agency, the portion of the cybersecurity mission that is the
			 responsibility of the Federal agency.</text>
				</paragraph></section><section id="HE2CE352F5BFF411583F9FD926A6C68A3"><enum>402.</enum><header>Assessment of
			 cybersecurity workforce</header>
				<subsection id="H915A3336FAF2471EA0732C010057ADF2"><enum>(a)</enum><header>In
			 general</header><text>The Director of the Office of Personnel Management and
			 the Director shall assess the readiness and capacity of the Federal workforce
			 to meet the needs of the cybersecurity mission of the Federal
			 Government.</text>
				</subsection><subsection id="H782CEFF1928942679BCA9AFB55E56726"><enum>(b)</enum><header>Strategy</header>
					<paragraph id="HE710FA0153904F3188659A86D6ED1D57"><enum>(1)</enum><header>In
			 general</header><text>Not later than 180 days after the date of enactment of
			 this Act, the Director of the Office of Personnel Management shall develop and
			 implement a comprehensive workforce strategy that enhances the readiness,
			 capacity, training, and recruitment and retention of Federal cybersecurity
			 personnel.</text>
					</paragraph><paragraph id="HB99A4CA25EED43A4AF61BEACDA45890F"><enum>(2)</enum><header>Contents</header><text>The
			 strategy developed under paragraph (1) shall include—</text>
						<subparagraph id="H58336F63A2E84DFCAEFAE4A740EC4B7A"><enum>(A)</enum><text>a 5-year plan on
			 recruitment of personnel for the Federal workforce; and</text>
						</subparagraph><subparagraph id="H7F5A82B3CBF8402E9232FD06E4AAD982"><enum>(B)</enum><text>10-year and
			 20-year projections of workforce needs.</text>
						</subparagraph></paragraph></subsection></section><section id="H50EB2D37AB284BC897B4F1C804FB6CCC"><enum>403.</enum><header>Strategic
			 cybersecurity workforce planning</header>
				<subsection id="H56E60F666067416BABE1A006E0AA80A0"><enum>(a)</enum><header>Federal agency
			 development of strategic cybersecurity workforce plans</header><text>Not later
			 than 180 days after the date of enactment of this Act and in every subsequent
			 year, the head of each Federal agency shall develop a strategic cybersecurity
			 workforce plan as part of the Federal agency performance plan required under
			 section 1115 of title 31, United States Code.</text>
				</subsection><subsection id="H81C9CC16B1FA4DC591A8A36A7C0C17F5"><enum>(b)</enum><header>Interagency
			 coordination</header><text>Each Federal agency shall develop a plan prepared
			 under subsection (a)—</text>
					<paragraph id="HA920A8F4172445919210638C18AE3546"><enum>(1)</enum><text>on the basis of
			 the assessment developed under section 402 and any subsequent guidance from the
			 Director of the Office of Personnel Management and the Director; and</text>
					</paragraph><paragraph id="HA8BB84090D62489992EEC2E9C3641F0C"><enum>(2)</enum><text>in consultation
			 with the Director and the Director of the Office of Management and
			 Budget.</text>
					</paragraph></subsection><subsection id="H9A09DBBF27804B678CE972DEDC30B43A"><enum>(c)</enum><header>Contents of the
			 plan</header>
					<paragraph id="H2734E07EF23544DBADFF2F8C1550789D"><enum>(1)</enum><header>In
			 general</header><text>Each plan prepared under subsection (a) shall
			 include—</text>
						<subparagraph id="HEA45E5E0367D422DBDE7419997C7C913"><enum>(A)</enum><text>a description of
			 the Federal agency’s cybersecurity mission;</text>
						</subparagraph><subparagraph id="HF320B5E82F52451BBC7DCD0C900266A5"><enum>(B)</enum><text>subject to
			 paragraph (2), a description and analysis, relating to the specialized
			 workforce needed by the Federal agency to fulfill the Federal agency’s
			 cybersecurity mission, including—</text>
							<clause id="H3F278E37AD4543E9B8EA51967D1E57F5"><enum>(i)</enum><text>the
			 workforce needs of the Federal agency on the date of the report, and 10-year
			 and 20-year projections of workforce needs;</text>
							</clause><clause id="H96B6D7FEBB2B4DADA584BF748D4BD30F"><enum>(ii)</enum><text>hiring
			 projections to meet workforce needs, including, for at least a 2-year period,
			 specific occupation and grade levels;</text>
							</clause><clause id="H2FC56E0577A94F308ECF0173DDE5E764"><enum>(iii)</enum><text>long-term and
			 short-term strategic goals to address critical skills deficiencies, including
			 analysis of the numbers of and reasons for attrition of employees;</text>
							</clause><clause id="H0AD91A3040FF44E9ADEDA4205CA66C52"><enum>(iv)</enum><text>recruitment
			 strategies, including the use of student internships, part-time employment,
			 student loan reimbursement, and telework, to attract highly qualified
			 candidates from diverse backgrounds and geographic locations;</text>
							</clause><clause id="H9CB87CD79681440898A89A8CA4DDEBED"><enum>(v)</enum><text>an
			 assessment of the sources and availability of individuals with needed
			 expertise;</text>
							</clause><clause id="HE7AAE40903FE4AB19CDF8B4E26807F0D"><enum>(vi)</enum><text>ways to
			 streamline the hiring process;</text>
							</clause><clause id="H76914304288D4AF086751F28F223291C"><enum>(vii)</enum><text>the barriers to
			 recruiting and hiring individuals qualified in cybersecurity and
			 recommendations to overcome the barriers; and</text>
							</clause><clause id="H06631475EAE4468CB604C03EC2F4ABF7"><enum>(viii)</enum><text>a
			 training and development plan, consistent with the curriculum developed under
			 section 406, to enhance and improve the knowledge of employees.</text>
							</clause></subparagraph></paragraph><paragraph id="HC118D48F47614C2288E30C5468B62346"><enum>(2)</enum><header>Federal agencies
			 with small specialized workforce</header><text>In accordance with guidance
			 provided by the Director of the Office of Personnel Management, a Federal
			 agency that needs only a small specialized workforce to fulfill the Federal
			 agency’s cybersecurity mission may present the workforce plan components
			 referred to in paragraph (1)(B) as part of the Federal agency performance plan
			 required under section 1115 of title 31, United States Code.</text>
					</paragraph></subsection></section><section id="H33E56C792D1C447F8A7156C9E8737164"><enum>404.</enum><header>Cybersecurity
			 occupation classifications</header>
				<subsection id="H61F2A6B3061E47F6A7BACFFB49AA85F4"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, the Director of the Office of Personnel Management, in coordination with
			 the Director, shall develop and issue comprehensive occupation classifications
			 for Federal employees engaged in cybersecurity missions.</text>
				</subsection><subsection id="HA3E01FDB6AC14E4680506F0A1801FAF7"><enum>(b)</enum><header>Applicability of
			 classifications</header><text>The Director of the Office of Personnel
			 Management shall ensure that the comprehensive occupation classifications
			 issued under subsection (a) may be used throughout the Federal
			 Government.</text>
				</subsection></section><section id="H45ADCBF5990540D6AE1F277C30001BC8"><enum>405.</enum><header>Measures of
			 cybersecurity hiring effectiveness</header>
				<subsection id="H41779A21EF3146E2B7BF7BCE13829237"><enum>(a)</enum><header>In
			 general</header><text>The head of each Federal agency shall measure, and
			 collect information on, indicators of the effectiveness of the recruitment and
			 hiring by the Federal agency of a workforce needed to fulfill the Federal
			 agency’s cybersecurity mission.</text>
				</subsection><subsection id="H6C918A26055F4AFF924EA731BBE15BD2"><enum>(b)</enum><header>Types of
			 information</header><text>The indicators of effectiveness measured and subject
			 to collection of information under subsection (a) shall include indicators with
			 respect to the following:</text>
					<paragraph id="HD2EB95E5A38E442991BC10A557EBBC9A"><enum>(1)</enum><header>Recruiting and
			 hiring</header><text>In relation to recruiting and hiring by the Federal
			 agency—</text>
						<subparagraph id="HED47B99AF66A42A5BA87132521B6859C"><enum>(A)</enum><text>the ability to
			 reach and recruit well-qualified individuals from diverse talent pools;</text>
						</subparagraph><subparagraph id="H7ED37560ED914DA99030A4101C2F9E63"><enum>(B)</enum><text>the use and impact
			 of special hiring authorities and flexibilities to recruit the most qualified
			 applicants, including the use of student internship and scholarship programs
			 for permanent hires;</text>
						</subparagraph><subparagraph id="H06462B76D2BD46039957B2EFBE6FDDC5"><enum>(C)</enum><text>the use and impact
			 of special hiring authorities and flexibilities to recruit diverse candidates,
			 including criteria such as the veteran status, race, ethnicity, gender,
			 disability, or national origin of the candidates; and</text>
						</subparagraph><subparagraph id="HA75AA1D1725B40B58F92358510003BA3"><enum>(D)</enum><text>the educational
			 level, and source of applicants.</text>
						</subparagraph></paragraph><paragraph id="HDFABBF33AB7C4D58B5FA5467CA0CA060"><enum>(2)</enum><header>Supervisors</header><text>In
			 relation to the supervisors of the positions being filled—</text>
