<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 413</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20110217">February 17, 2011</action-date>
			<action-desc><sponsor name-id="S210">Mr. Lieberman</sponsor> (for
			 himself, <cosponsor name-id="S252">Ms. Collins</cosponsor>, and
			 <cosponsor name-id="S277">Mr. Carper</cosponsor>) introduced the following
			 bill; which was read twice and referred to the
			 <committee-name committee-id="SSGA00">Committee on Homeland Security and
			 Governmental Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend the Homeland Security Act of 2002 and other laws
		  to enhance the security and resiliency of the cyber and communications
		  infrastructure of the United States. </official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title</header><text display-inline="no-display-inline">This Act may be cited as
			 the <quote><short-title>Cybersecurity and Internet Freedom
			 Act of 2011</short-title></quote>.</text>
		</section><section id="ID6791185bbe23484f981b6694aa23238a"><enum>2.</enum><header>Internet Freedom
			 Act</header>
			<subsection id="ID8145cd687c474c76a2d61ebe459ed78e"><enum>(a)</enum><header>Short
			 title</header><text>This section may be cited as the <quote>Internet Freedom
			 Act</quote>.</text>
			</subsection><subsection id="ID3072b7a58129470ba50bd84259ccfe9a"><enum>(b)</enum><header>Findings</header><text>Congress
			 finds that—</text>
				<paragraph id="ID33216823fb96455e87c88ee8a802d168"><enum>(1)</enum><text>the Internet is
			 vital to almost every facet of the daily lives of the people of the United
			 States, from the water we drink to the power we use to the ways we
			 communicate;</text>
				</paragraph><paragraph id="IDbe2722559ed5458886ca58112e42085b"><enum>(2)</enum><text>in the modern
			 world, the Internet is essential to the free flow of ideas and
			 information;</text>
				</paragraph><paragraph id="IDe3e1248667094c2daae15bef366e636a"><enum>(3)</enum><text>it is vital that
			 the Internet, and the access of the people of the United States to the
			 Internet, be protected to ensure the reliability of the critical services that
			 rely upon this network and the availability of the information and
			 communications that travel over this network;</text>
				</paragraph><paragraph id="IDbd570dd0435f405792560c626e3d5549"><enum>(4)</enum><text>the Internet has
			 developed into a robust network within the United States, with thousands of
			 providers, making it technically impossible to shut down the Internet;</text>
				</paragraph><paragraph id="ID9bb900bd7c1948c3909d4a9d68f92fa3"><enum>(5)</enum><text>although the
			 United States must ensure the security of the Nation and its critical
			 infrastructure, the actions of the Government must not encroach on rights
			 guaranteed by the First Amendment to the Constitution of the United
			 States;</text>
				</paragraph><paragraph id="ID6ebf7ba2200d44aba271cd9087c3a437"><enum>(6)</enum><text>cyber attacks are
			 a real and evolving threat to the information infrastructure and economy of the
			 Nation;</text>
				</paragraph><paragraph id="ID95abeab2499142f2860ad391f3a61342"><enum>(7)</enum><text>the Sergeant at
			 Arms of the Senate reported in March 2010 that the computer systems of
			 executive branch agencies of the Federal Government and Congress are probed or
			 attacked an average of 1,800,000,000 times per month;</text>
				</paragraph><paragraph id="ID6440b551bd3b4803a4db6dbd26a80290"><enum>(8)</enum><text>experts estimate
			 that cyber attacks can produce $8,000,000,000 in annual losses to the national
			 economy;</text>
				</paragraph><paragraph id="ID7f053932764f43c99a4e1305618858dc"><enum>(9)</enum><text>in the event of a
			 cyber attack, it is essential that the law clearly and unambiguously delineate
			 limits on what the Federal Government can and cannot do to protect the
			 information infrastructure that is essential to the reliable operation of the
			 Internet and the critical infrastructure of the Nation; and</text>
				</paragraph><paragraph id="ID169a812f5c8548c2845efb28a654e6f8"><enum>(10)</enum><text>neither the
			 President, the Director of the National Center for Cybersecurity and
			 Communications, nor any other officer or employee of the Federal Government
			 should have the authority to shut down the Internet.</text>
				</paragraph></subsection><subsection id="IDd6ccff5c8eef424fb81d159c728f5a65"><enum>(c)</enum><header>Limitation</header><text>Notwithstanding
			 any provision of this Act, an amendment made by this Act, or section 706 of the
			 Communications Act of 1934 (47 U.S.C. 606), neither the President, the Director
			 of the National Center for Cybersecurity and Communications, or any officer or
			 employee of the United States Government shall have the authority to shut down
			 the Internet.</text>
			</subsection></section><section id="idF00C0A746BD14CD7B92D164B4FC5209F"><enum>3.</enum><header>Table of
			 contents</header><text display-inline="no-display-inline">The table of contents
			 for this Act is as follows:</text>
			<toc>
				<toc-entry idref="S1" level="section">Sec. 1. Short
				title.</toc-entry>
				<toc-entry idref="ID6791185bbe23484f981b6694aa23238a" level="section">Sec. 2. Internet Freedom Act.</toc-entry>
				<toc-entry idref="idF00C0A746BD14CD7B92D164B4FC5209F" level="section">Sec. 3. Table of contents.</toc-entry>
				<toc-entry idref="ID4fce584630ff41b28a241a0765f7b29d" level="section">Sec. 4. Definitions.</toc-entry>
				<toc-entry idref="idF043ACBD2C564FB388676429B7716A3C" level="title">TITLE I—Office of Cyberspace Policy</toc-entry>
				<toc-entry idref="id992EDFA5EA4B41179681BF821FAE894D" level="section">Sec. 101. Establishment of the Office of Cyberspace
				Policy.</toc-entry>
				<toc-entry idref="ID96ea2845ae6b4e4dae9e593117924a85" level="section">Sec. 102. Appointment and responsibilities of the
				Director.</toc-entry>
				<toc-entry idref="ID4e16813dbb8b4275b2dc837e2a1efdbe" level="section">Sec. 103. Prohibition on political campaigning.</toc-entry>
				<toc-entry idref="ID1e94202640024384a87e343a84b43d6c" level="section">Sec. 104. Review of Federal agency budget requests relating to
				the National Strategy.</toc-entry>
				<toc-entry idref="IDe4459ca89728479da2ae8555f44e38c2" level="section">Sec. 105. Access to intelligence.</toc-entry>
				<toc-entry idref="IDcf140785c1424cdba99b8832271eaeb6" level="section">Sec. 106. Consultation.</toc-entry>
				<toc-entry idref="ID4eebe40aa1924b6b81022e289796dced" level="section">Sec. 107. Reports to Congress.</toc-entry>
				<toc-entry idref="id3C4F4EFC6C5D483E85A959A8C8A05244" level="title">TITLE II—National Center for Cybersecurity and
				Communications</toc-entry>
				<toc-entry idref="id9DDF4948510C4606816921E13E927E43" level="section">Sec. 201. Cybersecurity.</toc-entry>
				<toc-entry idref="id09378F28821A4536B8E6EBBF1EEFB294" level="title">TITLE III—Federal information security management</toc-entry>
				<toc-entry idref="id3707C79386544858A9895DA9F4A555BE" level="section">Sec. 301. Coordination of Federal information
				policy.</toc-entry>
				<toc-entry idref="idB3615AE252CB4FF5A86D4143B6D5DE6D" level="title">TITLE IV—Recruitment and professional development</toc-entry>
				<toc-entry idref="ID29c72cb85cb54b4aaddeab346c193576" level="section">Sec. 401. Definitions.</toc-entry>
				<toc-entry idref="ID8b3dfe337f3249459729da301ac9a864" level="section">Sec. 402. Assessment of cybersecurity workforce.</toc-entry>
				<toc-entry idref="IDf9e9b7375eb844dda53fb996371978dc" level="section">Sec. 403. Strategic cybersecurity workforce
				planning.</toc-entry>
				<toc-entry idref="ID6cf6c953481e43b1b5392b0476e88005" level="section">Sec. 404. Cybersecurity occupation classifications.</toc-entry>
				<toc-entry idref="ID1a6d962aedca4c549183ecb2bde165af" level="section">Sec. 405. Measures of cybersecurity hiring
				effectiveness.</toc-entry>
				<toc-entry idref="ID319a942788be46748fd9c586718d6182" level="section">Sec. 406. Training and education.</toc-entry>
				<toc-entry idref="IDc32ea0eb8e1d4438abec09ef41835570" level="section">Sec. 407. Cybersecurity incentives.</toc-entry>
				<toc-entry idref="ID12ffe66f0c774e17916ead94399dacfc" level="section">Sec. 408. Recruitment and retention program for the National
				Center for Cybersecurity and Communications.</toc-entry>
				<toc-entry idref="id72901E10981A4D4996240B88D11E79CA" level="title">TITLE V—Other provisions</toc-entry>
				<toc-entry idref="ID8341c072a47f4eb68e8739799f60c4fc" level="section">Sec. 501. Cybersecurity research and development.</toc-entry>
				<toc-entry idref="IDb051d2fdb28844a09118be8409f42b36" level="section">Sec. 502. Prioritized critical information
				infrastructure.</toc-entry>
				<toc-entry idref="ID8dee57d503054ddcad53cf59054e804c" level="section">Sec. 503. National Center for Cybersecurity and Communications
				acquisition authorities.</toc-entry>
				<toc-entry idref="IDf25ea60651464629aa89763d19916f46" level="section">Sec. 504. Evaluation of the effective implementation of Office
				of Management and Budget information security related policies and
				directives.</toc-entry>
				<toc-entry idref="IDa9d2582a915f438bb7c1b906f75c7f14" level="section">Sec. 505. Technical and conforming amendments.</toc-entry>
			</toc>
		</section><section id="ID4fce584630ff41b28a241a0765f7b29d"><enum>4.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="ID4550447a9d5e4d9fb72383cd7bab308b"><enum>(1)</enum><header>Appropriate
			 congressional committees</header><text>The term <term>appropriate congressional
			 committees</term> means—</text>
				<subparagraph id="ID7204ff7528fb4ab19a6ba1a43c1d33de"><enum>(A)</enum><text>the Committee on
			 Homeland Security and Governmental Affairs of the Senate;</text>
				</subparagraph><subparagraph id="ID7b6b0fffdaf14671a7843dda3aeadc2a"><enum>(B)</enum><text>the Committee on
			 Homeland Security of the House of Representatives;</text>
				</subparagraph><subparagraph id="id787D60FF4DCC41749F529FD85D79A7A5"><enum>(C)</enum><text>the Committee on
			 Oversight and Government Reform of the House of Representatives; and</text>
				</subparagraph><subparagraph id="ID61c4956987a3402b81f997941fcd68e7"><enum>(D)</enum><text>any other
			 congressional committee with jurisdiction over the particular matter.</text>
				</subparagraph></paragraph><paragraph id="id2B0E1EE2D8104A7FA87B6E6E542563CC"><enum>(2)</enum><header>Critical
			 infrastructure</header><text>The term <term>critical infrastructure</term> has
			 the meaning given that term in section 1016(e) of the USA PATRIOT Act (42
			 U.S.C. 5195c(e)).</text>
			</paragraph><paragraph id="IDf99dfa39ab97410fafc1ab1bc42cd55d"><enum>(3)</enum><header>Cyberspace</header><text>The
			 term <term>cyberspace</term> means the interdependent network of information
			 infrastructure, and includes the Internet, telecommunications networks,
			 computer systems, and embedded processors and controllers in critical
			 industries.</text>
			</paragraph><paragraph commented="no" id="IDa973d27adf2842998ad8bca2066700a7"><enum>(4)</enum><header>Director</header><text>The
			 term <term>Director</term> means the Director of Cyberspace Policy established
			 under section 101.</text>
			</paragraph><paragraph id="IDe3bc9f8329fc4588963dcb6d319a7570"><enum>(5)</enum><header>Federal
			 agency</header><text>The term <term>Federal agency</term>—</text>
				<subparagraph id="IDe14527ef4ff642c29664334215a494b5"><enum>(A)</enum><text>means any
			 executive department, Government corporation, Government controlled
			 corporation, or other establishment in the executive branch of the Government
			 (including the Executive Office of the President), or any independent
			 regulatory agency; and</text>
				</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDdae110e4379140a4b86a22cedb8f8449"><enum>(B)</enum><text>does not include
			 the governments of the District of Columbia and of the territories and
			 possessions of the United States and their various subdivisions.</text>
				</subparagraph></paragraph><paragraph id="ID3bddb9ee9e4c4b05bdab0b1de25bfeb1"><enum>(6)</enum><header>Federal
			 information infrastructure</header><text>The term <term>Federal information
			 infrastructure</term>—</text>
				<subparagraph id="ID092cfe7e7e774c5da6972344b2cf1f62"><enum>(A)</enum><text>means information
			 infrastructure that is owned, operated, controlled, or licensed for use by, or
			 on behalf of, any Federal agency, including information systems used or
			 operated by another entity on behalf of a Federal agency; and</text>
				</subparagraph><subparagraph id="ID7e414e94c77c42aa9535b5562226584f"><enum>(B)</enum><text>does not
			 include—</text>
					<clause id="IDb4577df4c37d47a98fdeedb32072d3b2"><enum>(i)</enum><text>a
			 national security system; or</text>
					</clause><clause id="ID82de5a1883404cdba6865a5c30e07171"><enum>(ii)</enum><text>information
			 infrastructure that is owned, operated, controlled, or licensed for use by, or
			 on behalf of, the Department of Defense, a military department, or another
			 element of the intelligence community.</text>
					</clause></subparagraph></paragraph><paragraph commented="no" id="IDd437c7aa67554fff940b60dac35cc859"><enum>(7)</enum><header>Incident</header><text>The
			 term <term>incident</term> has the meaning given that term in section 3551 of
			 title 44, United States Code, as added by this Act.</text>
			</paragraph><paragraph id="idA5DFC369EF754660935370882902E317"><enum>(8)</enum><header>Information
			 infrastructure</header><text>The term <term>information infrastructure</term>
			 means the underlying framework that information systems and assets rely on to
			 process, transmit, receive, or store information electronically, including
			 programmable electronic devices and communications networks and any associated
			 hardware, software, or data.</text>
			</paragraph><paragraph id="ID4bff5905200b4464b658cb02067d34b0"><enum>(9)</enum><header>Information
			 security</header><text>The term <term>information security</term> means
			 protecting information and information systems from disruption or unauthorized
			 access, use, disclosure, modification, or destruction in order to
			 provide—</text>
				<subparagraph id="IDa1cb5424db6840849c33cdf310fd248c"><enum>(A)</enum><text>integrity, by
			 guarding against improper information modification or destruction, including by
			 ensuring information nonrepudiation and authenticity;</text>
				</subparagraph><subparagraph id="ID0b90165382cb4a6eb41a418351771a73"><enum>(B)</enum><text>confidentiality,
			 by preserving authorized restrictions on access and disclosure, including means
			 for protecting personal privacy and proprietary information; and</text>
				</subparagraph><subparagraph id="ID31ee4fcef18142b089009e86b745db57"><enum>(C)</enum><text>availability, by
			 ensuring timely and reliable access to and use of information.</text>
				</subparagraph></paragraph><paragraph id="ID80c659e13ea64c358f7936a47e200ef9"><enum>(10)</enum><header>Information
			 technology</header><text>The term <term>information technology</term> has the
			 meaning given that term in section 11101 of title 40, United States
			 Code.</text>
			</paragraph><paragraph id="ID6f3346bce3954dd4aa84b7c1e3c84f48"><enum>(11)</enum><header>Intelligence
			 community</header><text>The term <term>intelligence community</term> has the
			 meaning given that term under section 3(4) of the National Security Act of 1947
			 (50 U.S.C. 401a(4)).</text>
			</paragraph><paragraph id="id0A1913EB57C442CA8469ABC8E3E423F7"><enum>(12)</enum><header>Key
			 resources</header><text>The term <term>key resources</term> has the meaning
			 given that term in section 2 of the Homeland Security Act of 2002 (6 U.S.C.
			 101).</text>
			</paragraph><paragraph id="idACE88060488042FFB4AAA5F71B5CDA9E"><enum>(13)</enum><header>National
			 Center for Cybersecurity and Communications</header><text>The term
			 <term>National Center for Cybersecurity and Communications</term> means the
			 National Center for Cybersecurity and Communications established under section
			 242(a) of the Homeland Security Act of 2002, as added by this Act.</text>
			</paragraph><paragraph id="ID70fc3b1fc4fa4012a925dc07cfa1e848"><enum>(14)</enum><header>National
			 information infrastructure</header><text>The term <term>national information
			 infrastructure</term> means information infrastructure—</text>
				<subparagraph id="ID33c26e9085474800898a152ec5b65dac"><enum>(A)</enum><text>that is owned,
			 operated, or controlled within or from the United States; and</text>
				</subparagraph><subparagraph id="id138DF7DDC64D437398F0533C422062CC"><enum>(B)</enum><text>that is not
			 owned, operated, controlled, or licensed for use by a Federal agency.</text>
				</subparagraph></paragraph><paragraph id="idDD7A2703805E4CB3BD35B09E1B752297"><enum>(15)</enum><header>National
			 security system</header><text>The term <term>national security system</term>
			 has the meaning given that term in section 3551 of title 44, United States
			 Code, as added by this Act.</text>
			</paragraph><paragraph id="ID7d9961fdf9eb48ca954bd325c5bfb3c4"><enum>(16)</enum><header>National
			 strategy</header><text>The term <term>National Strategy</term> means the
			 national strategy to increase the security and resiliency of cyberspace
			 developed under section 101(a)(1).</text>
			</paragraph><paragraph id="IDb8f9d13ac7bd4aa6b085bcdaec2ff007"><enum>(17)</enum><header>Office</header><text>The
			 term <term>Office</term> means the Office of Cyberspace Policy established
			 under section 101.</text>
			</paragraph><paragraph id="IDaa1f8395324341f9a065c6a1bc9273d7"><enum>(18)</enum><header>Resiliency</header><text>The
			 term <term>resiliency</term> means the ability to eliminate or reduce the
			 magnitude or duration of a disruptive event, including the ability to prevent,
			 prepare for, respond to, and recover from the event.</text>
			</paragraph><paragraph id="IDb9c3630e71614580ab814d58523d9d87"><enum>(19)</enum><header>Risk</header><text>The
			 term <term>risk</term> means the potential for an unwanted outcome resulting
			 from an incident, as determined by the likelihood of the occurrence of the
			 incident and the associated consequences, including potential for an adverse
			 outcome assessed as a function of threats, vulnerabilities, and consequences
			 associated with an incident.</text>
			</paragraph><paragraph id="IDbdc1140fbc8647b49d3c11ad954f5a32"><enum>(20)</enum><header>Risk-based
			 security</header><text>The term <term>risk-based security</term> has the
			 meaning given that term in section 3551 of title 44, United States Code, as
			 added by this Act.</text>
			</paragraph></section><title id="idF043ACBD2C564FB388676429B7716A3C"><enum>I</enum><header>Office of
			 Cyberspace Policy</header>
			<section id="id992EDFA5EA4B41179681BF821FAE894D"><enum>101.</enum><header>Establishment
			 of the Office of Cyberspace Policy</header>
				<subsection id="ID75caba9a20f8465191213455ceff688b"><enum>(a)</enum><header>Establishment
			 of office</header><text>There is established in the Executive Office of the
			 President an Office of Cyberspace Policy which shall—</text>
					<paragraph id="ID99cbeba301754497b592fa0ed98b5d57"><enum>(1)</enum><text>develop, not
			 later than 1 year after the date of enactment of this Act, and update as
			 needed, but not less frequently than once every 2 years, a national strategy to
			 increase the security and resiliency of cyberspace, that includes goals and
			 objectives relating to—</text>
						<subparagraph id="ID1ac21d81571844d582fdef01a5ccf6db"><enum>(A)</enum><text>computer network
			 operations, including offensive activities, defensive activities, and other
			 activities;</text>
						</subparagraph><subparagraph id="IDe281093fc61d4eb99cac813c95015035"><enum>(B)</enum><text>information
			 assurance;</text>
						</subparagraph><subparagraph id="IDf7454062dcfe4a928607d4aa84260958"><enum>(C)</enum><text>protection of
			 critical infrastructure and key resources;</text>
						</subparagraph><subparagraph id="IDe14e3771b7f04388bac968a0035e7341"><enum>(D)</enum><text>research and
			 development priorities;</text>
						</subparagraph><subparagraph id="IDe2c2b7326d6c4e89a30757b674b7ea86"><enum>(E)</enum><text>law
			 enforcement;</text>
						</subparagraph><subparagraph id="ID50b421f7ecc747d78c6fc29415a5e062"><enum>(F)</enum><text>diplomacy;</text>
						</subparagraph><subparagraph id="ID6bcb680b14e947efa7446945bb6892ca"><enum>(G)</enum><text>homeland
			 security;</text>
						</subparagraph><subparagraph id="id20AD24AE52BE48EF8117977747A670AA"><enum>(H)</enum><text>protection of
			 privacy and civil liberties;</text>
						</subparagraph><subparagraph id="ID0c063748ef0b47908dbcd78d228a0cdc"><enum>(I)</enum><text>military and
			 intelligence activities; and</text>
						</subparagraph><subparagraph id="id76C1D38314AD4B77993CB0762A7B4E2D"><enum>(J)</enum><text>identity
			 management and authentication;</text>
						</subparagraph></paragraph><paragraph id="IDf587f73c88d7479f85c0c2bcff2b5421"><enum>(2)</enum><text>oversee,
			 coordinate, and integrate all policies and activities of the Federal Government
			 across all instruments of national power relating to ensuring the security and
			 resiliency of cyberspace, including—</text>
						<subparagraph id="id35D3BFB35BB44CA78DB6072ECD419EE6"><enum>(A)</enum><text>diplomatic,
			 economic, military, intelligence, homeland security, and law enforcement
			 policies and activities within and among Federal agencies; and</text>
						</subparagraph><subparagraph id="id82745302764840F1ADFE9A40523CEDFE"><enum>(B)</enum><text>offensive
			 activities, defensive activities, and other policies and activities necessary
			 to ensure effective capabilities to operate in cyberspace;</text>
						</subparagraph></paragraph><paragraph id="ID39c231b97a4846e880e2f46c81bbb857"><enum>(3)</enum><text>ensure that all
			 Federal agencies comply with appropriate guidelines, policies, and directives
			 from the Department of Homeland Security, other Federal agencies with
			 responsibilities relating to cyberspace security or resiliency, and the
			 National Center for Cybersecurity and Communications; and</text>
					</paragraph><paragraph id="ID99761da954414cb5bf4817dcdb8b96ef"><enum>(4)</enum><text>ensure that
			 Federal agencies have access to, receive, and appropriately disseminate law
			 enforcement information, intelligence information, terrorism information, and
			 any other information (including information relating to incidents provided
			 under subsections (a)(4) and (c) of section 246 of the Homeland Security Act of
			 2002, as added by this Act) relevant to—</text>
						<subparagraph id="id00D3A1717608411E910F5640EF643FE7"><enum>(A)</enum><text>the security of
			 the Federal information infrastructure or the national information
			 infrastructure; and</text>
						</subparagraph><subparagraph id="id61C7852B77CC409193564E1B55C0556B"><enum>(B)</enum><text>the security
			 of—</text>
							<clause id="id7391423FD77A424F9966403C1F46519F"><enum>(i)</enum><text>information
			 infrastructure that is owned, operated, controlled, or licensed for use by, or
			 on behalf of, the Department of Defense, a military department, or another
			 element of the intelligence community; or</text>
							</clause><clause id="id07626018FCDB44B8B34E36368F29ECD6"><enum>(ii)</enum><text>a
			 national security system.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="IDae23baa7cd154bdcb981708cb36c6a9c"><enum>(b)</enum><header>Director of
			 Cyberspace Policy</header>
					<paragraph id="IDee963ea411824d559c12bc96888aeef8"><enum>(1)</enum><header>In
			 general</header><text>There shall be a Director of Cyberspace Policy, who shall
			 be the head of the Office.</text>
					</paragraph><paragraph id="IDb63e356f83d34b2fa89a7b25f4f39243"><enum>(2)</enum><header>Executive
			 schedule position</header><text>Section 5312 of title 5, United States Code, is
			 amended by adding at the end the following:</text>
						<quoted-block display-inline="no-display-inline" id="id14FE65187BEF4247A92FC5FD7DC78C91" style="OLC"><list level="paragraph">
								<list-item>Director of Cyberspace
				  Policy.</list-item></list>
							<after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection></section><section id="ID96ea2845ae6b4e4dae9e593117924a85"><enum>102.</enum><header>Appointment
			 and responsibilities of the Director</header>
				<subsection id="ID502df5be10f34eb99e61de5265557edf"><enum>(a)</enum><header>Appointment</header>
					<paragraph id="IDb3ac16cfc73147e7b0ee09bf4427fbb7"><enum>(1)</enum><header>In
			 general</header><text>The Director shall be appointed by the President, by and
			 with the advice and consent of the Senate.</text>
					</paragraph><paragraph id="ID6b0f6f552b214f26bad41ec026219b57"><enum>(2)</enum><header>Qualifications</header><text>The
			 President shall appoint the Director from among individuals who have
			 demonstrated ability and knowledge in information technology, cybersecurity,
			 and the operations, security, and resiliency of communications networks.</text>
					</paragraph><paragraph id="ID436611d66bb942cf983812973d7e9499"><enum>(3)</enum><header>Prohibition</header><text>No
			 person shall serve as Director while serving in any other position in the
			 Federal Government.</text>
					</paragraph></subsection><subsection id="ID7b8a73be08ef4d87a12832b6af549988"><enum>(b)</enum><header>Responsibilities</header><text>The
			 Director shall—</text>
					<paragraph id="ID7949c5a7cb6e48269334d5f0fd29f96b"><enum>(1)</enum><text>advise the
			 President regarding the establishment of policies, goals, objectives, and
			 priorities for securing the information infrastructure of the Nation;</text>
					</paragraph><paragraph id="IDb2b4c00469e24b7487c444695de9365f"><enum>(2)</enum><text>advise the
			 President and other entities within the Executive Office of the President
			 regarding mechanisms to build, and improve the resiliency and efficiency of,
			 the information and communication industry of the Nation, in collaboration with
			 the private sector, while promoting national economic interests;</text>
					</paragraph><paragraph id="ID1cca91a419474287be52ba941570f0fe"><enum>(3)</enum><text>work with Federal
			 agencies to—</text>
						<subparagraph id="ID43a2870531b349a7b81604e2c194a751"><enum>(A)</enum><text>oversee,
			 coordinate, and integrate the implementation of the National Strategy,
			 including coordination with—</text>
							<clause id="ID51d64f8e959a4140bdac69c612e5ecf7"><enum>(i)</enum><text>the
			 Department of Homeland Security;</text>
							</clause><clause id="IDa7fa3b04255b49748d7a87c452debbe6"><enum>(ii)</enum><text>the Department
			 of Defense;</text>
							</clause><clause id="IDeb6aac5bf151430f8f1ac46cce8b72b7"><enum>(iii)</enum><text>the Department
			 of Commerce;</text>
							</clause><clause id="ID64ceb72a838c459da8d354e497fabdb5"><enum>(iv)</enum><text>the Department
			 of State;</text>
							</clause><clause id="ID48bf6d384bd044e28c02c9e915b81990"><enum>(v)</enum><text>the
			 Department of Justice;</text>
							</clause><clause id="IDdd827754730946a29611769ea4388546"><enum>(vi)</enum><text>the Department
			 of Energy;</text>
							</clause><clause id="IDab07fbb7462c493da409726f0c8c3be6"><enum>(vii)</enum><text>through the
			 Director of National Intelligence, the intelligence community; and</text>
							</clause><clause id="IDcb38f3e17ddb410f855f77a73235e670"><enum>(viii)</enum><text>and any other
			 Federal agency with responsibilities relating to the National Strategy;
			 and</text>
							</clause></subparagraph><subparagraph id="ID6cdc7739d32b42b587fa753900debf2a"><enum>(B)</enum><text>resolve any
			 disputes that arise between Federal agencies relating to the National Strategy
			 or other matters within the responsibility of the Office;</text>
						</subparagraph></paragraph><paragraph id="ID60270f2a232c4bcd9fc4cb6af1539184"><enum>(4)</enum><text>if the policies
			 or activities of a Federal agency are not in compliance with the
			 responsibilities of the Federal agency under the National Strategy—</text>
						<subparagraph id="id3E8AEE475B5C444292D6632030140A4C"><enum>(A)</enum><text>notify the
			 Federal agency;</text>
						</subparagraph><subparagraph id="idF59D7E3BA0C44D29A9F1D8EC8797741F"><enum>(B)</enum><text>transmit a copy
			 of each notification under subparagraph (A) to the President and the
			 appropriate congressional committees; and</text>
						</subparagraph><subparagraph id="id2B0D747548BC44EEB3449A3B9A12ED55"><enum>(C)</enum><text>coordinate the
			 efforts to bring the Federal agency into compliance;</text>
						</subparagraph></paragraph><paragraph id="ID9ca566f644924e83a4b1ce5e4ff0e668"><enum>(5)</enum><text>ensure the
			 adequacy of protections for privacy and civil liberties in carrying out the
			 responsibilities of the Director under this title, including through
			 consultation with the Privacy and Civil Liberties Oversight Board established
			 under section 1061 of the National Security Intelligence Reform Act of 2004 (42
			 U.S.C. 2000ee);</text>
					</paragraph><paragraph id="ID123dc80677e54befbbe9ba0f71e73785"><enum>(6)</enum><text>upon reasonable
			 request, appear before any duly constituted committees of the Senate or of the
			 House of Representatives;</text>
					</paragraph><paragraph id="IDaf8fafdf7990400caec9dcf9d7145a77"><enum>(7)</enum><text>recommend to the
			 Office of Management and Budget or the head of a Federal agency actions
			 (including requests to Congress relating to the reprogramming of funds) that
			 the Director determines are necessary to ensure risk-based security of—</text>
						<subparagraph id="id9940A24056BA4D149CD842004DAEE6A5"><enum>(A)</enum><text>the Federal
			 information infrastructure;</text>
						</subparagraph><subparagraph id="idE49949A7C3B34CB49D1F561DD55E1DE3"><enum>(B)</enum><text>information
			 infrastructure that is owned, operated, controlled, or licensed for use by, or
			 on behalf of, the Department of Defense, a military department, or another
			 element of the intelligence community; or</text>
						</subparagraph><subparagraph id="idDD60089F39E14C23B7B0046DFA5C2F7B"><enum>(C)</enum><text>a national
			 security system;</text>
						</subparagraph></paragraph><paragraph id="IDbd8dfc0a859e4b40918ea1d48fe82a2c"><enum>(8)</enum><text>advise the
			 Administrator of the Office of E-Government and Information Technology and the
			 Administrator of the Office of Information and Regulatory Affairs on the
			 development, and oversee the implementation, of policies, principles,
			 standards, guidelines, and budget priorities for information technology
			 functions and activities of the Federal Government;</text>
					</paragraph><paragraph id="ID799d2e401bb0436babe28fd12b528879"><enum>(9)</enum><text>coordinate and
			 ensure, to the maximum extent practicable, that the standards and guidelines
			 developed for national security systems and the standards and guidelines under
			 section 20 of the National Institute of Standards and Technology Act (15 U.S.C.