						<subparagraph id="H903B7A69CF344CBF99237C7CC21D87E7"><enum>(A)</enum><text>satisfaction with
			 the quality of the applicants interviewed and hired;</text>
						</subparagraph><subparagraph id="H09723D126EE142C5837FCFC5FFF6A745"><enum>(B)</enum><text>satisfaction with
			 the match between the skills of the individuals and the needs of the Federal
			 agency;</text>
						</subparagraph><subparagraph id="HABC739A64183492C9EC8044A6EF30970"><enum>(C)</enum><text>satisfaction of
			 the supervisors with the hiring process and hiring outcomes;</text>
						</subparagraph><subparagraph id="H833EDAA3BC9E44C9B612D1229F27E04E"><enum>(D)</enum><text>whether any
			 mission-critical deficiencies were addressed by the individuals and the
			 connection between the deficiencies and the performance of the Federal agency;
			 and</text>
						</subparagraph><subparagraph id="H0364C37BBAB94FD699B73D140F9735DE"><enum>(E)</enum><text>the satisfaction
			 of the supervisors with the period of time elapsed to fill the
			 positions.</text>
						</subparagraph></paragraph><paragraph id="HD50A4F6347854BC1BDE1DB59C4CD5EA5"><enum>(3)</enum><header>Applicants</header><text>The
			 satisfaction of applicants with the hiring process, including clarity of job
			 announcements, any reasons for withdrawal of an application, the
			 user-friendliness of the application process, communication regarding status of
			 applications, and the timeliness of offers of employment.</text>
					</paragraph><paragraph id="HFAA45587AEDD4592922E994FF7CD6059"><enum>(4)</enum><header>Hired
			 individuals</header><text>In relation to the individuals hired—</text>
						<subparagraph id="HBBBF569006304A34A92B7C622B84A4AC"><enum>(A)</enum><text>satisfaction with
			 the hiring process;</text>
						</subparagraph><subparagraph id="H8D4E91B0BA9B4243BEFE780E106CB0B2"><enum>(B)</enum><text>satisfaction with
			 the process of starting employment in the position for which the individual was
			 hired;</text>
						</subparagraph><subparagraph id="HEE47088B5F7C4FDD94D54C0230350924"><enum>(C)</enum><text>attrition;
			 and</text>
						</subparagraph><subparagraph id="HD9257089A7784C85A4DF5B2695C09BA0"><enum>(D)</enum><text>the results of
			 exit interviews.</text>
						</subparagraph></paragraph></subsection><subsection id="H5DD489E59957439BACFEA407813ADACD"><enum>(c)</enum><header>Reports</header>
					<paragraph id="HAB6759A3333E4392B5EDFDA6AC9A7B5C"><enum>(1)</enum><header>In
			 general</header><text>The head of each Federal agency shall submit the
			 information collected under this section to the Director of the Office of
			 Personnel Management on an annual basis and in accordance with the regulations
			 issued under subsection (d).</text>
					</paragraph><paragraph id="H69FFF78D85F446DFBF15078D3F5BC55F"><enum>(2)</enum><header>Availability of
			 recruiting and hiring information</header>
						<subparagraph id="HE0C7F9B56B774B48ACDB19D50E6D9CED"><enum>(A)</enum><header>In
			 general</header><text>The Director of the Office of Personnel Management shall
			 prepare an annual report containing the information received under paragraph
			 (1) in a consistent format to allow for a comparison of hiring effectiveness
			 and experience across demographic groups and Federal agencies.</text>
						</subparagraph><subparagraph id="H1975A67883EC4FDCB0DAAA25BD11119A"><enum>(B)</enum><header>Submission</header><text>The
			 Director of the Office of Personnel Management shall—</text>
							<clause id="H1B7AC80452354EB6B63707995ABBD280"><enum>(i)</enum><text>not
			 later than 90 days after the receipt of all information required to be
			 submitted under paragraph (1), make the report prepared under subparagraph (A)
			 publicly available, including on the Web site of the Office of Personnel
			 Management; and</text>
							</clause><clause id="H664D270D0D5F44ECAD60A2383445F435"><enum>(ii)</enum><text>before the date
			 on which the report prepared under subparagraph (A) is made publicly available,
			 submit the report to Congress.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="H67C1A13A0F5A495C95AE915A96395EC4"><enum>(d)</enum><header>Regulations</header>
					<paragraph id="H4BBAA00A427C48DAB5C637ECE9B897D3"><enum>(1)</enum><header>In
			 general</header><text>Not later than 180 days after the date of enactment of
			 this Act, the Director of the Office of Personnel Management shall issue
			 regulations establishing the methodology, timing, and reporting of the data
			 required to be submitted under this section.</text>
					</paragraph><paragraph id="H6D2D410327AC470E958A67C039529649"><enum>(2)</enum><header>Scope and detail
			 of required information</header><text>The regulations under paragraph (1) shall
			 delimit the scope and detail of the information that a Federal agency is
			 required to collect and submit under this section, taking account of the size
			 and complexity of the workforce that the Federal agency needs to fulfill the
			 Federal agency’s cybersecurity mission.</text>
					</paragraph></subsection></section><section id="HAD6BAC56375042ABAAF6D236D2AAFFBA"><enum>406.</enum><header>Training and
			 education</header>
				<subsection id="H76F695383D994B5295FFEEE39ED8A0C8"><enum>(a)</enum><header>Training</header>
					<paragraph id="HFCA25F9F443D4EEFBDF00ADC8703EA25"><enum>(1)</enum><header>Federal
			 Government employees and Federal contractors</header><text>The Director of the
			 Office of Personnel Management, in conjunction with the Director of the
			 National Center for Cybersecurity and Communications, the Director of National
			 Intelligence, the Secretary of Defense, and the Chief Information Officers
			 Council established under section 3603 of title 44, United States Code, shall
			 establish a cybersecurity awareness and education curriculum that shall be
			 required for all Federal employees and contractors engaged in the design,
			 development, or operation of agency information infrastructure, as defined
			 under section 3551 of title 44, United States Code.</text>
					</paragraph><paragraph id="H35C7BAD822694DA5BE033AC2FCB8C810"><enum>(2)</enum><header>Contents</header><text>The
			 curriculum established under paragraph (1) may include—</text>
						<subparagraph id="H78FEE2525C454C4C9FD3CA1CB135151D"><enum>(A)</enum><text>role-based
			 security awareness training;</text>
						</subparagraph><subparagraph id="HE06EDF7D257B4946926F34F777FEC5C1"><enum>(B)</enum><text>recommended
			 cybersecurity practices;</text>
						</subparagraph><subparagraph id="H06B2DA8FB87C45ECA7D1B1C03E10FF10"><enum>(C)</enum><text>cybersecurity
			 recommendations for traveling abroad;</text>
						</subparagraph><subparagraph id="HC1286BA2490F43BC9BAD8CCA37424BF2"><enum>(D)</enum><text>unclassified
			 counterintelligence information;</text>
						</subparagraph><subparagraph id="HD8E8764E052B4095822DBA04324047A9"><enum>(E)</enum><text>information
			 regarding industrial espionage;</text>
						</subparagraph><subparagraph id="HF6A23570C6DC4DE8AC88DD29C976A746"><enum>(F)</enum><text>information
			 regarding malicious activity online;</text>
						</subparagraph><subparagraph id="HA2976D0A72E141C6AF67F101C2BC58A2"><enum>(G)</enum><text>information
			 regarding cybersecurity and law enforcement;</text>
						</subparagraph><subparagraph id="H05720A5373384978AAE6E57C31E57183"><enum>(H)</enum><text>identity
			 management information;</text>
						</subparagraph><subparagraph id="H3A4B24D6D1A6401EA164E11D2C74FCA2"><enum>(I)</enum><text>information
			 regarding supply chain security;</text>
						</subparagraph><subparagraph id="H52B18B1EFBF1405ABC28FA5CD8B448D1"><enum>(J)</enum><text>information
			 security risks associated with the activities of Federal employees; and</text>
						</subparagraph><subparagraph id="HB4A1C1FEFC354E7D9A031735D67AEFCA"><enum>(K)</enum><text>the
			 responsibilities of Federal employees in complying with policies and procedures
			 designed to reduce information security risks identified under subparagraph
			 (J).</text>
						</subparagraph></paragraph><paragraph id="H9BAF45BCE5B9446691416FB0548CDA20"><enum>(3)</enum><header>Federal
			 cybersecurity professionals</header><text>The Director of the Office of
			 Personnel Management in conjunction with the Director of the National Center
			 for Cybersecurity and Communications, the Director of National Intelligence,
			 the Secretary of Defense, the Director of the Office of Management and Budget,
			 and, as appropriate, colleges, universities, and nonprofit organizations with
			 cybersecurity training expertise, shall develop a program, to provide training
			 to improve and enhance the skills and capabilities of Federal employees engaged
			 in the cybersecurity mission, including training specific to the acquisition
			 workforce.</text>
					</paragraph><paragraph id="HBE7A70E659AF40C196ADE5E49D77DC3D"><enum>(4)</enum><header>Heads of Federal
			 agencies</header><text>Not later than 30 days after the date on which an
			 individual is appointed to a position at level I or II of the Executive