			 278g–3) are complementary and unified;</text>
					</paragraph><paragraph id="ID3704b7c9f3634b46a1a8b5ccc8ede978"><enum>(10)</enum><text>in consultation
			 with the Administrator of the Office of Information and Regulatory Affairs,
			 coordinate efforts of Federal agencies relating to the development of
			 regulations, rules, requirements, or other actions applicable to the national
			 information infrastructure to ensure, to the maximum extent practicable, that
			 the efforts are complementary;</text>
					</paragraph><paragraph id="ID5841f151146f426d9baf194f5961b76d"><enum>(11)</enum><text>coordinate the
			 activities of the Office of Science and Technology Policy, the National
			 Economic Council, the Office of Management and Budget, the National Security
			 Council, the Homeland Security Council, and the United States Trade
			 Representative related to the National Strategy and other matters within the
			 purview of the Office;</text>
					</paragraph><paragraph id="ID286db13ad7df4b2285cb6080fd5d1022"><enum>(12)</enum><text>carry out the
			 responsibilities for national security and emergency preparedness
			 communications described in section 706 of the Communications Act of 1934 (47
			 U.S.C. 606) to ensure integration and coordination; and</text>
					</paragraph><paragraph id="idD0F5748ABDCD41228B936A0D23340D32"><enum>(13)</enum><text>as assigned by
			 the President, other duties relating to the security and resiliency of
			 cyberspace.</text>
					</paragraph></subsection><subsection id="id5493A55BA2704E51A487FE18AE1CFE1C"><enum>(c)</enum><header>Conforming
			 regulations and orders</header><text>The President shall amend the regulations
			 and orders issued under section 706 of the Communications Act of 1934 (47
			 U.S.C. 606) in accordance with subsection (b)(12).</text>
				</subsection></section><section id="ID4e16813dbb8b4275b2dc837e2a1efdbe"><enum>103.</enum><header>Prohibition on
			 political campaigning</header><text display-inline="no-display-inline">Section
			 7323(b)(2)(B) of title 5, United States Code, is amended—</text>
				<paragraph id="ID0a78f364789a4a4689d55facacbbdd40"><enum>(1)</enum><text>in clause (i), by
			 striking <quote>or</quote> at the end;</text>
				</paragraph><paragraph id="ID9614e2f9c59346359158ee894cfb1162"><enum>(2)</enum><text>in clause (ii),
			 by striking the period at the end and inserting <quote>; or</quote>; and</text>
				</paragraph><paragraph id="ID098bebed624e49eb9f31c46f6c5521bc"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block display-inline="no-display-inline" id="idFB02671DB9094214A9FD0587C6707363" style="OLC">
						<clause commented="no" id="ID53f755f029f04fdaa105e781bc16cf2a"><enum>(iii)</enum><text>notwithstanding
				the exception under subparagraph (A) (relating to an appointment made by the
				President, by and with the advice and consent of the Senate), the Director of
				Cyberspace
				Policy.</text>
						</clause><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></section><section id="ID1e94202640024384a87e343a84b43d6c"><enum>104.</enum><header>Review of
			 Federal agency budget requests relating to the National Strategy</header>
				<subsection id="IDc3f90deed04449119bb174539fa6dbd0"><enum>(a)</enum><header>In
			 general</header><text>For each fiscal year, the head of each Federal agency
			 shall transmit to the Director a copy of any portion of the budget of the
			 Federal agency intended to implement the National Strategy at the same time as
			 that budget request is submitted to the Office of Management and Budget in the
			 preparation of the budget of the President submitted to Congress under section
			 1105(a) of title 31, United States Code.</text>
				</subsection><subsection id="IDbe9cc76ab1a540858032ebad53129209"><enum>(b)</enum><header>Timely
			 submissions</header><text>The head of each Federal agency shall ensure the
			 timely development and submission to the Director of each proposed budget under
			 this section, in such format as may be designated by the Director with the
			 concurrence of the Director of the Office of Management and Budget.</text>
				</subsection><subsection id="IDdc3f1cb264ca4589aeee29f05bc5ee1f"><enum>(c)</enum><header>Adequacy of the
			 proposed budget requests</header><text>With the assistance of, and in
			 coordination with, the Office of E-Government and Information Technology and
			 the National Center for Cybersecurity and Communications, the Director shall
			 review each budget submission to assess the adequacy of the proposed request
			 with regard to implementation of the National Strategy, including the overall
			 sufficiency of the requests to implement effectively the National Strategy
			 across all Federal agencies.</text>
				</subsection><subsection id="ID2176b3303f884770a1eb4f504b484249"><enum>(d)</enum><header>Inadequate
			 budget requests</header><text>If the Director concludes that a budget request
			 submitted under subsection (a) is inadequate, in whole or in part, to implement
			 the objectives of the National Strategy, the Director shall submit to the
			 Director of the Office of Management and Budget and the head of the Federal
			 agency submitting the budget request a written description of funding levels
			 and specific initiatives that would, in the determination of the Director, make
			 the request adequate.</text>
				</subsection></section><section id="IDe4459ca89728479da2ae8555f44e38c2"><enum>105.</enum><header>Access to
			 intelligence</header><text display-inline="no-display-inline">The Director
			 shall have access to law enforcement information, intelligence information,
			 terrorism information, and any other information (including information
			 relating to incidents provided under subsections (a)(4) and (c) of section 246
			 of the Homeland Security Act of 2002, as added by this Act) that is obtained
			 by, or in the possession of, any Federal agency that the Director determines
			 relevant to the security of—</text>
				<paragraph id="id048DD9A209AC4550B98C43FDA5C10E6E"><enum>(1)</enum><text display-inline="yes-display-inline">the Federal information
			 infrastructure;</text>
				</paragraph><paragraph id="idDD972DB81CFA405C90ECF77FC644EFCC"><enum>(2)</enum><text display-inline="yes-display-inline">information infrastructure that is owned,
			 operated, controlled, or licensed for use by, or on behalf of, the Department
			 of Defense, a military department, or another element of the intelligence
			 community;</text>
				</paragraph><paragraph id="id57EDF0AFA95B4D65A27CDB69E15C7384"><enum>(3)</enum><text display-inline="yes-display-inline">a national security system; or</text>
				</paragraph><paragraph id="idF84602BC1E4C4688908409F019038F57"><enum>(4)</enum><text display-inline="yes-display-inline">national information infrastructure.</text>
				</paragraph></section><section id="IDcf140785c1424cdba99b8832271eaeb6"><enum>106.</enum><header>Consultation</header>
				<subsection id="IDc3ca0433b51144088932460f39ebac17"><enum>(a)</enum><header>In
			 general</header><text>The Director may consult and obtain recommendations from,
			 as needed, such Presidential and other advisory entities as the Director
			 determines will assist in carrying out the mission of the Office,
			 including—</text>
					<paragraph id="id62A763BC963B47DBBD65D8019D9A03DD"><enum>(1)</enum><text>the National
			 Security Telecommunications Advisory Committee;</text>
					</paragraph><paragraph id="id689F26F6654C4D4B93025ACD9B96D711"><enum>(2)</enum><text>the National
			 Infrastructure Advisory Council;</text>
					</paragraph><paragraph id="idA116FFDDEB1B45E39C1041430DE2FAEB"><enum>(3)</enum><text>the Privacy and
			 Civil Liberties Oversight Board;</text>
					</paragraph><paragraph id="idA09765AD96734F779B9E16FF2B57A51D"><enum>(4)</enum><text>the President’s
			 Intelligence Advisory Board;</text>
					</paragraph><paragraph id="ID58a9a83a7f9f4e0184d7c97134e3a78b"><enum>(5)</enum><text>the Critical
			 Infrastructure Partnership Advisory Council;</text>
					</paragraph><paragraph id="id42DED38BB91B420DB87C8773728D2A05"><enum>(6)</enum><text>the Committee on
			 Foreign Investment in the United States;</text>
					</paragraph><paragraph id="ID4126f3183af540e1a47d14fe9bc0393f"><enum>(7)</enum><text>the Information
			 Security and Privacy Advisory Board;</text>
					</paragraph><paragraph id="IDe6e63758725a45f286f454792efd5a73"><enum>(8)</enum><text>the National
			 Cybersecurity Advisory Council established under section 239 of the Homeland
			 Security Act of 2002, as added by this Act; and</text>
					</paragraph><paragraph id="idB014F5948E9E4B93870142D9FA163B2A"><enum>(9)</enum><text>any other entity
			 that may provide assistance to the Director.</text>
					</paragraph></subsection><subsection id="ID0ab3d5457d3d4219b8a279446a5b422c"><enum>(b)</enum><header>National
			 Strategy</header><text>In developing and updating the National Strategy the
			 Director shall consult with the National Cybersecurity Advisory Council and, as
			 appropriate, State and local governments and private entities.</text>
				</subsection></section><section id="ID4eebe40aa1924b6b81022e289796dced"><enum>107.</enum><header>Reports to
			 Congress</header>
				<subsection id="ID03a372819ff5435da4da5d8f45590fbb"><enum>(a)</enum><header>In
			 general</header><text>The Director shall submit an annual report to the
			 appropriate congressional committees describing the activities, ongoing
			 projects, and plans of the Federal Government designed to meet the goals and
			 objectives of the National Strategy.</text>
				</subsection><subsection id="ID70ac880d602541ac8830e60aa4bf9662"><enum>(b)</enum><header>Classified
			 annex</header><text>A report submitted under this section shall be submitted in
			 an unclassified form, but may include a classified annex, if necessary.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="id0F25C619149F4CB88090A2DDFDB40DAE"><enum>(c)</enum><header>Public
			 report</header><text>An unclassified version of each report submitted under
			 this section shall be made available to the public.</text>
				</subsection></section></title><title id="id3C4F4EFC6C5D483E85A959A8C8A05244"><enum>II</enum><header>National Center
			 for Cybersecurity and Communications</header>
			<section id="id9DDF4948510C4606816921E13E927E43"><enum>201.</enum><header>Cybersecurity</header><text display-inline="no-display-inline">Title II of the Homeland Security Act of
			 2002 (6 U.S.C. 121 et seq.) is amended by adding at the end the
			 following:</text>
				<quoted-block display-inline="no-display-inline" id="id187E9CE4A0304D8CBDBC2F50BCEAFB23" style="OLC">
					<subtitle id="idB3D24B1FCBA246FDB68631AA0603CD9F"><enum>E</enum><header>Cybersecurity</header>
						<section id="id1E279600464842C9B55CADFF8FDCA5D0"><enum>241.</enum><header>Definitions</header><text display-inline="no-display-inline">In this subtitle—</text>
							<paragraph id="IDe3cb41e9df314689a06badb278028f61"><enum>(1)</enum><text>the term
				<term>agency information infrastructure</term> means the Federal information
				infrastructure of a particular Federal agency;</text>
							</paragraph><paragraph id="ID45b22b47b40e4079b9035f267bdca2e3"><enum>(2)</enum><text>the term
				<term>appropriate committees of Congress</term> means the Committee on Homeland
				Security and Governmental Affairs of the Senate and the Committee on Homeland
				Security of the House of Representatives;</text>
							</paragraph><paragraph id="IDf43c5d3a821d48f78351b708f0f1cf34"><enum>(3)</enum><text>the term
				<term>Center</term> means the National Center for Cybersecurity and
				Communications established under section 242(a);</text>
							</paragraph><paragraph id="ID06be710a57b14ee984514909d6b90fc1"><enum>(4)</enum><text>the term
				<term>covered critical infrastructure</term> means a system or asset identified
				by the Secretary as covered critical infrastructure under section 254;</text>
							</paragraph><paragraph id="ID5e5f7c17320348f0808a55e34a977c5e"><enum>(5)</enum><text>the term
				<term>cyber risk</term> means any risk to information infrastructure, including
				physical or personnel risks and security vulnerabilities, that, if exploited or
				not mitigated, could pose a significant risk of disruption to the operation of
				information infrastructure essential to the reliable operation of covered
				critical infrastructure;</text>
							</paragraph><paragraph id="IDa25f110fc0884d9e9efc3d4ecee09ee5"><enum>(6)</enum><text>the term
				<term>Director</term> means the Director of the Center appointed under section
				242(b)(1);</text>
							</paragraph><paragraph id="ID66fb8e2d29f14dc59ca0a432401eacad"><enum>(7)</enum><text>the term
				<term>Federal agency</term>—</text>
								<subparagraph id="ID048ef7392a5e4e4ab2ef43dd12107bf1"><enum>(A)</enum><text>means any
				executive department, military department, Government corporation, Government
				controlled corporation, or other establishment in the executive branch of the
				Government (including the Executive Office of the President), or any
				independent regulatory agency; and</text>
								</subparagraph><subparagraph id="ID05b5a4a5905f4245927cfc34035ed525"><enum>(B)</enum><text>does not include
				the governments of the District of Columbia and of the territories and
				possessions of the United States and their various subdivisions;</text>
								</subparagraph></paragraph><paragraph id="IDfdbb3640f6624c6d993e1010d2d2d066"><enum>(8)</enum><text>the term
				<term>Federal information infrastructure</term>—</text>
								<subparagraph id="id2AEB65E29B594ED8BF2CCC48BD2A9597"><enum>(A)</enum><text>means information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, any Federal agency, including information systems used or
				operated by another entity on behalf of a Federal agency; and</text>
								</subparagraph><subparagraph id="id7D84F41C9F3840C89242946941B9E26B"><enum>(B)</enum><text>does not
				include—</text>
									<clause id="idA70F986E50E04A1B8DCB2534E5AB5C0E"><enum>(i)</enum><text>a
				national security system; or</text>
									</clause><clause id="id4CE79C93A40D4A5C98FF5EF302D4FE92"><enum>(ii)</enum><text>information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, the Department of Defense, a military department, or another
				element of the intelligence community;</text>
									</clause></subparagraph></paragraph><paragraph commented="no" id="id59A7550D0B484F5AA2153DDB60598BB7"><enum>(9)</enum><text>the term
				<term>incident</term> has the meaning given that term in section 3551 of title
				44, United States Code;</text>
							</paragraph><paragraph id="id3A37B86154B242619F412CEF2EB73B40"><enum>(10)</enum><text>the term
				<term>information infrastructure</term> means the underlying framework that
				information systems and assets rely on to process, transmit, receive, or store
				information electronically, including—</text>
								<subparagraph id="id785D572B09524882BB82D04A7A22A70B"><enum>(A)</enum><text>programmable
				electronic devices and communications networks; and</text>
								</subparagraph><subparagraph id="id7D37236972DE40D98760EEBA032BE279"><enum>(B)</enum><text>any associated
				hardware, software, or data;</text>
								</subparagraph></paragraph><paragraph id="IDe4abd9a421324151931e06b0adf28999"><enum>(11)</enum><text>the term
				<term>information security</term> means protecting information and information
				systems from disruption or unauthorized access, use, disclosure, modification,
				or destruction in order to provide—</text>
								<subparagraph id="IDc50c7f6cf6134f10ac6fac50e62a427e"><enum>(A)</enum><text>integrity, by
				guarding against improper information modification or destruction, including by
				ensuring information nonrepudiation and authenticity;</text>
								</subparagraph><subparagraph id="IDedb3d682203d4f4194bc04d5058be1ff"><enum>(B)</enum><text>confidentiality,
				by preserving authorized restrictions on access and disclosure, including means
				for protecting personal privacy and proprietary information; and</text>
								</subparagraph><subparagraph id="ID6963b415177f4c479515af0923c24e97"><enum>(C)</enum><text>availability, by
				ensuring timely and reliable access to and use of information;</text>
								</subparagraph></paragraph><paragraph id="ID70c27d9b21f946d3b4f3a2d56157a93a"><enum>(12)</enum><text>the term
				<term>information sharing and analysis center</term> means a self-governed
				forum whose members work together within a specific sector of critical
				infrastructure to identify, analyze, and share with other members and the
				Federal Government critical information relating to threats, vulnerabilities,
				or incidents to the security and resiliency of the critical infrastructure that
				comprises the specific sector;</text>
							</paragraph><paragraph commented="no" id="idD33DE4DC9A28442A80539032F55DA8EC"><enum>(13)</enum><text>the term
				<term>information system</term> has the meaning given that term in section 3502
				of title 44, United States Code;</text>
							</paragraph><paragraph id="IDba303972d33d4cc9a6c33ac439bc9b64"><enum>(14)</enum><text>the term
				<term>intelligence community</term> has the meaning given that term in section
				3(4) of the National Security Act of 1947 (50 U.S.C. 401a(4));</text>
							</paragraph><paragraph commented="no" id="ID70d65f09c1b141238eb3c394c0e3cea5"><enum>(15)</enum><text>the term
				<term>management controls</term> means safeguards or countermeasures for an
				information system that focus on the management of risk and the management of
				information system security;</text>
							</paragraph><paragraph id="IDd4adedf65880495e98570fa444abba47"><enum>(16)</enum><text>the term
				<term>National Cybersecurity Advisory Council</term> means the National
				Cybersecurity Advisory Council established under section 239;</text>
							</paragraph><paragraph id="idA3869E3E837B4A7E8D254F5FF9FB6295"><enum>(17)</enum><text>the term
				<term>national cyber emergency</term> means an actual or imminent action by any
				individual or entity to exploit a cyber risk in a manner that disrupts,
				attempts to disrupt, or poses a significant risk of disruption to the operation
				of the information infrastructure essential to the reliable operation of
				covered critical infrastructure;</text>
							</paragraph><paragraph id="ID9d1796ae5f2343bfbefee68036b7ff40"><enum>(18)</enum><text>the term
				<term>national information infrastructure</term> means information
				infrastructure—</text>
								<subparagraph id="IDde45b231633a469cb48532cab0dd3e10"><enum>(A)</enum><text>that is owned,
				operated, or controlled within or from the United States; and</text>
								</subparagraph><subparagraph id="id42E2469390C04156BE46580A424B2873"><enum>(B)</enum><text>that is not
				owned, operated, controlled, or licensed for use by a Federal agency;</text>
								</subparagraph></paragraph><paragraph id="id4B69F8EABC474DB3989393D914D0E626"><enum>(19)</enum><text>the term
				<term>national security system</term> has the meaning given that term in
				section 3551 of title 44, United States Code;</text>
							</paragraph><paragraph id="ID07953588dca24c9ca2800cd110a1f395"><enum>(20)</enum><text>the term
				<term>operational controls</term> means the safeguards and countermeasures for
				an information system that are primarily implemented and executed by
				individuals not systems;</text>
							</paragraph><paragraph id="IDb9bebc69affe4f05a4f7d65c26e5d530"><enum>(21)</enum><text>the term
				<term>sector-specific agency</term> means the relevant Federal agency
				responsible for infrastructure protection activities in a designated critical
				infrastructure sector or key resources category under the National
				Infrastructure Protection Plan, or any other appropriate Federal agency
				identified by the President after the date of enactment of this
				subtitle;</text>
							</paragraph><paragraph commented="no" id="idCF58C95D7546460D986C41DDA11CC7AC"><enum>(22)</enum><text>the term
				<term>sector coordinating councils</term> means self-governed councils that are
				composed of representatives of key stakeholders within a specific sector of
				critical infrastructure that serve as the principal private sector policy
				coordination and planning entities with the Federal Government relating to the
				security and resiliency of the critical infrastructure that comprise that
				sector;</text>
							</paragraph><paragraph id="ID7f4001cd6fc543feaa7c2842a223dc4d"><enum>(23)</enum><text>the term
				<term>security controls</term> means the management, operational, and technical
				controls prescribed for an information system to protect the information
				security of the system;</text>
							</paragraph><paragraph id="IDb550c41b96ef4ca0bb3ef8735a029035"><enum>(24)</enum><text>the term
				<term>small business concern</term> has the meaning given that term under
				section 3 of the Small Business Act (15 U.S.C. 632);</text>
							</paragraph><paragraph id="ID14b1db30cffd4913bef57aaf0cb40233"><enum>(25)</enum><text>the term
				<term>technical controls</term> means the safeguards or countermeasures for an
				information system that are primarily implemented and executed by the
				information system through mechanisms contained in the hardware, software, or
				firmware components of the system;</text>
							</paragraph><paragraph id="ID997b1112107b4499a3d9c48ce628dbda"><enum>(26)</enum><text>the term
				<term>terrorism information</term> has the meaning given that term in section
				1016 of the Intelligence Reform and Terrorism Prevention Act of 2004 (6 U.S.C.
				485);</text>
							</paragraph><paragraph id="ID84a659aa4fb84562992065b16bb0c8e5"><enum>(27)</enum><text>the term
				<term>United States person</term> has the meaning given that term in section
				101 of the Foreign Intelligence Surveillance Act of 1978 (50 U.S.C. 1801);
				and</text>
							</paragraph><paragraph id="ID9f02d117c2f24f2ca3e2cf54e6db8a05"><enum>(28)</enum><text>the term
				<term>US–CERT</term> means the United States Computer Emergency Readiness Team
				established under section 244.</text>
							</paragraph></section><section id="IDf6b7d2881b9e4f02aa9f77f4ac2d4880"><enum>242.</enum><header>National
				Center for Cybersecurity and Communications</header>
							<subsection id="IDeabbad22809046aeb4bb79672b30f59c"><enum>(a)</enum><header>Establishment</header>
								<paragraph id="ID5eaea1e7659c4b03b70ca13ecb82cbd1"><enum>(1)</enum><header>In
				general</header><text>There is established within the Department a National
				Center for Cybersecurity and Communications.</text>
								</paragraph><paragraph id="ID2067184a447f4649bcc9af37efbd6a7f"><enum>(2)</enum><header>Operational
				entity</header><text>The Center may—</text>
									<subparagraph id="ID1603730aa3fe48faafd8b0a390ad0a26"><enum>(A)</enum><text>enter into
				contracts for the procurement of property and services for the Center;
				and</text>
									</subparagraph><subparagraph id="ID7332e1d4b86a46f387eee38dbf97088c"><enum>(B)</enum><text>appoint employees
				of the Center in accordance with the civil service laws of the United
				States.</text>
									</subparagraph></paragraph></subsection><subsection id="idD68E4211862F4F7E9484A7A6FE14EB66"><enum>(b)</enum><header>Director</header>
								<paragraph id="ID1d0fa8135d7948ae827af81c6a93fc47"><enum>(1)</enum><header>In
				general</header><text>The Center shall be headed by a Director, who shall be
				appointed by the President, by and with the advice and consent of the
				Senate.</text>
								</paragraph><paragraph id="id7E3F1EBADDDA409BBCA557CEA92ADB3B"><enum>(2)</enum><header>Reporting to
				Secretary</header><text>The Director shall report directly to the Secretary and
				serve as the principal advisor to the Secretary on cybersecurity and the
				operations, security, and resiliency of the information infrastructure and
				communications infrastructure of the United States.</text>
								</paragraph><paragraph id="ID6a0b29c3970c4aab918f579d4b1f7583"><enum>(3)</enum><header>Presidential
				advice</header><text>The Director shall regularly advise the President on the
				exercise of the authorities provided under this subtitle or any other provision
				of law relating to the security of the Federal information infrastructure or an
				agency information infrastructure.</text>
								</paragraph><paragraph id="ID393dac9f414745f980f55a36e84ce18a"><enum>(4)</enum><header>Qualifications</header><text>The
				Director shall be appointed from among individuals who have—</text>
									<subparagraph id="IDad106b2a635c43f2bef81c11b57b901a"><enum>(A)</enum><text>a demonstrated
				ability in and knowledge of information technology, cybersecurity, and the
				operations, security and resiliency of communications networks; and</text>
									</subparagraph><subparagraph id="ID6bbf79f57f3f44cd9415bf1c628340a4"><enum>(B)</enum><text>significant
				executive leadership and management experience in the public or private
				sector.</text>
									</subparagraph></paragraph><paragraph id="IDaabbf1a5347d44ea86b190986feb85b3"><enum>(5)</enum><header>Limitation on
				service</header>
									<subparagraph id="IDa510cd4a90c24b61a9e2fdccdb1eb0c5"><enum>(A)</enum><header>In
				general</header><text>Subject to subparagraph (B), the individual serving as
				the Director may not, while so serving, serve in any other capacity in the
				Federal Government, except to the extent that the individual serving as
				Director is doing so in an acting capacity.</text>
									</subparagraph><subparagraph id="ID3464b38c077845b79549c81fda8bd123"><enum>(B)</enum><header>Exception</header><text>The
				Director may serve on any commission, board, council, or similar entity with
				responsibilities or duties relating to cybersecurity or the operations,
				security, and resiliency of the information infrastructure and communications
				infrastructure of the United States at the direction of the President or as
				otherwise provided by law.</text>
									</subparagraph></paragraph></subsection><subsection id="ID448baf944fa64d1d988f74d12cda922f"><enum>(c)</enum><header>Deputy
				Directors</header>
								<paragraph id="ID2a10ae132efa4f6bb6a7747ff4f57546"><enum>(1)</enum><header>In
				general</header><text>There shall be not less than 2 Deputy Directors for the
				Center, who shall report to the Director.</text>
								</paragraph><paragraph id="IDaafb1a69e4334aed944654a38611bc4c"><enum>(2)</enum><header>Infrastructure
				protection</header>
									<subparagraph id="ID33b7cb88ded44cacac5560a9d690d7cd"><enum>(A)</enum><header>Appointment</header><text>There
				shall be a Deputy Director appointed by the Secretary, who shall have expertise
				in infrastructure protection.</text>
									</subparagraph><subparagraph commented="no" id="ID4eee7281f33d4fbeb0b944d3b8821a01"><enum>(B)</enum><header>Responsibilities</header><text>The
				Deputy Director appointed under subparagraph (A) shall—</text>
										<clause commented="no" id="ID843f87e52b5f4db8aefe27a0a128f7af"><enum>(i)</enum><text>assist the
				Director and the Assistant Secretary for Infrastructure Protection in
				coordinating, managing, and directing the information, communications, and
				physical infrastructure protection responsibilities and activities of the
				Department, including activities under Homeland Security Presidential
				Directive–7, or any successor thereto, and the National Infrastructure
				Protection Plan, or any successor thereto;</text>
										</clause><clause commented="no" id="ID4fd2bbd2b9354dedb37fb64d5d4d2396"><enum>(ii)</enum><text>review the
				budget for the Center and the Office of Infrastructure Protection before
				submission of the budget to the Secretary to ensure that activities are
				appropriately coordinated;</text>
										</clause><clause commented="no" id="IDecafef8b8fd547c29403e2995253bccf"><enum>(iii)</enum><text>develop, update
				periodically, and submit to the appropriate committees of Congress a strategic
				plan detailing how critical infrastructure protection activities will be
				coordinated between the Center, the Office of Infrastructure Protection, and
				the private sector;</text>
										</clause><clause commented="no" id="ID47c54998a0b44805995d1e9ebd076206"><enum>(iv)</enum><text>subject to the
				direction of the Director resolve conflicts between the Center and the Office
				of Infrastructure Protection relating to the information, communications, and
				physical infrastructure protection responsibilities of the Center and the
				Office of Infrastructure Protection; and</text>
										</clause><clause id="ID7801fa397cef4975bb0535bbfc36b509"><enum>(v)</enum><text>perform such
				other duties as the Director may assign.</text>
										</clause></subparagraph><subparagraph id="IDab918264561948038e2e4a6a628d2884"><enum>(C)</enum><header>Annual
				evaluation</header><text>The Assistant Secretary for Infrastructure Protection
				shall submit annually to the Director an evaluation of the performance of the
				Deputy Director appointed under subparagraph (A).</text>
									</subparagraph></paragraph><paragraph id="ID14b50a71492f4eeeab37d83010e7f904"><enum>(3)</enum><header>Intelligence
				community</header><text>The Director of National Intelligence shall identify an
				employee of an element of the intelligence community to serve as a Deputy
				Director of the Center. The employee shall be detailed to the Center on a
				reimbursable basis for such period as is agreed to by the Director and the
				Director of National Intelligence, and, while serving as Deputy Director, shall
				report directly to the Director of the Center.</text>
								</paragraph></subsection><subsection id="ID1562f73c6b10458bb3a44e69505a240a"><enum>(d)</enum><header>Liaison
				officers</header>
								<paragraph id="idAD75C8FD4C6D4FDCB730132AA093796A"><enum>(1)</enum><header>In
				general</header><text>The Secretary of Defense, the Attorney General, the
				Secretary of Commerce, and the Director of National Intelligence shall detail
				personnel to the Center to act as full-time liaisons with the Department of
				Defense, the Department of Justice, the National Institute of Standards and
				Technology, and elements of the intelligence community to assist in
				coordination between and among the Center, the Department of Defense, the
				Department of Justice, the National Institute of Standards and Technology, and
				elements of the intelligence community.</text>
								</paragraph><paragraph id="ID1104bc253e654256be62747b229e675b"><enum>(2)</enum><header>Private
				sector</header>
									<subparagraph id="id819939BD882D4CB1AEC88A9FE6D10ABB"><enum>(A)</enum><header>In
				general</header><text>Consistent with applicable law and ethics requirements,
				and except as provided in subparagraph (B), the Director may authorize
				representatives from private sector entities to participate in the activities
				of the Center to improve the information sharing, analysis, and coordination of
				activities of the US–CERT.</text>
									</subparagraph><subparagraph id="id9D4B16FF828D43DD890A5C558F9C713D"><enum>(B)</enum><header>Limitation</header><text>A
				representative from a private sector entity authorized to participate in the
				activities of the Center under subparagraph (A) may not participate in any
				activities of the Center under section 248, 249, or 250.</text>
									</subparagraph></paragraph></subsection><subsection id="ID43ba004819da4f2e8dbc365f86b37dc8"><enum>(e)</enum><header>Privacy
				officer</header>
								<paragraph id="id678D1B915A8C414D883C45ED5B57630D"><enum>(1)</enum><header>In