			 Schedule, the Director of the National Center for Cybersecurity and
			 Communications and the Director of National Intelligence, or their designees,
			 shall provide that individual with a cybersecurity threat briefing.</text>
					</paragraph><paragraph id="HDAECBD392EE84C4DBAC629E7C7693482"><enum>(5)</enum><header>Certification</header><text>The
			 head of each Federal agency shall include in the annual report required under
			 section 3553(c) of title 44, United States Code, a certification regarding
			 whether all officers, employees, and contractors of the Federal agency have
			 completed the training required under this subsection.</text>
					</paragraph></subsection><subsection id="H62D715FBC3CD416ABBC8E104326FFA08"><enum>(b)</enum><header>Education</header>
					<paragraph id="HFA26285AD3DC4B38898EF670C96E01A9"><enum>(1)</enum><header>Federal
			 employees</header><text>The Director of the Office of Personnel Management, in
			 coordination with the Secretary of Education, the Director of the National
			 Science Foundation, and the Director, shall develop and implement a strategy to
			 provide Federal employees who work in cybersecurity missions with the
			 opportunity to obtain additional education.</text>
					</paragraph><paragraph id="H5C05B5F6AB884E02B5E9E4BC7081F7CE"><enum>(2)</enum><header>K through
			 12</header><text>The Secretary of Education, in coordination with the Director
			 of the National Center for Cybersecurity and Communications and State and local
			 governments, shall develop curriculum standards, guidelines, and recommended
			 courses to address cyber safety, cybersecurity, and cyber ethics for students
			 in kindergarten through grade 12.</text>
					</paragraph><paragraph id="H46F656914C144CC8B60937F938ECFFEC"><enum>(3)</enum><header>Undergraduate,
			 graduate, vocational, and technical institutions</header>
						<subparagraph id="HAA2B8572E8694B389383BE3CEBF0E9C9"><enum>(A)</enum><header>Secretary of
			 education</header><text>The Secretary of Education, in coordination with the
			 Director of the National Center for Cybersecurity and Communications,
			 shall—</text>
							<clause id="HE2055722295E463F8B2B2AAA63DB389A"><enum>(i)</enum><text>develop curriculum
			 standards and guidelines to address cyber safety, cybersecurity, and cyber
			 ethics for all students enrolled in undergraduate, graduate, vocational, and
			 technical institutions in the United States; and</text>
							</clause><clause id="HE1317BFB1F004EF8ABDDFC78C70985E1"><enum>(ii)</enum><text>analyze and
			 develop recommended courses for students interested in pursuing careers in
			 information technology, communications, computer science, engineering, math,
			 and science, as those subjects relate to cybersecurity.</text>
							</clause></subparagraph><subparagraph id="HD58A4999ABBF4496BC330B98B6BCA218"><enum>(B)</enum><header>Office of
			 personnel management</header><text>The Director of the Office of Personnel
			 Management, in coordination with the Director, shall develop strategies and
			 programs—</text>
							<clause id="H66672B3B4DA549BF88BE2FCB05A138A2"><enum>(i)</enum><text>to
			 recruit students from undergraduate, graduate, vocational, and technical
			 institutions in the United States to serve as Federal employees engaged in
			 cyber missions; and</text>
							</clause><clause id="H553ADE091C0A4B88A7FAE0D3F07D13AC"><enum>(ii)</enum><text>that provide
			 internship and part-time work opportunities with the Federal Government for
			 students at the undergraduate, graduate, vocational, and technical institutions
			 in the United States.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="H28AFFE70AB5D4D00929D07FC7C5FAC7C"><enum>(c)</enum><header>Cyber talent
			 competitions and challenges</header>
					<paragraph id="H8EFC4104B25F4AEBB9007EB743021513"><enum>(1)</enum><header>In
			 general</header><text>The Director of the National Center for Cybersecurity and
			 Communications shall establish a program to ensure the effective operation of
			 national and statewide competitions and challenges that seek to identify,
			 develop, and recruit talented individuals to work in Federal agencies, State
			 and local government agencies, and the private sector to perform duties
			 relating to the security of the Federal information infrastructure or the
			 national information infrastructure.</text>
					</paragraph><paragraph id="H0A0132C37F354D1AA85E66BD289AE725"><enum>(2)</enum><header>Groups and
			 individuals</header><text>The program under this subsection shall
			 include—</text>
						<subparagraph id="HF6449C77BD3C4156BA22C764BD17998A"><enum>(A)</enum><text>high school
			 students;</text>
						</subparagraph><subparagraph id="H3FF3B765D1AF49D683C044BCD2098908"><enum>(B)</enum><text>undergraduate
			 students;</text>
						</subparagraph><subparagraph id="H3F036010CA924338A5D75D0762AB353C"><enum>(C)</enum><text>graduate
			 students;</text>
						</subparagraph><subparagraph id="H15AA3C43F4C74423B660BA5309CED077"><enum>(D)</enum><text>academic and
			 research institutions;</text>
						</subparagraph><subparagraph id="H99E10DB20C88417E8E6F740819BECA83"><enum>(E)</enum><text>veterans;
			 and</text>
						</subparagraph><subparagraph id="HC6B0D81F0B85465AA77754F7E77448F8"><enum>(F)</enum><text>other groups or
			 individuals as the Director may determine.</text>
						</subparagraph></paragraph><paragraph id="HA62792136F36416487D04C4E51F248AF"><enum>(3)</enum><header>Support of other
			 competitions and challenges</header><text>The program under this subsection may
			 support other competitions and challenges not established under this subsection
			 through affiliation and cooperative agreements with—</text>
						<subparagraph id="HEC4A9673ED7447EDB75BCADCF7EC751B"><enum>(A)</enum><text>Federal
			 agencies;</text>
						</subparagraph><subparagraph id="HD996CF28415048F48E19C7792DBF70A8"><enum>(B)</enum><text>regional, State,
			 or community school programs supporting the development of cyber professionals;
			 or</text>
						</subparagraph><subparagraph id="H18AECEA8508B41119C5899299D46BD4C"><enum>(C)</enum><text>other private
			 sector organizations.</text>
						</subparagraph></paragraph><paragraph id="H3271FC5935C64FD29D00CF1C09DFB750"><enum>(4)</enum><header>Areas of
			 talent</header><text>The program under this subsection shall seek to identify,
			 develop, and recruit exceptional talent relating to—</text>
						<subparagraph id="HEB9F946BA5874F71A3B46CAD14ECFF19"><enum>(A)</enum><text>ethical
			 hacking;</text>
						</subparagraph><subparagraph id="HD7CB56B2C1FC4DBBB25B0E6000FB0901"><enum>(B)</enum><text>penetration
			 testing;</text>
						</subparagraph><subparagraph id="H67F370B993534C92A533962692821DFF"><enum>(C)</enum><text>vulnerability
			 assessment;</text>
						</subparagraph><subparagraph id="H6252D3F678AF4FC6A247784649A73E3C"><enum>(D)</enum><text>continuity of
			 system operations;</text>
						</subparagraph><subparagraph id="H0F9C031BCB114F198BE2ACFEE04C87C5"><enum>(E)</enum><text>cyber forensics;
			 and</text>
						</subparagraph><subparagraph id="H0D7CB4BA0059484BBB6DD039740DD4CF"><enum>(F)</enum><text>offensive and
			 defensive cyber operations.</text>
						</subparagraph></paragraph></subsection></section><section id="HF5B3F2B1703645259FD37282905B4C90"><enum>407.</enum><header>Cybersecurity
			 incentives</header>
				<subsection id="H589A3C37BBEC4259AE1DF3DC249F84F4"><enum>(a)</enum><header>Awards</header><text>In
			 making cash awards under chapter 45 of title 5, United States Code, the
			 President or the head of a Federal agency, in consultation with the Director,
			 shall consider the success of an employee in fulfilling the objectives of the
			 National Strategy, in a manner consistent with any policies, guidelines,
			 procedures, instructions, or standards established by the President.</text>
				</subsection><subsection id="H7033461007C048AEAD6B0508A257D84C"><enum>(b)</enum><header>Other
			 incentives</header><text>The head of each Federal agency shall adopt best
			 practices, developed by the Director of the National Center for Cybersecurity
			 and Communications and the Office of Management and Budget, regarding effective
			 ways to educate and motivate employees of the Federal Government to demonstrate
			 leadership in cybersecurity, including—</text>
					<paragraph id="HFA64F7D362EE4E41BAF41016D92EC910"><enum>(1)</enum><text>promotions and
			 other nonmonetary awards; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="H0DE0D72C61D64ABC9B932C5FAD1C2D0D"><enum>(2)</enum><text>publicizing
			 information sharing accomplishments by individual employees and, if
			 appropriate, the tangible benefits that resulted.</text>
					</paragraph></subsection></section><section id="H7B1F29F271574420B16AF28C29927744"><enum>408.</enum><header>Recruitment and
			 retention program for the National Center for Cybersecurity and
			 Communications</header>
				<subsection id="H2C81108161B94F65B5092D1C45014D26"><enum>(a)</enum><header>Definitions</header><text>In
			 this section:</text>