				general</header><text>The Director, in consultation with the Secretary, shall
				designate a full-time privacy officer, who shall report to the Director.</text>
								</paragraph><paragraph id="idF869BE81B6EB42A3BAE557A61829E72C"><enum>(2)</enum><header>Duties</header><text>The
				privacy officer designated under paragraph (1) shall have primary
				responsibility for implementation by the Center of the privacy policy for the
				Department established by the Privacy Officer appointed under section
				222.</text>
								</paragraph></subsection><subsection id="IDd28fa2e16f3a43099d58d702cd8aa2f2"><enum>(f)</enum><header>Duties of
				Director</header>
								<paragraph id="idA749182719E84C77A113BCFFF1DBC6CE"><enum>(1)</enum><header>In
				general</header><text>The Director shall—</text>
									<subparagraph id="ID88ab419b56db4c7a8548cb394843a132"><enum>(A)</enum><text>working
				cooperatively with the private sector, lead the Federal effort to secure,
				protect, and ensure the resiliency of the Federal information infrastructure,
				national information infrastructure, and communications infrastructure of the
				United States, including communications networks;</text>
									</subparagraph><subparagraph id="ID867d7f0daf814572aa52724a4ec31894"><enum>(B)</enum><text>assist in the
				identification, remediation, and mitigation of vulnerabilities to the Federal
				information infrastructure and the national information infrastructure;</text>
									</subparagraph><subparagraph id="idC869F448D8CB491C8CC3C9304A5F642D"><enum>(C)</enum><text>provide dynamic,
				comprehensive, and continuous situational awareness of the security status of
				the Federal information infrastructure, national information infrastructure,
				information infrastructure that is owned, operated, controlled, or licensed for
				use by, or on behalf of, the Department of Defense, a military department, or
				another element of the intelligence community, and information infrastructure
				located outside the United States the disruption of which could result in
				national or regional catastrophic damage in the United States by sharing and
				integrating classified and unclassified information, including information
				relating to threats, vulnerabilities, traffic, trends, incidents, and other
				anomalous activities affecting the infrastructure or systems, on a routine and
				continuous basis with—</text>
										<clause id="ID893bb294097f4d04809dd8755915b8c5"><enum>(i)</enum><text>the National
				Threat Operations Center of the National Security Agency;</text>
										</clause><clause id="IDe87c580957124855af14ec4d2121ba46"><enum>(ii)</enum><text>the United
				States Cyber Command, including the Joint Task Force-Global Network
				Operations;</text>
										</clause><clause id="ID67e6bcad3135454dbf2e04ef7f22366c"><enum>(iii)</enum><text>the Cyber Crime
				Center of the Department of Defense;</text>
										</clause><clause id="IDa8393ce13c27463e9da9220de6ac73c9"><enum>(iv)</enum><text>the National
				Cyber Investigative Joint Task Force;</text>
										</clause><clause id="IDc3d499d5a30b4c96b20baa868f066477"><enum>(v)</enum><text>the Intelligence
				Community Incident Response Center;</text>
										</clause><clause id="ID3b215d5620a945edbec93528409d2aa8"><enum>(vi)</enum><text>any other
				Federal agency, or component thereof, identified by the Director; and</text>
										</clause><clause id="IDcaed24a7c3774ed89bb5ab5f06872962"><enum>(vii)</enum><text>any non-Federal
				entity, including, where appropriate, information sharing and analysis centers,
				identified by the Director, with the concurrence of the owner or operator of
				that entity and consistent with applicable law;</text>
										</clause></subparagraph><subparagraph id="ID27587333bc9848c284916709927a0fd4"><enum>(D)</enum><text>work with the
				entities described in subparagraph (C) to establish policies and procedures
				that enable information sharing between and among the entities;</text>
									</subparagraph><subparagraph id="ID2a268e0efe56438fbc5c113f8ebc8244"><enum>(E)</enum><clause commented="no" display-inline="yes-display-inline" id="id01E5552A19FD4F9C9A679B79426D9B12"><enum>(i)</enum><text>develop, in
				coordination with the Assistant Secretary for Infrastructure Protection, other
				Federal agencies, the private sector, and State and local governments, a
				national incident response plan that details the roles of Federal agencies,
				State and local governments, and the private sector, including plans to be
				executed in response to a declaration of a national cyber emergency by the
				President under section 249; and</text>
										</clause><clause id="idAA77114C28FE4EE7A52A514CF953277F" indent="up1"><enum>(ii)</enum><text>establish mechanisms for assisting
				owners or operators of critical infrastructure, including covered critical
				infrastructure, in the deployment of emergency measures or other actions,
				including measures to restore the critical infrastructure in the event of the
				destruction or a serious disruption of the critical infrastructure;</text>
										</clause></subparagraph><subparagraph id="IDffd934c822594d098fd5adb85cb6d307"><enum>(F)</enum><text>conduct
				risk-based assessments of the Federal information infrastructure with respect
				to acts of terrorism, natural disasters, and other large-scale disruptions and
				provide the results of the assessments to the Director of Cyberspace Policy and
				to affected Federal agencies;</text>
									</subparagraph><subparagraph id="IDc13ddc59c46a4312afec5f2b97558d78"><enum>(G)</enum><text>develop, oversee
				the implementation of, and enforce policies, principles, and guidelines on
				information security for the Federal information infrastructure, including
				timely adoption of and compliance with standards developed by the National
				Institute of Standards and Technology under section 20 of the National
				Institute of Standards and Technology Act (15 U.S.C. 278g–3);</text>
									</subparagraph><subparagraph id="id9EF5CC492A5A40ABAC845A9C311FA1B8"><enum>(H)</enum><text>provide
				assistance to the National Institute of Standards and Technology in developing
				standards under section 20 of the National Institute of Standards and
				Technology Act (15 U.S.C. 278g–3);</text>
									</subparagraph><subparagraph id="IDcc938ab9410b42eda20124e5e4143a8a"><enum>(I)</enum><text>provide to
				Federal agencies mandatory security controls to mitigate and remediate
				vulnerabilities of and incidents affecting the Federal information
				infrastructure;</text>
									</subparagraph><subparagraph id="ID68b7451f9c144aac8406f3c98e1a4b35"><enum>(J)</enum><text>subject to
				paragraph (2), and as needed, assist the Director of the Office of Management
				and Budget and the Director of Cyberspace Policy in conducting analysis and
				prioritization of budgets, resources, and policies relating to the security of
				the Federal information infrastructure;</text>
									</subparagraph><subparagraph id="ID6991b94c2fa14a4090763344bd6d7e56"><enum>(K)</enum><text>in accordance
				with section 253, develop, periodically update, and implement a supply chain
				risk management strategy to enhance, in a risk-based and cost-effective manner,
				the security of the communications and information technology products and
				services purchased by the Federal Government;</text>
									</subparagraph><subparagraph id="ID0fa954292d41494d9b13aeaae11f242b"><enum>(L)</enum><text>notify the
				Director of Cyberspace Policy of any incident involving the Federal information
				infrastructure, information infrastructure that is owned, operated, controlled,
				or licensed for use by, or on behalf of, the Department of Defense, a military
				department, or another element of the intelligence community, or the national
				information infrastructure that could compromise or significantly affect
				economic or national security;</text>
									</subparagraph><subparagraph id="ID1ea07445fc4e45cbba45c919240103ec"><enum>(M)</enum><text>consult, in
				coordination with the Director of Cyberspace Policy, with appropriate
				international partners to enhance the security of the Federal information
				infrastructure, national information infrastructure, and information
				infrastructure located outside the United States the disruption of which could
				result in national or regional catastrophic damage in the United States;</text>
									</subparagraph><subparagraph id="ID8a1e6d5970e4464dba609b56ceb7514a"><enum>(N)</enum><clause commented="no" display-inline="yes-display-inline" id="id7FF3D3F64A9649CEB5F6AA25BB9ECD5E"><enum>(i)</enum><text>coordinate and
				integrate information to analyze the composite security state of the Federal
				information infrastructure and information infrastructure that is owned,
				operated, controlled, or licensed for use by, or on behalf of, the Department
				of Defense, a military department, or another element of the intelligence
				community;</text>
										</clause><clause id="ID11a4bcf4bfdc4059b9f3522dd05cd7d3" indent="up1"><enum>(ii)</enum><text>ensure the information required
				under clause (i) and section 3553(c)(1)(A) of title 44, United States Code,
				including the views of the Director on the adequacy and effectiveness of
				information security throughout the Federal information infrastructure and
				information infrastructure that is owned, operated, controlled, or licensed for
				use by, or on behalf of, the Department of Defense, a military department, or
				another element of the intelligence community, is available on an automated and
				continuous basis through the system maintained under section 3552(a)(3)(D) of
				title 44, United States Code;</text>
										</clause><clause id="ID623c2dce27f141969396cf851f38cce8" indent="up1"><enum>(iii)</enum><text>in conjunction with the
				quadrennial homeland security review required under section 707, and at such
				other times determined appropriate by the Director, analyze the composite
				security state of the national information infrastructure and submit to the
				President, Congress, and the Secretary a report regarding actions necessary to
				enhance the composite security state of the national information infrastructure
				based on the analysis; and</text>
										</clause><clause id="IDceefc2d7c17e41848e867c1d22253e11" indent="up1"><enum>(iv)</enum><text>foster collaboration and serve as
				the primary contact between the Federal Government, State and local
				governments, and private entities on matters relating to the security of the
				Federal information infrastructure and the national information
				infrastructure;</text>
										</clause></subparagraph><subparagraph id="ID2e0b4d55e9d8461e965cc45d927c9900"><enum>(O)</enum><text>oversee the
				development, implementation, and management of security requirements for
				Federal agencies relating to the external access points to or from the Federal
				information infrastructure;</text>
									</subparagraph><subparagraph id="id934E86D4ADF3439E9B6F6EE3AF3B6018"><enum>(P)</enum><text>establish,
				develop, and oversee the capabilities and operations within the US–CERT as
				required by section 244;</text>
									</subparagraph><subparagraph id="id03241982EB3547E4B61120B6E0516707"><enum>(Q)</enum><text>oversee the
				operations of the National Communications System, as described in Executive
				Order 12472 (49 Fed. Reg. 13471; relating to the assignment of national
				security and emergency preparedness telecommunications functions), as amended
				by Executive Order 13286 (68 Fed. Reg. 10619) and Executive Order 13407 (71
				Fed. Reg. 36975), or any successor thereto, including planning for and
				providing communications for the Federal Government under all circumstances,
				including crises, emergencies, attacks, recoveries, and reconstitutions;</text>
									</subparagraph><subparagraph id="IDbb3d210b43094cc7bea8c07b86a6312b"><enum>(R)</enum><text>ensure, in
				coordination with the privacy officer designated under subsection (e), the
				Privacy Officer appointed under section 222, and the Director of the Office of
				Civil Rights and Civil Liberties appointed under section 705, that the
				activities of the Center comply with all policies, regulations, and laws
				protecting the privacy and civil liberties of United States persons;</text>
									</subparagraph><subparagraph id="IDbdb96d0a0c4a4635a9ce8c7f68dbdcdf"><enum>(S)</enum><text>subject to the
				availability of resources, in accordance with applicable law relating to the
				protection of trade secrets, and at the discretion of the Director, provide
				voluntary technical assistance—</text>
										<clause id="ID51890c3ac3f641f2a1a9546096e9e90f"><enum>(i)</enum><text>at the request of
				an owner or operator of covered critical infrastructure, to assist the owner or
				operator in complying with sections 248 and 249, including implementing
				required security or emergency measures and developing response plans for
				national cyber emergencies declared under section 249; and</text>
										</clause><clause id="IDd0cf11469d97442bafd5f0306800b97a"><enum>(ii)</enum><text>at the request
				of the owner or operator of national information infrastructure that is not
				covered critical infrastructure, and based on risk, to assist the owner or
				operator in implementing best practices, and related standards and guidelines,
				recommended under section 247 and other measures necessary to mitigate or
				remediate vulnerabilities of the information infrastructure and the
				consequences of efforts to exploit the vulnerabilities;</text>
										</clause></subparagraph><subparagraph id="id28B8CF7638E84380BE0BC8932980A7F0"><enum>(T)</enum><clause commented="no" display-inline="yes-display-inline" id="id7053D58BADA24BBA881EE9A13C0B79CB"><enum>(i)</enum><text>conduct, in
				consultation with the National Cybersecurity Advisory Council, the head of
				appropriate sector-specific agencies, and any private sector entity determined
				appropriate by the Director, risk-based assessments of national information
				infrastructure and information infrastructure located outside the United States
				the disruption of which could result in national or regional catastrophic
				damage in the United States, on a sector-by-sector basis, with respect to acts
				of terrorism, natural disasters, and other large-scale disruptions or financial
				harm, which shall identify and prioritize risks to the national information
				infrastructure and information infrastructure located outside the United States
				the disruption of which could result in national or regional catastrophic
				damage in the United States, including vulnerabilities and associated
				consequences; and</text>
										</clause><clause id="id20A76C96070849A48C637FC683CCEE68" indent="up1"><enum>(ii)</enum><text>coordinate and evaluate the
				mitigation or remediation of vulnerabilities and consequences identified under
				clause (i);</text>
										</clause></subparagraph><subparagraph id="ID10265c9539c64cfd974cc2d8e6bb604e"><enum>(U)</enum><text>regularly
				evaluate and assess technologies designed to enhance the protection of the
				Federal information infrastructure and national information infrastructure,
				including an assessment of the cost-effectiveness of the technologies;</text>
									</subparagraph><subparagraph id="ID65c4509d6dd54b4ba9ff73ea62ebbb8b"><enum>(V)</enum><text>promote the use
				of the best practices recommended under section 247 to State and local
				governments and the private sector;</text>
									</subparagraph><subparagraph id="ID07d8424a2941443e9364e28f0f743cd7"><enum>(W)</enum><text>develop and