					<paragraph id="H830236E35D5343D09E870931ED5E6462"><enum>(1)</enum><header>Center</header><text>The
			 term <term>Center</term> means the National Center for Cybersecurity and
			 Communications.</text>
					</paragraph><paragraph id="H594822EFED94457A9F53DA529C12F0DB"><enum>(2)</enum><header>Department</header><text>The
			 term <term>Department</term> means the Department of Homeland Security.</text>
					</paragraph><paragraph id="HFC017F64C5FA44B99607D3A2D8BC408D"><enum>(3)</enum><header>Director</header><text>The
			 term <term>Director</term> means the Director of the Center.</text>
					</paragraph><paragraph id="HE5B02CD0F6E34BA9BB70883A6622E737"><enum>(4)</enum><header>Entry level
			 position</header><text>The term <term>entry level position</term> means a
			 position that—</text>
						<subparagraph id="H778CD3DE8F9E49C09894594E41BF1C68"><enum>(A)</enum><text>is established by
			 the Director in the Center; and</text>
						</subparagraph><subparagraph id="HE1BE2490E39A43139424D7DC8DEBEE61"><enum>(B)</enum><text>is classified at
			 GS–7, GS–8, or GS–9 of the General Schedule.</text>
						</subparagraph></paragraph><paragraph id="HB3C666E660DB450883CCAB997CDB86FA"><enum>(5)</enum><header>Secretary</header><text>The
			 term <term>Secretary</term> means the Secretary of Homeland Security.</text>
					</paragraph><paragraph id="HF352A10DF276485EBDF3766D863FE7CA"><enum>(6)</enum><header>Senior
			 position</header><text>The term <term>senior position</term> means a position
			 that—</text>
						<subparagraph id="H1629F259C761432DAC084CC78626FD6C"><enum>(A)</enum><text>is established by
			 the Director in the Center; and</text>
						</subparagraph><subparagraph id="HD9397C6ECD0F4A0FA6D96536241DBBED"><enum>(B)</enum><text>is not established
			 under section 5108 of title 5, United States Code, but is similar in duties and
			 responsibilities for positions established under that section.</text>
						</subparagraph></paragraph></subsection><subsection id="H7E0DC09C9D6B4983B8EB2655C9DF5E5B"><enum>(b)</enum><header>Recruitment and
			 retention program</header>
					<paragraph id="H195AA554494A4E5B895B93F420422739"><enum>(1)</enum><header>Establishment</header><text>The
			 Director may establish a program to assist in the recruitment and retention of
			 highly skilled personnel to carry out the functions of the Center.</text>
					</paragraph><paragraph id="H5293BBD66891440CBD11C637B706486A"><enum>(2)</enum><header>Consultation and
			 considerations</header><text>In establishing a program under this section, the
			 Director shall—</text>
						<subparagraph id="H7ED0E7DE43BE47528A014FE14F9F6C5E"><enum>(A)</enum><text>consult with the
			 Secretary; and</text>
						</subparagraph><subparagraph id="HFBF37193A8E6430E8EBD2BE68C490B16"><enum>(B)</enum><text>consider—</text>
							<clause id="H8E3A71F027664B7496AE3944B7D50B9F"><enum>(i)</enum><text>national and local
			 employment trends;</text>
							</clause><clause id="HA7D7C9E49AC34C3D97E42859359E987E"><enum>(ii)</enum><text>the
			 availability and quality of candidates;</text>
							</clause><clause id="HFE7AA70E54564214A93807C6564C178E"><enum>(iii)</enum><text>any specialized
			 education or certifications required for positions;</text>
							</clause><clause id="H47E5D88C68EC42E89D18365EEBA13377"><enum>(iv)</enum><text>whether there is
			 a shortage of certain skills; and</text>
							</clause><clause id="H182C4F9C05F14D9F8D9B6C56E935A6CF"><enum>(v)</enum><text>such
			 other factors as the Director determines appropriate.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="H51D6D419666E4866ADDD1A2F8914E55D"><enum>(c)</enum><header>Hiring and
			 special pay authorities</header>
					<paragraph id="H1C4BC152F8FD40AFAA0C38E274DFFAE2"><enum>(1)</enum><header>Direct hire
			 authority</header><text>Without regard to the civil service laws (other than
			 sections 3303 and 3328 of title 5, United States Code), the Director may
			 appoint not more than 500 employees under this subsection to carry out the
			 functions of the Center.</text>
					</paragraph><paragraph id="HD0B06DE4CB4D4AA294F635958B863FD6"><enum>(2)</enum><header>Rates of
			 pay</header>
						<subparagraph id="H6F3833FA90984AF8AFFF1478A9918E06"><enum>(A)</enum><header>Entry level
			 positions</header><text>The Director may fix the pay of the employees appointed
			 to entry level positions under this subsection without regard to chapter 51 and
			 subchapter III of chapter 53 of title 5, United States Code, relating to
			 classification of positions and General Schedule pay rates, except that the
			 rate of pay for any such employee may not exceed the maximum rate of basic pay
			 payable for a position at GS–10 of the General Schedule while that employee is
			 in an entry level position.</text>
						</subparagraph><subparagraph id="H976E961C0AD94C629B7E2D7DCD1DC9A5"><enum>(B)</enum><header>Senior
			 positions</header>
							<clause id="HB760BEBE0A3F40D797CFA9E6F5DB5785"><enum>(i)</enum><header>In
			 general</header><text>The Director may fix the pay of the employees appointed
			 to senior positions under this subsection without regard to chapter 51 and
			 subchapter III of chapter 53 of title 5, United States Code, relating to
			 classification of positions and General Schedule pay rates, except that the
			 rate of pay for any such employee may not exceed the maximum rate of basic pay
			 payable under section 5376 of title 5, United States Code.</text>
							</clause><clause id="HF4E467DDB0DD42639B88C44BDAE90734"><enum>(ii)</enum><header>Higher maximum
			 rates</header>
								<subclause id="HF12C3E31CC67413BB6B4340C18A5A313"><enum>(I)</enum><header>In
			 general</header><text>Notwithstanding the limitation on rates of pay under
			 clause (i)—</text>
									<item id="H259DB0583E144F40809F943151B7C50C"><enum>(aa)</enum><text>not
			 more than 20 employees, identified by the Director, may be paid at a rate of
			 pay not to exceed the maximum rate of basic pay payable for a position at level
			 I of the Executive Schedule under section 5312 of title 5, United States Code;
			 and</text>
									</item><item id="H85B9177462B44403A9A7F342356BD8FA"><enum>(bb)</enum><text>not
			 more than 5 employees, identified by the Director with the approval of the
			 Secretary, may be paid at a rate of pay not to exceed the maximum rate of basic
			 pay payable for the Vice President under section 104 of title 3, United States
			 Code.</text>
									</item></subclause><subclause id="H32F33D62B54D48568DD48FA52F122351"><enum>(II)</enum><header>Nondelegation
			 of authority</header><text>The Secretary or the Director may not delegate any
			 authority under this clause.</text>
								</subclause></clause></subparagraph></paragraph></subsection><subsection id="H2310DAD8DAD84B5D825FCDFB8A942260"><enum>(d)</enum><header>Conversion to
			 Competitive Service</header>
					<paragraph id="H3F99172D3B0E45C8AE31D8B7F3C54310"><enum>(1)</enum><header>Definition</header><text>In
			 this subsection, the term <term>qualified employee</term> means any individual
			 appointed to an excepted service position in the Department who performs
			 functions relating to the security of the Federal information infrastructure or
			 national information infrastructure.</text>
					</paragraph><paragraph id="H720A96FE0C2E4DDFB3F10A347226B854"><enum>(2)</enum><header>Competitive
			 civil service status</header><text>In consultation with the Director, the
			 Secretary may grant competitive civil service status to a qualified employee if
			 that employee is—</text>
						<subparagraph id="H97CC90202DBA4F5D879813908C7B1B2E"><enum>(A)</enum><text>employed in the
			 Center; or</text>
						</subparagraph><subparagraph id="HDEFE02CD84E34839BFB07E46B37E451D"><enum>(B)</enum><text>transferring to
			 the Center.</text>
						</subparagraph></paragraph></subsection><subsection id="H114CD428B7EB45E2866F11751552F683"><enum>(e)</enum><header>Retention
			 Bonuses</header>
					<paragraph id="H6340045829CE4544AB37D1B018CDCAC6"><enum>(1)</enum><header>Authority</header><text>Notwithstanding
			 section 5754 of title 5, United States Code, the Director may—</text>
						<subparagraph id="H439BEFBD228041AC9520C46E20E6D7D7"><enum>(A)</enum><text>pay a retention
			 bonus under that section to any individual appointed under this subsection, if
			 the Director determines that, in the absence of a retention bonus, there is a
			 high risk that the individual would likely leave employment with the
			 Department; and</text>
						</subparagraph><subparagraph id="HE8CAD0229BCC4836B975ECF5506401EE"><enum>(B)</enum><text>exercise the
			 authorities of the Office of Personnel Management and the head of an agency
			 under that section with respect to retention bonuses paid under this
			 subsection.</text>
						</subparagraph></paragraph><paragraph id="H4521CD9B21E24467B20008DE83D3CAA5"><enum>(2)</enum><header>Limitations on
			 amount of annual bonuses</header>
						<subparagraph id="H058820D265D748A5823D9B8D269E0D06"><enum>(A)</enum><header>Definitions</header><text>In
			 this paragraph:</text>
							<clause id="H6500F617BAB7471FBCFD077E6783D5B5"><enum>(i)</enum><header>Maximum total
			 pay</header><text>The term <term>maximum total pay</term> means—</text>
								<subclause id="H34A53A29EDCE4BCE8F0AC66D71A7BE65"><enum>(I)</enum><text>in the case of an
			 employee described under subsection (c)(2)(B)(i), the total amount of pay paid
			 in a calendar year at the maximum rate of basic pay payable for a position at
			 level I of the Executive Schedule under section 5312 of title 5, United States
			 Code;</text>
								</subclause><subclause id="H3C8C2FD607314A00B6F6CBB7A8A19648"><enum>(II)</enum><text>in the case of an
			 employee described under subsection (c)(2)(B)(ii)(I)(aa), the total amount of
			 pay paid in a calendar year at the maximum rate of basic pay payable for a
			 position at level I of the Executive Schedule under section 5312 of title 5,
			 United States Code; and</text>
								</subclause><subclause id="H15ED9F2845F94191980A758474589B69"><enum>(III)</enum><text>in the case of
			 an employee described under subsection (c)(2)(B)(ii)(I)(bb), the total amount
			 of pay paid in a calendar year at the maximum rate of basic pay payable for the
			 Vice President under section 104 of title 3, United States Code.</text>
								</subclause></clause><clause id="HB7834C27A38A4A4793EB1D803F1984A1"><enum>(ii)</enum><header>Total
			 compensation</header><text>The term <term>total compensation</term>
			 means—</text>
								<subclause id="H5E7B4C4D8BEC41B3875AFA3A075498B5"><enum>(I)</enum><text>the amount of pay
			 paid to an employee in any calendar year; and</text>
								</subclause><subclause id="H790673001B0A42F4ABF6D6B1666816D9"><enum>(II)</enum><text>the amount of all
			 retention bonuses paid to an employee in any calendar year.</text>
								</subclause></clause></subparagraph><subparagraph id="HB0F33B97E32949BDAC0EB02D2571A972"><enum>(B)</enum><header>Limitation</header><text>The
			 Director may not pay a retention bonus under this subsection to an employee
			 that would result in the total compensation of that employee exceeding maximum
			 total pay.</text>
						</subparagraph></paragraph></subsection><subsection id="HB0CF4398FE354C778C9C05311ECC18E9"><enum>(f)</enum><header>Termination of
			 Authority</header><text>The authority to make appointments and pay retention
			 bonuses under this section shall terminate 3 years after the date of enactment
			 of this Act.</text>
				</subsection><subsection id="H6F3FF94BB074415BAFA35B264A1E3DFD"><enum>(g)</enum><header>Reports</header>
					<paragraph id="H1320B4359DB749908110E26AE7A6961F"><enum>(1)</enum><header>Plan for
			 execution of authorities</header><text>Not later than 120 days of enactment of
			 this Act, the Director shall submit a report to the appropriate committees of
			 Congress with a plan for the execution of the authorities provided under this
			 section.</text>
					</paragraph><paragraph id="HEB86DB2FE25A44E8A07538718AB5BF26"><enum>(2)</enum><header>Annual
			 report</header><text>Not later than 6 months after the date of enactment of
			 this Act, and every year thereafter, the Director shall submit to the
			 appropriate committees of Congress a detailed report that—</text>
						<subparagraph id="HBAA1E672C1DC4D7EB17268BA6C932DBD"><enum>(A)</enum><text>discusses how the
			 actions taken during the period of the report are fulfilling the critical
			 hiring needs of the Center;</text>
						</subparagraph><subparagraph id="HDE0DADFBC81A4FF8A6AC34C9DC8FABA8"><enum>(B)</enum><text>assesses metrics
			 relating to individuals hired under the authority of this section,
			 including—</text>
							<clause id="H9297929970FA4827A2DC58F1F589ADCA"><enum>(i)</enum><text>the
			 numbers of individuals hired;</text>
							</clause><clause id="H119D8B8EA1F2424B94D19A7F940BA363"><enum>(ii)</enum><text>the
			 turnover in relevant positions;</text>
							</clause><clause id="HEE5134BEAA484A2CAC116DB30ADB3C0A"><enum>(iii)</enum><text>with respect to
			 each individual hired—</text>
								<subclause id="H91DCA93F61BF44B9834E52D3AE3FA05E"><enum>(I)</enum><text>the position for
			 which hired;</text>
								</subclause><subclause id="H71EAED6B28D444AB87E43665A95DD6A0"><enum>(II)</enum><text>the salary
			 paid;</text>
								</subclause><subclause id="HCA89144EA8AB4A1ABF9905751ED4807F"><enum>(III)</enum><text>any retention
			 bonus paid and the amount of the bonus;</text>
								</subclause><subclause id="H1B9117E9EC9844D490B26332EE1AA4B5"><enum>(IV)</enum><text>the geographic
			 location from which hired;</text>
								</subclause><subclause id="H2161375EB47F4B79A3C55D9E120ADD72"><enum>(V)</enum><text>the immediate past
			 salary; and</text>
								</subclause><subclause id="HDB3F8FCB3AE24A7CA5C64A532CDB65B9"><enum>(VI)</enum><text>whether the
			 individual was a noncareer appointee in the Senior Executive Service or an
			 appointee to a position of a confidential or policy-determining character under
			 schedule C of subpart C of part 213 of title 5 of the Code of Federal
			 Regulations before the hiring; and</text>
								</subclause></clause><clause id="H29A3D729B87B4C6E98203784765E86BB"><enum>(iv)</enum><text>whether public
			 notice for recruitment was made, and if so—</text>
								<subclause id="H777C3AB8306644F082314E618342A0F4"><enum>(I)</enum><text>the total number
			 of qualified applicants;</text>
								</subclause><subclause id="H8F84C04059154C1A98C7F07EC4735B12"><enum>(II)</enum><text>the number of
			 veteran preference eligible candidates who applied;</text>
								</subclause><subclause id="H795B1FEA139F4E05A65E1084998D8219"><enum>(III)</enum><text>the time from
			 posting to job offer; and</text>
								</subclause><subclause id="HBB23698BE3EA4789A6B4D3B10D38AEFF"><enum>(IV)</enum><text>statistics on
			 diversity, including age, disability, race, gender, and national origin, of
			 individuals hired under the authority of this section to the extent such
			 statistics are available; and</text>
								</subclause></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="HF429A3C633C9436DB5D1B78933B61940"><enum>(C)</enum><text>includes rates of
			 pay set in accordance with subsection (c).</text>
						</subparagraph></paragraph></subsection></section></title><title id="H8FE1AF45D0A44625B7092FB2A2178235"><enum>V</enum><header>Other
			 provisions</header>
			<section id="HE433FB8EC5F548DCBE0F6AC9FA0CF4BA"><enum>501.</enum><header>Consultation on
			 cybersecurity matters</header><text display-inline="no-display-inline">The
			 Chairman of the Federal Trade Commission, the Chairman of the Federal
			 Communications Commission, and the head of any other Federal agency determined
			 appropriate by the President shall consult with the Director of the National
			 Center for Cybersecurity and Communications regarding any regulation, rule, or
			 requirement to be issued or other action to be required by the Federal agency
			 relating to the security and resiliency of the national information
			 infrastructure.</text>
			</section><section id="H5D2AA97A464E4BB496DA2BB10A878C13"><enum>502.</enum><header>Cybersecurity
			 research and development</header><text display-inline="no-display-inline">Subtitle D of title II of the Homeland
			 Security Act of 2002 (6 U.S.C. 161 et seq.) is amended by adding at the end the
			 following:</text>
				<quoted-block display-inline="no-display-inline" id="H84151D59A971418DA3B74AF97E588C81" style="OLC">
					<section id="H6982DC463EEC4FD1ACEAADC24D603656"><enum>238.</enum><header>Cybersecurity
				research and development</header>
						<subsection id="HEB16D1CECC53413290B3BB61DC0E114A"><enum>(a)</enum><header>Establishment of
				research and development program</header><text>The Under Secretary for Science
				and Technology, in coordination with the Director of the National Center for
				Cybersecurity and Communications, shall carry out a research and development
				program for the purpose of improving the security of information
				infrastructure.</text>
						</subsection><subsection id="HF935A1EF59594E488CA240500863A9A5"><enum>(b)</enum><header>Eligible
				projects</header><text>The research and development program carried out under
				subsection (a) may include projects to—</text>
							<paragraph id="H2C4C41B334754B199771279A34B4EFBC"><enum>(1)</enum><text>advance the
				development and accelerate the deployment of more secure versions of
				fundamental Internet protocols and architectures, including for the secure
				domain name addressing system and routing security;</text>
							</paragraph><paragraph id="H5ECD477834914A0D84C82669A2F2FDD0"><enum>(2)</enum><text>improve and create
				technologies for detecting and analyzing attacks or intrusions, including
				analysis of malicious software;</text>
							</paragraph><paragraph id="HC0877145C0B74FD08560D58829F3FDED"><enum>(3)</enum><text>improve and create
				mitigation and recovery methodologies, including techniques for containment of
				attacks and development of resilient networks and systems;</text>
							</paragraph><paragraph id="H14E439CCE3574DD39F69CC42B5177F58"><enum>(4)</enum><text>develop and