				implement outreach and awareness programs on cybersecurity, including—</text>
										<clause id="id1CB5F19767DC40F29E13BF9A3F4A7436"><enum>(i)</enum><text>a
				public education campaign to increase the awareness of cybersecurity, cyber
				safety, and cyber ethics, which shall include use of the Internet, social
				media, entertainment, and other media to reach the public;</text>
										</clause><clause id="ID6684200a3f2e40ff9ef7b5e84eeffbb6"><enum>(ii)</enum><text>an education
				campaign to increase the understanding of State and local governments and
				private sector entities of the costs of failing to ensure effective security of
				information infrastructure and cost-effective methods to mitigate and remediate
				vulnerabilities; and</text>
										</clause><clause id="idB39BC40B98FA40BE83C0F08C25AECB78"><enum>(iii)</enum><text>outcome-based
				performance measures to determine the success of the programs;</text>
										</clause></subparagraph><subparagraph id="ID625e7c7ee30744a9839947e9ee2a0b14"><enum>(X)</enum><text>develop and
				implement a national cybersecurity exercise program that includes—</text>
										<clause id="IDbbee5b4a44814b4c9ed2e14b327d5f45"><enum>(i)</enum><text>the participation
				of State and local governments, international partners of the United States,
				and the private sector;</text>
										</clause><clause id="IDa4ffc0cfd80d449fbff88aaa28671b50"><enum>(ii)</enum><text>an after action
				report analyzing lessons learned from exercises and identifying vulnerabilities
				to be remediated or mitigated; and</text>
										</clause><clause id="ID3446a9c3dfb6452192502e146604965e"><enum>(iii)</enum><text>oversight, in
				coordination with the Director of the Office of Cyberspace Policy, of the
				efforts by Federal agencies to address deficiencies identified in the after
				action reports required under clause (ii);</text>
										</clause></subparagraph><subparagraph id="id55A6154769474B7DB9EEFCD243AC2666"><enum>(Y)</enum><text>coordinate with
				the Assistant Secretary for Infrastructure Protection to ensure that—</text>
										<clause id="idF808EEBA8E554250B0106BEB800372CA"><enum>(i)</enum><text>cybersecurity is
				appropriately addressed in carrying out the infrastructure protection
				responsibilities described in section 201(d); and</text>
										</clause><clause id="id22B00F713EF34A158BB84ADF7B3B4C17"><enum>(ii)</enum><text>the operations
				of the Center and the Office of Infrastructure Protection avoid duplication and
				use, to the maximum extent practicable, joint mechanisms for information
				sharing and coordination with the private sector;</text>
										</clause></subparagraph><subparagraph id="IDc21226f90e444df2987d06872de6454e"><enum>(Z)</enum><text>oversee the
				activities of the Office of Emergency Communications established under section
				1801;</text>
									</subparagraph><subparagraph id="ID0dab0dd7e8954f5b9dd18d32e329128b"><enum>(AA)</enum><text>in coordination
				with the Director of the Office of Cyberspace Policy and the heads of relevant
				Federal agencies, develop and implement an identity management strategy for
				cyberspace, which shall include, at a minimum, research and development goals,
				an analysis of appropriate protections for privacy and civil liberties, and
				mechanisms to develop and disseminate best practices and standards relating to
				identity management, including usability and transparency; and</text>
									</subparagraph><subparagraph id="ID1a9bc7b6e7764f05a8a8063a50047bdb"><enum>(BB)</enum><text>perform such
				other duties as the Secretary may direct relating to the security and
				resiliency of the information and communications infrastructure of the United
				States.</text>
									</subparagraph></paragraph><paragraph id="ID6f7a11a0e31543e4afc6ab92dbaa3760"><enum>(2)</enum><header>Budget
				analysis</header><text>In conducting analysis and prioritization of budgets
				under paragraph (1)(J), the Director—</text>
									<subparagraph id="ID3c8c2bc1bb8e46ca9d30eff17a93690a"><enum>(A)</enum><text>in coordination
				with the Director of the Office of Management and Budget, may access
				information from any Federal agency regarding the finances, budget, and
				programs of the Federal agency relevant to the security of the Federal
				information infrastructure;</text>
									</subparagraph><subparagraph id="ID45de313c148c4794b6b6307703284a4f"><enum>(B)</enum><text>may make
				recommendations to the Director of the Office of Management and Budget and the
				Director of Cyberspace Policy regarding the budget for each Federal agency to
				ensure that adequate funding is devoted to securing the Federal information
				infrastructure, in accordance with policies, principles, and guidelines
				established by the Director under this subtitle; and</text>
									</subparagraph><subparagraph id="IDfa0ff061cf2343539d75bcef0b0131f3"><enum>(C)</enum><text>shall provide
				copies of any recommendations made under subparagraph (B) to—</text>
										<clause id="IDfaedbb0686c0492aa46401ade26717aa"><enum>(i)</enum><text>the Committee on
				Appropriations of the Senate;</text>
										</clause><clause id="ID2a289db89922423da0b4b33465fecf1f"><enum>(ii)</enum><text>the Committee on
				Appropriations of the House of Representatives; and</text>
										</clause><clause id="ID40741b6ef3064b3da4b1b35bba47904b"><enum>(iii)</enum><text>the appropriate
				committees of Congress.</text>
										</clause></subparagraph></paragraph></subsection><subsection id="ID6dedfb157a4e4dc4b91c4280ec71842b"><enum>(g)</enum><header>Use of
				mechanisms for collaboration</header><text>In carrying out the responsibilities
				and authorities of the Director under this subtitle, to the maximum extent
				practicable, the Director shall use mechanisms for collaboration and
				information sharing (including mechanisms relating to the identification and
				communication of threats, vulnerabilities, and associated consequences)
				established by other components of the Department or other Federal agencies to
				avoid unnecessary duplication or waste.</text>
							</subsection><subsection id="IDdf464a3b75404cebaea874d91df91a80"><enum>(h)</enum><header>Sufficiency of
				resources plan</header>
								<paragraph id="ID59d817f1e38f43eeb1a841e7333ff42e"><enum>(1)</enum><header>Report</header><text>Not
				later than 120 days after the date of enactment of this subtitle, the Director
				of the Office of Management and Budget shall submit to the appropriate
				committees of Congress and the Comptroller General of the United States a
				report on the resources and staff necessary to carry out fully the
				responsibilities under this subtitle.</text>
								</paragraph><paragraph id="ID3a1bb57f8122455ba14afe74ea069f6f"><enum>(2)</enum><header>Comptroller
				General review</header>
									<subparagraph id="idA32E92668A0B4245BFC845E4CFCBE3EE"><enum>(A)</enum><header>In
				general</header><text>The Comptroller General of the United States shall
				evaluate the reasonableness and adequacy of the report submitted by the
				Director under paragraph (1).</text>
									</subparagraph><subparagraph id="id46223B464F0F4D1483D7C66C5D23FA8D"><enum>(B)</enum><header>Report</header><text>Not
				later than 60 days after the date on which the report is submitted under
				paragraph (1), the Comptroller General shall submit to the appropriate
				committees of Congress a report containing the findings of the review under
				subparagraph (A).</text>
									</subparagraph></paragraph></subsection><subsection id="ID07c8e9f724574345a95e3601ef3293a0"><enum>(i)</enum><header>Functions
				transferred</header><text>There are transferred to the Center the National
				Cyber Security Division, the Office of Emergency Communications, and the
				National Communications System, including all the functions, personnel, assets,
				authorities, and liabilities of the National Cyber Security Division, the
				Office of Emergency Communications, and the National Communications
				System.</text>
							</subsection><subsection id="IDcb1f10a26f8c488ea096fa74a6c7f772"><enum>(j)</enum><header>Assistant to
				the director for state, local, and private sector outreach</header><text>The
				Director shall identify a senior official in the Center who—</text>
								<paragraph id="idD21662923AC945BF8F705DCA3302229F"><enum>(1)</enum><text>shall report
				directly to the Director; and</text>
								</paragraph><paragraph id="id07D12AE509BC4F17BB63F44B952FD950"><enum>(2)</enum><text>in coordination
				with the Special Assistant to the Secretary appointed under section 102(f),
				shall—</text>
									<subparagraph id="IDe90818dc74594c518ff66129d3f3f6ae"><enum>(A)</enum><text>advise the
				Director on policies and regulations, rules, requirements or other actions
				affecting the private sector, including the economic impact;</text>
									</subparagraph><subparagraph id="IDd6b6cb6c17404d7c9887d0867c32d30a"><enum>(B)</enum><text>work with
				individual businesses and other nongovernmental organizations to foster
				dialogue with the Center;</text>
									</subparagraph><subparagraph id="ID84ad915003ba44a7a603acd424cd2005"><enum>(C)</enum><text>foster
				partnerships and facilitate communication between the Center and State and
				local governments and private sector entities;</text>
									</subparagraph><subparagraph id="ID64ebe73bf18c48d6a71f4bcffcea1e65"><enum>(D)</enum><text>coordinate and
				maintain communication and interaction with State and local governments and
				private sector entities on matters relating to the security of the Federal
				information infrastructure and the national information infrastructure;</text>
									</subparagraph><subparagraph id="ID81333f9785a9409894a4528d71c17267"><enum>(E)</enum><text>assist the
				Director in sharing best practices, guidelines, and other important information
				relating to the policies, goals, and activities of the Center;</text>
									</subparagraph><subparagraph id="ID3f5d656b82e84dd495fc18780553296d"><enum>(F)</enum><text>assist the
				Director in developing and implementing the national cybersecurity exercise
				program under subsection (f)(1)(X) as it relates to State and local governments
				and private sector entities;</text>
									</subparagraph><subparagraph id="ID409cf9de3e914db78c7917f5a9a2d5c3"><enum>(G)</enum><text>assist the
				Director in developing the national incident response plan under subsection
				(f)(1)(E) as it relates to State and local governments and private sector
				entities;</text>
									</subparagraph><subparagraph id="ID351e7f09a5f445dc9d67b10a4aa46c6a"><enum>(H)</enum><text>assist the
				Director in information sharing activities of the Center as it relates to State
				and local governments and private sector entities; and</text>
									</subparagraph><subparagraph id="ID060362f7b98f4a8690f0d8e44dae4083"><enum>(I)</enum><text>perform any other
				duties, as directed by the Director.</text>
									</subparagraph></paragraph></subsection></section><section id="id35D467794B804C8FBFF6A142C0B025DF"><enum>243.</enum><header>Physical and
				cyber infrastructure collaboration</header>
							<subsection id="ID85d67340c4e941a3b539828abe25ccc3"><enum>(a)</enum><header>In
				general</header><text>The Director and the Assistant Secretary for
				Infrastructure Protection shall coordinate the information, communications, and
				physical infrastructure protection responsibilities and activities of the
				Center and the Office of Infrastructure Protection.</text>
							</subsection><subsection id="ID2f522de07773408d82cef7f3b879d7db"><enum>(b)</enum><header>Oversight</header><text>The
				Secretary shall ensure that the coordination described in subsection (a)
				occurs.</text>
							</subsection></section><section id="ID82845397830046c58a2ac43623da495b"><enum>244.</enum><header>United States
				Computer Emergency Readiness Team</header>
							<subsection id="ID6679bb9293a647c2a5a46a571d93366b"><enum>(a)</enum><header>Establishment
				of office</header><text>There is established within the Center, the United
				States Computer Emergency Readiness Team, which shall be headed by a Director,
				who shall be selected from the Senior Executive Service by the
				Secretary.</text>
							</subsection><subsection id="IDbd117ec2ff2848078d0b9b70b0929359"><enum>(b)</enum><header>Responsibilities</header><text>The
				US–CERT shall—</text>
								<paragraph id="id2D57BA9ECF264E538DD35AFFD3803485"><enum>(1)</enum><text>collect,
				coordinate, and disseminate information on—</text>
									<subparagraph id="ID75df899cc3384b3f9fde391705d48408"><enum>(A)</enum><text>risks to the
				Federal information infrastructure, information infrastructure that is owned,
				operated, controlled, or licensed for use by, or on behalf of, the Department
				of Defense, a military department, or another element of the intelligence
				community, or the national information infrastructure; and</text>
									</subparagraph><subparagraph id="IDd3da8e1e7327411b8812d0c35f2e0e54"><enum>(B)</enum><text>security controls
				to enhance the security of the Federal information infrastructure or the
				national information infrastructure against the risks identified in
				subparagraph (A); and</text>
									</subparagraph></paragraph><paragraph id="idE4F23F6AFB844A7AA27334B525F24F0E"><enum>(2)</enum><text>establish a
				mechanism for engagement with the private sector.</text>
								</paragraph></subsection><subsection id="IDbe4bbe8a6a344ca6a898c01d159a661b"><enum>(c)</enum><header>Monitoring,
				analysis, warning, and response</header>
								<paragraph id="ID1bed867a5d1d4aa193979252dc647bb1"><enum>(1)</enum><header>Duties</header><text>Subject
				to paragraph (2), the US–CERT shall—</text>
									<subparagraph id="IDd4c8ab0177684ec4adb199467220ca1e"><enum>(A)</enum><text>provide analysis
				and reports to Federal agencies on the security of the Federal information
				infrastructure;</text>
									</subparagraph><subparagraph commented="no" id="IDe4696337a7cc47af912d1604b8ccd3ba"><enum>(B)</enum><text>provide
				continuous, automated monitoring of the Federal information infrastructure at
				external Internet access points, which shall include detection and warning of
				threats, vulnerabilities, traffic, trends, incidents, and other anomalous
				activities affecting the information security of the Federal information
				infrastructure;</text>
									</subparagraph><subparagraph id="id7BFF266B11F245E5B5DA31F40509F2AE"><enum>(C)</enum><text>warn Federal
				agencies of threats, vulnerabilities, incidents, and anomalous activities that
				could affect the Federal information infrastructure;</text>
									</subparagraph><subparagraph id="idD6587E13C5FE4D0AA4FAF3C28F4FA6D0"><enum>(D)</enum><text>develop,
				recommend, and deploy security controls to mitigate or remediate
				vulnerabilities;</text>
									</subparagraph><subparagraph id="id1E5A1E04FB4B4002911B5D8ACEA7404D"><enum>(E)</enum><text>support Federal
				agencies in conducting risk assessments of the agency information
				infrastructure;</text>
									</subparagraph><subparagraph id="IDc8317416d544432cbcb3737a3b8c2aa9"><enum>(F)</enum><text>disseminate to
				Federal agencies risk analyses of incidents that could impair the risk-based
				security of the Federal information infrastructure;</text>
									</subparagraph><subparagraph id="ID36fc0857a3b8462fb928249e8ce588d0"><enum>(G)</enum><text>develop and
				acquire predictive analytic tools to evaluate threats, vulnerabilities,
				traffic, trends, incidents, and anomalous activities;</text>
									</subparagraph><subparagraph id="IDb2411edf3b314f04986788111244abed"><enum>(H)</enum><text>aid in the
				detection of, and warn owners or operators of national information