				support infrastructure and tools to support cybersecurity research and
				development efforts, including modeling, testbeds, and data sets for assessment
				of new cybersecurity technologies;</text>
							</paragraph><paragraph id="HEB6C9ED1A2E349ED855578C30BA9E03A"><enum>(5)</enum><text>assist the
				development and support of technologies to reduce vulnerabilities in process
				control systems;</text>
							</paragraph><paragraph id="H66A5A6435218453DA3411F7B47FA26CE"><enum>(6)</enum><text>understand human
				behavioral factors that can affect cybersecurity technology and
				practices;</text>
							</paragraph><paragraph id="H9FA90B2B31A547E88E0959429B39AF7B"><enum>(7)</enum><text>test, evaluate,
				and facilitate, with appropriate protections for any proprietary information
				concerning the technologies, the transfer of technologies associated with the
				engineering of less vulnerable software and securing the information technology
				software development lifecycle;</text>
							</paragraph><paragraph id="HD45134880CC44C37B3305300445AFA74"><enum>(8)</enum><text>assist the
				development of identity management and attribution technologies;</text>
							</paragraph><paragraph id="HF138CA98ADC042CA8C3296B778D8632E"><enum>(9)</enum><text>assist the
				development of technologies designed to increase the security and resiliency of
				telecommunications networks;</text>
							</paragraph><paragraph id="HD7122BD13DDA4534ABBF7F55E76B0353"><enum>(10)</enum><text>advance the
				protection of privacy and civil liberties in cybersecurity technology and
				practices; and</text>
							</paragraph><paragraph id="HB827DBBE2ED14BAAB89DF430D13B61A0"><enum>(11)</enum><text>address other
				risks identified by the Director of the National Center for Cybersecurity and
				Communications.</text>
							</paragraph></subsection><subsection id="HAE87B38FF2E54CB8B5526534DB025B06"><enum>(c)</enum><header>Coordination
				with other research initiatives</header><text>The Under Secretary—</text>
							<paragraph id="HC0B4271ED62A49ED8DE72A17580AEFEB"><enum>(1)</enum><text>shall ensure that
				the research and development program carried out under subsection (a) is
				consistent with the national strategy to increase the security and resilience
				of cyberspace developed by the Director of Cyberspace Policy under section 101
				of the <short-title>Protecting Cyberspace as a National
				Asset Act of 2010</short-title>, or any succeeding strategy;</text>
							</paragraph><paragraph id="H0C85ED7E6A354F44863083ECF9C11C0D"><enum>(2)</enum><text>shall, to the
				extent practicable, coordinate the research and development activities of the
				Department with other ongoing research and development security-related
				initiatives, including research being conducted by—</text>
								<subparagraph id="HA0332A068EF54598BD5A27D2C3070A3F"><enum>(A)</enum><text>the National
				Institute of Standards and Technology;</text>
								</subparagraph><subparagraph id="HAFBFC3701ACA48129128F2968E6202BC"><enum>(B)</enum><text>the National
				Academy of Sciences;</text>
								</subparagraph><subparagraph id="HE7A3633E98F64794980BA972DCFFF80D"><enum>(C)</enum><text>other Federal
				agencies, as defined under section 241;</text>
								</subparagraph><subparagraph id="HE9099DBE1E754C9B9C7CE4FE7B8349ED"><enum>(D)</enum><text>other Federal and
				private research laboratories, research entities, and universities and
				institutions of higher education, and relevant nonprofit organizations;
				and</text>
								</subparagraph><subparagraph id="H35B34E281CB6462E851092079057982D"><enum>(E)</enum><text>international
				partners of the United States;</text>
								</subparagraph></paragraph><paragraph id="HB351178EAAD0407A84A727CD4FB80D84"><enum>(3)</enum><text>shall carry out
				any research and development project under subsection (a) through a
				reimbursable agreement with an appropriate Federal agency, as defined under
				section 241, if the Federal agency—</text>
								<subparagraph id="H39FB57DE250A4E5CAA126D43A9865960"><enum>(A)</enum><text>is sponsoring a
				research and development project in a similar area; or</text>
								</subparagraph><subparagraph id="H0741C003ADA44CD986C328A0DF2DDD75"><enum>(B)</enum><text>has a unique
				facility or capability that would be useful in carrying out the project;</text>
								</subparagraph></paragraph><paragraph id="HDA34A5340F9C45A9BB5C23693C5730E3"><enum>(4)</enum><text>may make grants
				to, or enter into cooperative agreements, contracts, other transactions, or
				reimbursable agreements with, the entities described in paragraph (2);
				and</text>
							</paragraph><paragraph id="H29A2761C1FDA494D9EC3574C547867F3"><enum>(5)</enum><text>shall submit a
				report to the appropriate committees of Congress on a review of the
				cybersecurity activities, and the capacity, of the national laboratories and
				other research entities available to the Department to determine if the
				establishment of a national laboratory dedicated to cybersecurity research and
				development is necessary.</text>
							</paragraph></subsection><subsection id="HB40D8F43238B465D8CD0C1AEF381040D"><enum>(d)</enum><header>Privacy and
				civil rights and civil liberties issues</header>
							<paragraph id="H8C0C0717382C4451A25C280913CC77F1"><enum>(1)</enum><header>Consultation</header><text>In
				carrying out research and development projects under subsection (a), the Under
				Secretary shall consult with the Privacy Officer appointed under section 222
				and the Officer for Civil Rights and Civil Liberties of the Department
				appointed under section 705.</text>
							</paragraph><paragraph id="H8CA2754076B24C40BC4FC75BD1CE1B76"><enum>(2)</enum><header>Privacy impact
				assessments</header><text>In accordance with sections 222 and 705, the Privacy
				Officer shall conduct privacy impact assessments and the Officer for Civil
				Rights and Civil Liberties shall conduct reviews, as appropriate, for research
				and development projects carried out under subsection (a) that the Under
				Secretary determines could have an impact on privacy, civil rights, or civil
				liberties.</text>
							</paragraph></subsection></section><section id="HF7176184C839412F8995C0273FF45827"><enum>239.</enum><header>National
				Cybersecurity Advisory Council</header>
						<subsection id="H78C8EECE79434FB7B71E01F9FF77D4FF"><enum>(a)</enum><header>Establishment</header><text>Not
				later than 90 days after the date of enactment of this section, the Secretary
				shall establish an advisory committee under section 871 on private sector
				cybersecurity, to be known as the National Cybersecurity Advisory Council (in
				this section referred to as the <term>Council</term>).</text>
						</subsection><subsection id="H1BA367631300486E90B8422CDEE884ED"><enum>(b)</enum><header>Responsibilities</header>
							<paragraph id="H42934702C37A409A9E9B2849D4C705D5"><enum>(1)</enum><header>In
				general</header><text>The Council shall advise the Director of the National
				Center for Cybersecurity and Communications on the implementation of the
				cybersecurity provisions affecting the private sector under this subtitle and
				subtitle E.</text>
							</paragraph><paragraph id="H58BCE0AC131D4C1DA78FE3256F1A7DC9"><enum>(2)</enum><header>Incentives and
				regulations</header><text>The Council shall advise the Director of the National
				Center for Cybersecurity and Communications and appropriate committees of
				Congress (as defined in section 241) and any other congressional committee with
				jurisdiction over the particular matter regarding how market incentives and
				regulations may be implemented to enhance the cybersecurity and economic
				security of the Nation.</text>
							</paragraph></subsection><subsection id="H8CA58EC2EED44A52AD70D7ED5FC582A5"><enum>(c)</enum><header>Membership</header>
							<paragraph id="H0E5785C54CCB4E1FAB9338AFF67088FF"><enum>(1)</enum><header>In
				general</header><text>The members of the Council shall be appointed the
				Director of the National Center for Cybersecurity and Communications and shall,
				to the extent practicable, represent a geographic and substantive cross-section
				of owners and operators of critical infrastructure and others with expertise in
				cybersecurity, including, as appropriate—</text>
								<subparagraph id="H1CA21B87550D4CD0B59C15C8D435D606"><enum>(A)</enum><text>representatives of
				covered critical infrastructure (as defined under section 241);</text>
								</subparagraph><subparagraph id="H886E65773C04425BB681BD942059D3E9"><enum>(B)</enum><text>academic
				institutions with expertise in cybersecurity;</text>
								</subparagraph><subparagraph id="H69070F88FCAC448E87D9E01130882670"><enum>(C)</enum><text>Federal, State,
				and local government agencies with expertise in cybersecurity;</text>
								</subparagraph><subparagraph id="H582F33D725E34ECE8BD0755C4DE04E43"><enum>(D)</enum><text>a representative
				of the National Security Telecommunications Advisory Council, as established by
				Executive Order 12382 (47 Fed. Reg. 40531; relating to the establishment of the
				advisory council), as amended by Executive Order 13286 (68 Fed. Reg. 10619), as
				in effect on August 3, 2009, or any successor entity;</text>
								</subparagraph><subparagraph id="HC45F188E955E464580E40C18679EC292"><enum>(E)</enum><text>a representative
				of the Communications Sector Coordinating Council, or any successor
				entity;</text>
								</subparagraph><subparagraph id="HD52C7A609EA54370B1BC41F03B393345"><enum>(F)</enum><text>a representative
				of the Information Technology Sector Coordinating Council, or any successor
				entity;</text>
								</subparagraph><subparagraph id="H77C74ABC29144F78AFDDD7B340777C3F"><enum>(G)</enum><text>individuals,
				acting in their personal capacity, with demonstrated technical expertise in
				cybersecurity; and</text>
								</subparagraph><subparagraph id="H04CFA02176854124AC3BE2F23FA4BB38"><enum>(H)</enum><text>such other
				individuals as the Director determines to be appropriate, including owners of
				small business concerns (as defined under section 3 of the Small Business Act
				(15 U.S.C. 632)).</text>
								</subparagraph></paragraph><paragraph id="HFECA0947D58B4D66873FC3DDAE4E850C"><enum>(2)</enum><header>Term</header><text>The
				members of the Council shall be appointed for 2-year terms and may be appointed
				to consecutive terms.</text>
							</paragraph><paragraph id="H851F2AAD6BD54075B8045D9997261EBA"><enum>(3)</enum><header>Leadership</header><text>The
				Chairperson and Vice-Chairperson of the Council shall be selected by members of
				the Council from among the members of the Council and shall serve 2-year
				terms.</text>
							</paragraph></subsection><subsection id="H0902EF411FE24C09A8762AD569734AB6"><enum>(d)</enum><header>Applicability of
				Federal Advisory Committee Act</header><text>The Federal Advisory Committee Act
				(5 U.S.C. App.) shall not apply to the
				Council.</text>
						</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</section><section id="HECCACA2AA61E4AD59594D6417838B3B3"><enum>503.</enum><header>Prioritized
			 critical information infrastructure</header><text display-inline="no-display-inline">Section 210E(a)(2) of the Homeland Security
			 Act of 2002 (6 U.S.C. 124l(a)(2)) is amended—</text>
				<paragraph id="H19CB01A061AA4042B2BDFEAB8A57CC59"><enum>(1)</enum><text>by striking
			 <quote>In accordance</quote> and inserting the following:</text>
					<quoted-block display-inline="no-display-inline" id="HF33578D3F5A0480CB31B0A974F642183" style="OLC">
						<subparagraph id="H87D839C8D78445439131EE339902D5D3"><enum>(A)</enum><header>In
				general</header><text>In accordance</text>
						</subparagraph><after-quoted-block>;
				and</after-quoted-block></quoted-block>
				</paragraph><paragraph id="H9CD7780CBAF04417BA233F1743AF9970"><enum>(2)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block display-inline="no-display-inline" id="H74C21485F0AD42E7A29A94B633BE0A59" style="OLC">
						<subparagraph id="HABF1DB657A4C40B5901E6DBF3C1C0289"><enum>(B)</enum><header>Considerations</header><text>In
				establishing and maintaining a list under subparagraph (A), the Secretary, in
				coordination with the Director of the National Center for Cybersecurity and
				Communications and in consultation with the National Cybersecurity Advisory
				Council, shall—</text>
							<clause id="H10C57552E8504440B45DA77181997915"><enum>(i)</enum><text>consider cyber
				vulnerabilities and consequences by sector, including—</text>
								<subclause id="H7FD1AB620C42479FBAB7D6D9A2B251B6"><enum>(I)</enum><text>the factors listed
				in section 248(a)(2);</text>
								</subclause><subclause id="H1D1F746DE0034DBAB4AC58D409A02DC4"><enum>(II)</enum><text>interdependencies
				between components of covered critical infrastructure (as defined under section
				241); and</text>
								</subclause><subclause id="H6146285CEC364C3BBDBC8281AA7E2FAC"><enum>(III)</enum><text>any other
				security related factor determined appropriate by the Secretary; and</text>
								</subclause></clause><clause id="HC315607D84624E6E8D52CBDDABC4E4E8"><enum>(ii)</enum><text>add covered
				critical infrastructure to or delete covered critical infrastructure from the
				list based on the factors listed in clause (i) for purposes of sections 248 and
				249.</text>
							</clause></subparagraph><subparagraph id="HBAD531BBA08C434ABF3AD5F09C659069"><enum>(C)</enum><header>Notification</header><text>The
				Secretary—</text>
							<clause id="HB31CBE9AD7DD44FB9EEE0DFC95985DE1"><enum>(i)</enum><text>shall notify the
				owner or operator of any system or asset added under subparagraph (B)(ii) to
				the list established and maintained under subparagraph (A) as soon as is
				practicable;</text>
							</clause><clause id="H0575192CF7884388BBCB1D5F72241BFB"><enum>(ii)</enum><text>shall develop a
				mechanism for an owner or operator notified under clause (i) to provide
				relevant information to the Secretary and the Director of the National Center
				for Cybersecurity and Communications relating to the inclusion of the system or
				asset on the list, including any information that the owner or operator
				believes may have led to the improper inclusion of the system or asset on the
				list; and</text>
							</clause><clause id="HE038DEA5BCFE477ABE905F1896F6293E"><enum>(iii)</enum><text>at the sole and
				unreviewable discretion of the Secretary, may revise the list based on
				information provided in clause
				(ii).</text>
							</clause></subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></section><section id="HCA572FFC068342C7A56CCBC80134E53D"><enum>504.</enum><header>National Center
			 for Cybersecurity and Communications acquisition authorities</header>
				<subsection id="HC9508D7E0F764BAFA8260F93AD0C94CD"><enum>(a)</enum><header>In
			 general</header><text>The National Center for Cybersecurity and Communications
			 is authorized to use the authorities under subsections (c)(1) and (d)(1)(B) of
			 section 2304 of title 10, United States Code, instead of the authorities under
			 subsections (c)(1) and (d)(1)(B) of section 303 of the Federal Property and
			 Administrative Services Act of 1949 (41 U.S.C. 253), subject to all other
			 requirements of section 303 of the Federal Property and Administrative Services
			 Act of 1949.</text>
				</subsection><subsection id="H0AB94CE368664EE1AE505AB5FAA02037"><enum>(b)</enum><header>Guidelines</header><text>Not
			 later than 90 days after the date of enactment of this Act, the chief
			 procurement officer of the Department of Homeland Security shall issue
			 guidelines for use of the authority under subsection (a).</text>
				</subsection><subsection id="H27056EFC53DA47F2B510426A0C8B42D7"><enum>(c)</enum><header>Termination</header><text>The
			 National Center for Cybersecurity and Communications may not use the authority
			 under subsection (a) on and after the date that is 3 years after the date of
			 enactment of this Act.</text>
				</subsection><subsection id="HCC1653D5DF77462DA77CF5526C72CC0B"><enum>(d)</enum><header>Reporting</header>
					<paragraph id="H84FE44862E964531ABE1A009919E3349"><enum>(1)</enum><header>In
			 general</header><text>On a semiannual basis, the Director of the National
			 Center for Cybersecurity and Communications shall submit a report on use of the
			 authority granted by subsection (a) to—</text>
						<subparagraph id="H78422FFF4B0544C4A829C190DF098AA1"><enum>(A)</enum><text>the Committee on
			 Homeland Security and Governmental Affairs of the Senate; and</text>
						</subparagraph><subparagraph id="H50B3D0AA27CB4DBB9D1813D7C9E404AB"><enum>(B)</enum><text>the Committee on
			 Homeland Security of the House of Representatives.</text>
						</subparagraph></paragraph><paragraph id="HB1180239F5294232B03B821625D1DC6F"><enum>(2)</enum><header>Contents</header><text>Each
			 report submitted under paragraph (1) shall include, at a minimum—</text>
						<subparagraph id="H6C944C559A8B4030B4510227E8774A53"><enum>(A)</enum><text>the number of
			 contract actions taken under the authority under subsection (a) during the
			 period covered by the report; and</text>
						</subparagraph><subparagraph id="HAC1E7C23AF60457B8F639AB682C5F63C"><enum>(B)</enum><text>for each contract
			 action described in subparagraph (A)—</text>
							<clause id="HE61DC608B91646FCBE0E6E5BE7BEFFE6"><enum>(i)</enum><text>the
			 total dollar value of the contract action;</text>
							</clause><clause id="H8A97AC726EB24AE1AFC92D80CFB417A3"><enum>(ii)</enum><text>a
			 summary of the market research conducted by the National Center for
			 Cybersecurity and Communications, including a list of all offerors who were
			 considered and those who actually submitted bids, in order to determine that
			 use of the authority was appropriate; and</text>
							</clause><clause id="H1112CE409425462E87F9663013B6EB95"><enum>(iii)</enum><text>a
			 copy of the justification and approval documents required by section 303(f) of
			 the Federal Property and Administrative Services Act of 1949 (41 U.S.C.