				infrastructure regarding, threats, vulnerabilities, and incidents, affecting
				the national information infrastructure, including providing—</text>
										<clause id="ID0d489fa81f0942a8ba3a67884bea96b5"><enum>(i)</enum><text>timely, targeted,
				and actionable notifications of threats, vulnerabilities, and incidents;</text>
										</clause><clause id="IDc053ab914019481ea5933f55e716c08c"><enum>(ii)</enum><text>notifications
				under this subparagraph; and</text>
										</clause><clause id="ID285f6db6882d499ebdf1efb5dbeadcb5"><enum>(iii)</enum><text>recommended
				security controls to mitigate or remediate vulnerabilities; and</text>
										</clause></subparagraph><subparagraph id="ID5768b3a7c4e24eeba7a24d1b455d9394"><enum>(I)</enum><text>respond to
				assistance requests from Federal agencies and, subject to the availability of
				resources, owners or operators of the national information infrastructure
				to—</text>
										<clause id="ID7ff676c0302e43a38c4395310ee6cdd0"><enum>(i)</enum><text>isolate,
				mitigate, or remediate incidents;</text>
										</clause><clause id="ID85e45405deb34883aa7db9d29c1e8143"><enum>(ii)</enum><text>recover from
				damages and mitigate or remediate vulnerabilities; and</text>
										</clause><clause id="IDe4158773c0754306b3b8d23a4bbd8ff2"><enum>(iii)</enum><text>evaluate
				security controls and other actions taken to secure information infrastructure
				and incorporate lessons learned into best practices, policies, principles, and
				guidelines.</text>
										</clause></subparagraph></paragraph><paragraph id="ID7f6849548b6e4507955d821824e65e70"><enum>(2)</enum><header>Requirement</header><text>With
				respect to the Federal information infrastructure, the US–CERT shall conduct
				the activities described in paragraph (1) in a manner consistent with the
				responsibilities of the head of a Federal agency described in section 3553 of
				title 44, United States Code.</text>
								</paragraph><paragraph id="ID39f4ffc4135b44ad95c20cb0175db01a"><enum>(3)</enum><header>Report</header><text>Not
				later than 1 year after the date of enactment of this subtitle, and every year
				thereafter, the Secretary shall—</text>
									<subparagraph id="id9591D68B332345209DD1DDE6454BD2A5"><enum>(A)</enum><text>in conjunction
				with the Inspector General of the Department, conduct an independent audit or
				review of the activities of the US–CERT under paragraph (1)(B), which shall
				include, at a minimum, an assessment of whether and to what extent the
				activities authorized under paragraph (1)(B) have monitored communications
				other than communications to or from a Federal agency; and</text>
									</subparagraph><subparagraph id="id9721AE67B47241658FCDB3214E1C2E57"><enum>(B)</enum><text>submit to the
				appropriate committees of Congress and the President a report regarding the
				audit or review under subparagraph (A).</text>
									</subparagraph></paragraph><paragraph id="ID35990833ab4e41d9b04a5604bf902383"><enum>(4)</enum><header>Classified
				annex</header><text>A report submitted under paragraph (3) shall be submitted
				in an unclassified form, but may include a classified annex, if
				necessary.</text>
								</paragraph></subsection><subsection id="IDfd915807378747d3af2e21341f3dbfca"><enum>(d)</enum><header>Procedures for
				Federal Government</header><text>Not later than 90 days after the date of
				enactment of this subtitle, the head of each Federal agency shall establish
				procedures for the Federal agency that ensure that the US–CERT can perform the
				functions described in subsection (c) in relation to the Federal agency.</text>
							</subsection><subsection id="ID065ee0fa16904685a2041f2c3fc40e17"><enum>(e)</enum><header>Operational
				updates</header><text>The US–CERT shall provide unclassified and, as
				appropriate, classified updates regarding the composite security state of the
				Federal information infrastructure to the Federal Information Security
				Taskforce.</text>
							</subsection><subsection id="ID14de36d95cc849dfbbee02ea91599e46"><enum>(f)</enum><header>Federal points
				of contact</header><text>The Director of the US–CERT shall designate a
				principal point of contact within the US–CERT for each Federal agency
				to—</text>
								<paragraph id="IDf112c6948efd4446a9a936789c4bc96a"><enum>(1)</enum><text>maintain
				communication;</text>
								</paragraph><paragraph id="ID9a499ce323a14c91b44676c0f3bbf163"><enum>(2)</enum><text>ensure
				cooperative engagement and information sharing; and</text>
								</paragraph><paragraph id="ID34f895866f6d45eb8903e1c5d7d16bd0"><enum>(3)</enum><text>respond to
				inquiries or requests.</text>
								</paragraph></subsection><subsection id="IDb9ef821ea8854bc9b9e6d1d13e223c57"><enum>(g)</enum><header>Requests for
				information or physical access</header>
								<paragraph id="ID5ce49e24bf3d425483facfc97d8f553f"><enum>(1)</enum><header>Information
				access</header><text>Upon request of the Director of the US–CERT, the head of a
				Federal agency or an Inspector General for a Federal agency shall provide any
				law enforcement information, intelligence information, terrorism information,
				or any other information (including information relating to incidents provided
				under subsections (a)(4) and (c) of section 246) relevant to the security of
				the Federal information infrastructure or the national information
				infrastructure necessary to carry out the duties, responsibilities, and
				authorities under this subtitle.</text>
								</paragraph><paragraph id="IDd0ff0abf596e4280b584e3c17071dfb4"><enum>(2)</enum><header>Physical
				access</header><text>Upon request of the Director, and in consultation with the
				head of a Federal agency, the Federal agency shall provide physical access to
				any facility of the Federal agency necessary to determine whether the Federal
				agency is in compliance with any policies, principles, and guidelines
				established by the Director under this subtitle, or otherwise necessary to
				carry out the duties, responsibilities, and authorities of the Director
				applicable to the Federal information infrastructure.</text>
								</paragraph></subsection></section><section id="IDa4904f3a58824895a05620d3e9fe4a85"><enum>245.</enum><header>Additional
				authorities of the Director of the National Center for Cybersecurity and
				Communications</header>
							<subsection id="IDd584d34756b741948230f2608664615b"><enum>(a)</enum><header>Access to
				information</header><text>Unless otherwise directed by the President—</text>
								<paragraph id="ID433fedaaa87c47018306559fd62ef90a"><enum>(1)</enum><text>the Director
				shall access, receive, and analyze law enforcement information, intelligence
				information, terrorism information, and any other information (including
				information relating to incidents provided under subsections (a)(4) and (c) of
				section 246) relevant to the security of the Federal information
				infrastructure, information infrastructure that is owned, operated, controlled,
				or licensed for use by, or on behalf of, the Department of Defense, a military
				department, or another element of the intelligence community, or national
				information infrastructure from Federal agencies and, consistent with
				applicable law, State and local governments (including law enforcement
				agencies), and private entities, including information provided by any
				contractor to a Federal agency regarding the security of the agency information
				infrastructure;</text>
								</paragraph><paragraph id="IDd790b5b06bf94f8e8abf92d0d515c78b"><enum>(2)</enum><text>any Federal
				agency in possession of law enforcement information, intelligence information,
				terrorism information, or any other information (including information relating
				to incidents provided under subsections (a)(4) and (c) of section 246) relevant
				to the security of the Federal information infrastructure, information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, the Department of Defense, a military department, or another
				element of the intelligence community, or national information infrastructure
				shall provide that information to the Director in a timely manner; and</text>
								</paragraph><paragraph id="ID7803ffebce19433ead558e90ed1a2233"><enum>(3)</enum><text>the Director, in
				coordination with the Director of the Office of Management and Budget, the
				Attorney General, the Privacy and Civil Liberties Oversight Board established
				under section 1061 of the National Security Intelligence Reform Act of 2004 (42
				U.S.C. 2000ee), the Director of National Intelligence, and the Archivist of the
				United States, shall establish guidelines to ensure that information is
				transferred, stored, and preserved—</text>
									<subparagraph id="id5D907B3C6E19435CBC69E051EAAF81A3"><enum>(A)</enum><text>in accordance
				with applicable laws relating to the protection of trade secrets and other
				applicable laws; and</text>
									</subparagraph><subparagraph id="id4B1C879F11444252B08E65F459FBAEBE"><enum>(B)</enum><text>in a manner that
				protects the privacy and civil liberties of United States persons and
				intelligence sources and methods.</text>
									</subparagraph></paragraph></subsection><subsection id="ID94c9514efbad4d99bd00cdd8ee52cce8"><enum>(b)</enum><header>Operational
				evaluations</header>
								<paragraph id="id2FB72D6A7DF74E36BC20DB1818E7DD54"><enum>(1)</enum><header>In
				general</header><text>The Director—</text>
									<subparagraph id="IDcd44bc9c2c2e4601840a3b652c9a1ad1"><enum>(A)</enum><text>subject to
				paragraph (2), shall develop, maintain, and enhance capabilities to evaluate
				the security of the Federal information infrastructure as described in section
				3554(a)(3) of title 44, United States Code, including the ability to conduct
				risk-based penetration testing and vulnerability assessments;</text>
									</subparagraph><subparagraph id="ID6d06f342e1114bc2b548ce8b47e9c9f6"><enum>(B)</enum><text>in carrying out
				subparagraph (A), may request technical assistance from the Director of the
				Federal Bureau of Investigation, the Director of the National Security Agency,
				the head of any other Federal agency that may provide support, and any
				nongovernmental entity contracting with the Department or another Federal
				agency; and</text>
									</subparagraph><subparagraph id="ID4e177b177ad8489ea9f9700a9433c3ea"><enum>(C)</enum><text>in consultation
				with the Attorney General and the Privacy and Civil Liberties Oversight Board
				established under section 1061 of the National Security Intelligence Reform Act
				of 2004 (42 U.S.C. 2000ee), shall develop guidelines to ensure compliance with
				all applicable laws relating to the privacy of United States persons in
				carrying out the operational evaluations under subparagraph (A).</text>
									</subparagraph></paragraph><paragraph id="ID5a9926ed1c9345aa90183a95641de60f"><enum>(2)</enum><header>Operational
				evaluations</header>
									<subparagraph id="idF938236BE74C48B2BEAA5B2D09C50798"><enum>(A)</enum><header>In
				general</header><text>The Director may conduct risk-based operational
				evaluations of the agency information infrastructure of any Federal agency, at
				a time determined by the Director, in consultation with the head of the Federal
				agency, using the capabilities developed under paragraph (1)(A).</text>
									</subparagraph><subparagraph id="IDcc7bc874b701438ba5c8dbe29da99dc3"><enum>(B)</enum><header>Annual
				evaluation requirement</header><text>If the Director conducts an operational
				evaluation under subparagraph (A) or an operational evaluation at the request
				of a Federal agency to meet the requirements of section 3554 of title 44,
				United States Code, the operational evaluation shall satisfy the requirements
				of section 3554 for the Federal agency for the year of the evaluation, unless
				otherwise specified by the Director.</text>
									</subparagraph></paragraph></subsection><subsection id="id1473612EFBA2447E8EF7669E30D1019A"><enum>(c)</enum><header>Corrective
				measures and mitigation plans</header><text>If the Director determines that a
				Federal agency is not in compliance with applicable policies, principles,
				standards, and guidelines applicable to the Federal information
				infrastructure—</text>
								<paragraph id="IDd965440dee954b3b9a5f1c3aacacd48e"><enum>(1)</enum><text>the Director, in
				consultation with the Director of the Office of Management and Budget, may
				direct the head of the Federal agency to—</text>
									<subparagraph id="idF641053ECC5E493B8C19AAFBBABA5933"><enum>(A)</enum><text>take corrective
				measures to meet the policies, principles, standards, and guidelines;
				and</text>
									</subparagraph><subparagraph id="idF4DD2738D0704E2495F99A054ECA284A"><enum>(B)</enum><text>develop a plan to
				remediate or mitigate any vulnerabilities addressed by the policies,
				principles, standards, and guidelines;</text>
									</subparagraph></paragraph><paragraph id="IDe4c04fb215a04485900b7b4b291553ba"><enum>(2)</enum><text>within such time
				period as the Director shall prescribe, the head of the Federal agency
				shall—</text>
									<subparagraph id="IDb51e594d724345e2845a3c1d3adeaa61"><enum>(A)</enum><text>implement a
				corrective measure or develop a mitigation plan in accordance with paragraph
				(1); or</text>
									</subparagraph><subparagraph id="ID137f83b773694bdc805965ba2565315a"><enum>(B)</enum><text>submit to the
				Director, the Director of the Office of Management and Budget, the Inspector
				General for the Federal agency, and the appropriate committees of Congress a
				report indicating why the Federal agency has not implemented the corrective
				measure or developed a mitigation plan; and</text>
									</subparagraph></paragraph><paragraph id="IDe11721853f624826a6387d7ff8a363ae"><enum>(3)</enum><text>after providing
				notice to the head of the affected Federal agency, the Director may direct the
				isolation of any component of the agency information infrastructure, consistent
				with the contingency or continuity of operation plans applicable to the agency
				information infrastructure, until corrective measures are taken or mitigation
				plans approved by the Director are put in place, if—</text>
									<subparagraph id="ID84f2f816257040a8983ec73ca9b17bf2"><enum>(A)</enum><text>the head of the
				Federal agency has failed to comply with the corrective measures prescribed
				under paragraph (1); and</text>
									</subparagraph><subparagraph id="IDa5135a58878d4afeaab675d947dc347d"><enum>(B)</enum><text>the failure to
				comply presents a significant danger to the Federal information
				infrastructure.</text>
									</subparagraph></paragraph></subsection></section><section id="IDca133ac3db80457ea0b070c2c58b80d5"><enum>246.</enum><header>Information
				sharing</header>
							<subsection id="ID338a57b8f1b64d3db7843f8880a1982d"><enum>(a)</enum><header>Federal
				agencies</header>
								<paragraph id="ID5885aad8fc4549839e81e9499476d046"><enum>(1)</enum><header>Information
				sharing program</header><text>Consistent with the responsibilities described in
				sections 242 and 244, the Director, in consultation with the other members of
				the Chief Information Officers Council established under section 3603 of title
				44, United States Code, and the Federal Information Security Taskforce, shall
				establish a program for sharing information with and between the Center and
				other Federal agencies that includes processes and procedures, including
				standard operating procedures—</text>
									<subparagraph id="ID11631d611e014661812f91d42d378e46"><enum>(A)</enum><text>under which the