			 253(f)).</text>
							</clause></subparagraph></paragraph><paragraph id="H25EF793F07B548C491D691D94B67CAF1"><enum>(3)</enum><header>Classified
			 annex</header><text>A report submitted under this subsection shall be submitted
			 in an unclassified form, but may include a classified annex, if
			 necessary.</text>
					</paragraph></subsection></section><section id="H3D864E69EC8B486E868ACE23ACCA7C43"><enum>505.</enum><header>Technical and
			 conforming amendments</header>
				<subsection id="HF1EFD4CB93C64BAFA251D52F605451E7"><enum>(a)</enum><header>Elimination of
			 assistant Secretary for cybersecurity and communications</header><text>The
			 Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—</text>
					<paragraph id="H7B17DEE96F8C4BFCBA26B7F9B53F1A8E"><enum>(1)</enum><text>in section
			 103(a)(8) (6 U.S.C. 113(a)(8)), by striking <quote>,
			 cybersecurity,</quote>;</text>
					</paragraph><paragraph commented="no" id="H0280B17185384D0499E341D9CF7BAB46"><enum>(2)</enum><text>in section 514 (6
			 U.S.C. 321c)—</text>
						<subparagraph commented="no" id="HBE6C2223284A443E89837786ACEC0CA2"><enum>(A)</enum><text>by striking
			 subsection (b); and</text>
						</subparagraph><subparagraph commented="no" id="HDB26CE7B683B4135A6CFB2053F842F0E"><enum>(B)</enum><text>by redesignating
			 subsection (c) as subsection (b); and</text>
						</subparagraph></paragraph><paragraph commented="no" id="HDE227FDEE7F04D938C623F3AA66D3C71"><enum>(3)</enum><text>in section 1801(b)
			 (6 U.S.C. 571(b)), by striking <quote>shall report to the Assistant Secretary
			 for Cybersecurity and Communications</quote> and inserting <quote>shall report
			 to the Director of the National Center for Cybersecurity and
			 Communications</quote>.</text>
					</paragraph></subsection><subsection id="H7670FBB71C464CE0B2BD30CB6ADA623F"><enum>(b)</enum><header>CIO
			 council</header><text>Section 3603(b) of title 44, United States Code, is
			 amended—</text>
					<paragraph id="H4388D56BEBB64ED8B74AFE0E617A1660"><enum>(1)</enum><text>by redesignating
			 paragraph (7) as paragraph (8); and</text>
					</paragraph><paragraph id="HAA77F18FEC1E404BA4A4A4E39EB04926"><enum>(2)</enum><text>by inserting after
			 paragraph (6) the following:</text>
						<quoted-block display-inline="no-display-inline" id="HFA5FDDCC18C545078A3AA51DEADDB455" style="OLC">
							<paragraph id="HF88873196A8F4C1CBC0108A9C489A9D0"><enum>(7)</enum><text>The Director of
				the National Center for Cybersecurity and
				Communications.</text>
							</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection id="H8619F663D9144C0A9522BF29A0CBB90F"><enum>(c)</enum><header>Repeal</header><text>The
			 Homeland Security Act of 2002 (6 U.S.C. 101 et seq) is amended—</text>
					<paragraph id="H9A47251567874F5D9B9FFAB3DDD9A5F6"><enum>(1)</enum><text>by striking
			 section 223 (6 U.S.C. 143); and</text>
					</paragraph><paragraph id="HFBE74AFE6FDA44889C6991318E738989"><enum>(2)</enum><text>by redesignating
			 sections 224 and 225 (6 U.S.C. 144 and 145) as sections 223 and 224,
			 respectively.</text>
					</paragraph></subsection><subsection id="HBA9785C5E1494F108FC04D6A5445551D"><enum>(d)</enum><header>Technical
			 correction</header><text>Section 1802(a) of the Homeland Security Act of 2002
			 (6 U.S.C. 572(a)) is amended in the matter preceding paragraph (1) by striking
			 <quote>Department of</quote>.</text>
				</subsection><subsection id="HC7D418EA995E49F88C6FEBEDE7812800"><enum>(e)</enum><header>Executive
			 schedule position</header><text>Section 5313 of title 5, United States Code, is
			 amended by adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="H1CD3F2D3AF234379BD40B1B44164CCE6" style="OLC"><list level="subsection">
							<list-item>Director of the National Center for Cybersecurity
				  and
				  Communications.</list-item></list>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="HC396245226FF42248112426A8FE8A1DA"><enum>(f)</enum><header>Table of
			 contents</header><text>The table of contents in section 1(b) of the Homeland
			 Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—</text>
					<paragraph id="H8F5A3DB25C024119B106A153E3FDEDF4"><enum>(1)</enum><text>by striking the
			 items relating to sections 223, 224, and 225 and inserting the
			 following:</text>
						<quoted-block display-inline="no-display-inline" id="HA3EAC77871094401B1D7A3C1236D3C7D" style="OLC">
							<toc>
								<toc-entry bold="off" level="section">Sec. 223. NET
				guard.</toc-entry>
								<toc-entry bold="off" level="section">Sec. 224. Cyber Security
				Enhancements Act of 2002.</toc-entry>
							</toc>
							<after-quoted-block>;
				  </after-quoted-block></quoted-block>
						<continuation-text continuation-text-level="paragraph" indent="paragraph">and</continuation-text></paragraph><paragraph id="H0DECAFA4FBCF460095D84624707B7C60"><enum>(2)</enum><text>by inserting after
			 the item relating to section 237 the following:</text>
						<quoted-block display-inline="no-display-inline" id="H2FF1042005034E3CB35BD47E0588EB48" style="OLC">
							<toc>
								<toc-entry idref="H6982DC463EEC4FD1ACEAADC24D603656" level="section">Sec. 238. Cybersecurity research and development.</toc-entry>
								<toc-entry idref="HF7176184C839412F8995C0273FF45827" level="section">Sec. 239. National Cybersecurity Advisory Council.</toc-entry>
								<toc-entry idref="HB6BADBF5125C4A39870C6C89E22BF5DB" level="subtitle">Subtitle E—Cybersecurity</toc-entry>
								<toc-entry idref="HECE4813D3D1E40BBB11468AFB90049E1" level="section">Sec. 241. Definitions.</toc-entry>
								<toc-entry idref="HF0D13D8C46544A7A9998DC0082A0B780" level="section">Sec. 242. National Center for Cybersecurity and
				Communications.</toc-entry>
								<toc-entry idref="HB180B04D401F443CAEF1DA81B4CDA0D1" level="section">Sec. 243. Physical and cyber infrastructure
				collaboration.</toc-entry>
								<toc-entry idref="HD3C933BFC3F94B96A3164CF036069015" level="section">Sec. 244. United States Computer Emergency Readiness
				Team.</toc-entry>
								<toc-entry idref="H6C6DB48482434F48AC2F4EF0986CFAC6" level="section">Sec. 245. Additional authorities of the Director of the
				National Center for Cybersecurity and Communications.</toc-entry>
								<toc-entry idref="H036FA693FA624DE9A9DBEAC900D36C5A" level="section">Sec. 246. Information sharing.</toc-entry>
								<toc-entry idref="H158EAF78A29E4231B2DC9E11A323CB98" level="section">Sec. 247. Private sector assistance.</toc-entry>
								<toc-entry idref="H42AC9DE4AFED454CBBC1FB5362C8E755" level="section">Sec. 248. Cyber vulnerabilities to covered critical
				infrastructure.</toc-entry>
								<toc-entry idref="HE70DBC99F4154DD0AEEDD1E8DDF0A176" level="section">Sec. 249. National cyber emergencies..</toc-entry>
								<toc-entry idref="H5D2EB9B53BCC44789F63FC8A543B400D" level="section">Sec. 250. Enforcement.</toc-entry>
								<toc-entry idref="H6E76753D531C44299BEBB30F38434162" level="section">Sec. 251. Protection of information.</toc-entry>
								<toc-entry idref="HFC2C85C5E09C492AAFB3BCF1D30CF29C" level="section">Sec. 252. Sector-specific agencies.</toc-entry>
								<toc-entry idref="H8C0B8422662B42749910F5893800535A" level="section">Sec. 253. Strategy for Federal cybersecurity supply chain
				management.</toc-entry>
							</toc>
							<after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection></section></title></legis-body>
</bill>