				Director regularly shares with each Federal agency—</text>
										<clause id="ID10c1cea3d7694db1b16dff95b9be4417"><enum>(i)</enum><text>analysis and
				reports on the composite security state of the Federal information
				infrastructure and information infrastructure that is owned, operated,
				controlled, or licensed for use by, or on behalf of, the Department of Defense,
				a military department, or another element of the intelligence community, which
				shall include information relating to threats, vulnerabilities, incidents, or
				anomalous activities;</text>
										</clause><clause id="ID97150b1c15ce4c72a0afcd5e599d797a"><enum>(ii)</enum><text>any available
				analysis and reports regarding the security of the agency information
				infrastructure; and</text>
										</clause><clause id="IDef0c89007ac24fcb9caeb6122b9129ee"><enum>(iii)</enum><text>means and
				methods of preventing, responding to, mitigating, and remediating
				vulnerabilities; and</text>
										</clause></subparagraph><subparagraph id="ID303cedebac4545018507420933f47913"><enum>(B)</enum><text>under which the
				Director may request information from Federal agencies concerning the security
				of the Federal information infrastructure, information infrastructure that is
				owned, operated, controlled, or licensed for use by, or on behalf of, the
				Department of Defense, a military department, or another element of the
				intelligence community, or the national information infrastructure necessary to
				carry out the duties of the Director under this subtitle or any other provision
				of law.</text>
									</subparagraph></paragraph><paragraph id="ID1786c0d40cf045aaa7b1175657eee932"><enum>(2)</enum><header>Contents</header><text>The
				program established under this section shall include—</text>
									<subparagraph id="ID3c22d994ac204842bbaf9d40ac8f9ea0"><enum>(A)</enum><text>timeframes for
				the sharing of information under paragraph (1);</text>
									</subparagraph><subparagraph id="ID3b9caa8451a3445c97af2422bdfa081f"><enum>(B)</enum><text>guidance on what
				information shall be shared, including information regarding incidents;</text>
									</subparagraph><subparagraph id="ID8fd7f22c0ac84d4eb9739fdcff51b323"><enum>(C)</enum><text>a tiered
				structure that provides guidance for the sharing of urgent information;
				and</text>
									</subparagraph><subparagraph id="ID3e0ebf5643864c91bb666efd3c22296a"><enum>(D)</enum><text>processes and
				procedures under which the Director or the head of a Federal agency may report
				noncompliance with the program to the Director of Cyberspace Policy.</text>
									</subparagraph></paragraph><paragraph id="ID05e6d71d91c74db2a08cf452747af090"><enum>(3)</enum><header>US–CERT</header><text>The
				Director of the US–CERT shall ensure that the head of each Federal agency has
				continual access to data collected by the US–CERT regarding the agency
				information infrastructure of the Federal agency.</text>
								</paragraph><paragraph id="IDdb7ef2313e9246e0839c654f2cf1cb9a"><enum>(4)</enum><header>Federal
				agencies</header>
									<subparagraph id="id20AE58BC61DD43E5AFE7AF4FA4F29384"><enum>(A)</enum><header>In
				general</header><text>The head of a Federal agency shall comply with all
				processes and procedures established under this subsection regarding
				notification to the Director relating to incidents.</text>
									</subparagraph><subparagraph id="ID4f50033e5c1d42d496c974eec2730601"><enum>(B)</enum><header>Immediate
				notification required</header><text>Unless otherwise directed by the President,
				any Federal agency with a national security system shall immediately notify the
				Director regarding any incident affecting the risk-based security of the
				national security system.</text>
									</subparagraph></paragraph></subsection><subsection id="IDa36f728dc7e343fea81c06bb38dec5e8"><enum>(b)</enum><header>State and local
				governments, private sector, and international partners</header>
								<paragraph id="ID25f38ea76508482bb90e0f1683b2d669"><enum>(1)</enum><header>In
				general</header><text>The Director shall establish processes and procedures,
				including standard operating procedures, to ensure bidirectional information
				sharing with State and local governments, private entities, and international
				partners of the United States on—</text>
									<subparagraph id="ID7f6766c0c740423895951b02b6e121e7"><enum>(A)</enum><text>threats,
				vulnerabilities, incidents, and anomalous activities affecting the national
				information infrastructure; and</text>
									</subparagraph><subparagraph id="IDdb58e3a8fe68417294a4d3e7fab62b61"><enum>(B)</enum><text>means and methods
				of preventing, responding to, and mitigating and remediating
				vulnerabilities.</text>
									</subparagraph></paragraph><paragraph id="ID65ffab93766840768d4a2cbbf72918db"><enum>(2)</enum><header>Contents</header><text>The
				processes and procedures established under paragraph (1) shall include—</text>
									<subparagraph id="ID7106d2b9ee814b499c3f275917183342"><enum>(A)</enum><text>means or methods
				of accessing classified or unclassified information, as appropriate and in
				accordance with applicable laws regarding trade secrets, that will provide
				situational awareness of the security of the Federal information infrastructure
				and the national information infrastructure relating to threats,
				vulnerabilities, traffic, trends, incidents, and other anomalous activities
				affecting the Federal information infrastructure or the national information
				infrastructure;</text>
									</subparagraph><subparagraph id="ID8462deffa4b64b6da95a092de7740700"><enum>(B)</enum><text>a mechanism,
				established in consultation with the heads of the relevant sector-specific
				agencies, sector coordinating councils, and information sharing and analysis
				centers, by which owners and operators of covered critical infrastructure shall
				report incidents in the information infrastructure for covered critical
				infrastructure under subsection (c)(1)(A);</text>
									</subparagraph><subparagraph id="ID32cc49cca03847b89d4e66a7bf4bfca0"><enum>(C)</enum><text>guidance on the
				form, content, and priority of incident reports that shall be submitted under
				subsection (c)(1)(A), which shall—</text>
										<clause id="id36208A1AEBE24AF5BC3B6620B205990F"><enum>(i)</enum><text>include
				appropriate mechanisms to protect—</text>
											<subclause id="idAC16ABDAF4864F259B1AA668815A2AC2"><enum>(I)</enum><text>information in
				accordance with section 251;</text>
											</subclause><subclause id="idBD7D3F8BA9664FB59CF894FBD9DCA2BD"><enum>(II)</enum><text>personally
				identifiable information; and</text>
											</subclause><subclause id="id379275BD2AAF4E388E3A972938E3BBB2"><enum>(III)</enum><text>trade secrets;
				and</text>
											</subclause></clause><clause id="idF5DDEEEEB4E54ACD936148B623067530"><enum>(ii)</enum><text>prioritize the
				reporting of incidents based on the risk the incident poses to the disruption
				of the reliable operation of the covered critical infrastructure;</text>
										</clause></subparagraph><subparagraph id="ID6cee40765e3f402b913ad8ffd508ca52"><enum>(D)</enum><text>a procedure for
				notifying an information technology provider if a vulnerability is detected in
				the product or service produced by the information technology provider and,
				where possible, working with the information technology provider to remediate
				the vulnerability before any public disclosure of the vulnerability so as to
				minimize the opportunity for the vulnerability to be exploited; and</text>
									</subparagraph><subparagraph id="ID3967b691223249d19fd7304dc37797a9"><enum>(E)</enum><text>an evaluation of
				the need to provide security clearances to employees of State and local
				governments, private entities, and international partners to carry out this
				subsection.</text>
									</subparagraph></paragraph><paragraph id="IDc9bc0288108943fcbfbda33f1066aa7f"><enum>(3)</enum><header>Guidelines</header><text>The
				Director, in consultation with the Attorney General, the Director of National
				Intelligence, and the Privacy Officer established under section 242(e), shall
				develop guidelines to protect the privacy and civil liberties of United States
				persons and intelligence sources and methods, while carrying out this
				subsection.</text>
								</paragraph></subsection><subsection id="ID97aad728b0794688822b3f64f93ce286"><enum>(c)</enum><header>Incidents</header>
								<paragraph id="ID0e95573defa84d14b0282fe46c5fbb7d"><enum>(1)</enum><header>Non-Federal
				entities</header>
									<subparagraph id="IDa33bb20e95eb4ba1880892793a86ee4e"><enum>(A)</enum><header>In
				general</header>
										<clause id="IDf3f8414733d64dbdbaad871cca642078"><enum>(i)</enum><header>Mandatory
				reporting</header><text>Subject to clause (ii), the owner or operator of
				covered critical infrastructure shall report any incident affecting the
				information infrastructure of covered critical infrastructure to the extent the
				incident might indicate an actual or potential cyber risk, or exploitation of a
				cyber risk, in accordance with the policies and procedures for the mechanism
				established under subsection (b)(2)(B) and guidelines developed under
				subsection (b)(3).</text>
										</clause><clause id="IDb8df827e50bf487cb628e0c58fa839dc"><enum>(ii)</enum><header>Limitation</header><text>Clause
				(i) shall not authorize the Director, the Center, the Department, or any other
				Federal entity to—</text>
											<subclause id="IDf9bde0bcf96b4809842a22ccec916008"><enum>(I)</enum><text>compel the
				disclosure of information relating to an incident unless otherwise authorized
				by law; or</text>
											</subclause><subclause id="ID6010be0da8a34b0a8714e39539937d75"><enum>(II)</enum><text>intercept a
				wire, oral, or electronic communication (as those terms are defined in section
				2510 of title 18, United States Code), access a stored electronic or wire
				communication, install or use a pen register or trap and trace device, or
				conduct electronic surveillance (as defined in section 101 of the Foreign
				Intelligence Surveillance Act of 1978 (50 U.S.C. 1801)) relating to an
				incident, unless otherwise authorized under chapter 119, chapter 121, or
				chapter 206 of title 18, United States Code, or the Foreign Intelligence
				Surveillance Act of 1978 (50 U.S.C. 1801 et seq.).</text>
											</subclause></clause></subparagraph><subparagraph id="ID430f6e43ddb048faac65f9088e3be532"><enum>(B)</enum><header>Reporting
				procedures</header><text>The Director shall establish procedures that enable
				and encourage the owner or operator of national information infrastructure to
				report to the Director regarding incidents affecting such information
				infrastructure.</text>
									</subparagraph></paragraph><paragraph id="IDe080a7e329544de4b7fe875c52f1e480"><enum>(2)</enum><header>Information
				protection</header><text>Notwithstanding any other provision of law,
				information reported under paragraph (1) shall be protected from unauthorized
				disclosure, in accordance with section 251.</text>
								</paragraph></subsection><subsection id="ID4c71575e7ccf4d4296bf0270878d4cbc"><enum>(d)</enum><header>Additional
				responsibilities</header><text>The Director shall—</text>
								<paragraph id="IDc5fad579104546a284bc4142ff8125e9"><enum>(1)</enum><text>share data
				collected on the Federal information infrastructure with the National Science
				Foundation and other accredited research institutions for the sole purpose of
				cybersecurity research in a manner that protects privacy and civil liberties of
				United States persons and intelligence sources and methods;</text>
								</paragraph><paragraph id="IDf466b3864e584a0ba4b1ea7f2b7fe59a"><enum>(2)</enum><text>establish a
				website to provide an opportunity for the public to provide—</text>
									<subparagraph id="id0DEF1B25BD8F4722A54718EA10BF1FDA"><enum>(A)</enum><text>input about the
				operations of the Center; and</text>
									</subparagraph><subparagraph id="id87729CFEFE1548DDB9725A1F98FF0B60"><enum>(B)</enum><text>recommendations
				for improvements of the Center; and</text>
									</subparagraph></paragraph><paragraph id="ID2676267558ef4e29ac22608b525ce861"><enum>(3)</enum><text>in coordination
				with the Secretary of Defense, the Director of National Intelligence, the
				Secretary of State, and the Attorney General, develop information sharing pilot
				programs with international partners of the United States.</text>
								</paragraph></subsection></section><section id="ID197d66a7fda64f58bb7cecdfb99d5a2d"><enum>247.</enum><header>Private sector
				assistance</header>
							<subsection id="IDe19f343cf7d04968823bd2ba38586a76"><enum>(a)</enum><header>In
				general</header><text>The Director, in consultation with the Director of the
				National Institute of Standards and Technology, the Director of the National
				Security Agency, the head of any relevant sector-specific agency, the National
				Cybersecurity Advisory Council, State and local governments, and any private
				entities the Director determines appropriate, shall establish a program to
				promote, and provide technical assistance authorized under section 242(f)(1)(S)
				relating to the implementation of, best practices and related standards and
				guidelines for securing the national information infrastructure, including the
				costs and benefits associated with the implementation of the best practices and
				related standards and guidelines.</text>
							</subsection><subsection id="ID07f0692c1f8e4fe9aac0e4a6da81b657"><enum>(b)</enum><header>Analysis and
				improvement of standards and guidelines</header><text>For purposes of the
				program established under subsection (a), the Director shall—</text>
								<paragraph id="IDb0acfa6b83744220a8c095fffcd00347"><enum>(1)</enum><text>regularly assess
				and evaluate cybersecurity standards and guidelines issued by private sector
				organizations, recognized international and domestic standards setting
				organizations, and Federal agencies; and</text>
								</paragraph><paragraph id="IDe2a7e97c7fe94796872bea40a9184910"><enum>(2)</enum><text>in coordination
				with the National Institute of Standards and Technology, encourage the
				development of, and recommend changes to, the standards and guidelines
				described in paragraph (1) for securing the national information
				infrastructure.</text>
								</paragraph></subsection><subsection id="ID0e1bd977ad84498a997bf4b722a5425e"><enum>(c)</enum><header>Guidance and
				technical assistance</header>
								<paragraph id="IDb52562bcc003450d98d921c19b084a3a"><enum>(1)</enum><header>In
				general</header><text>The Director shall promote best practices and related
				standards and guidelines to assist owners and operators of national information
				infrastructure in increasing the security of the national information
				infrastructure and protecting against and mitigating or remediating known
				vulnerabilities.</text>
								</paragraph><paragraph id="ID54f2a50990f1400c8f9c65f19614d466"><enum>(2)</enum><header>Requirement</header><text>Technical
				assistance provided under section 242(f)(1)(S) and best practices promoted
				under this section shall be prioritized based on risk.</text>
								</paragraph></subsection><subsection id="IDcbde01537e5f4e6f9af3edf19e106f07"><enum>(d)</enum><header>Criteria</header><text>In
				promoting best practices or recommending changes to standards and guidelines
				under this section, the Director shall ensure that best practices, and related
				standards and guidelines—</text>
								<paragraph id="IDfd32f2f5dc6c482ea7eff069a11574f9"><enum>(1)</enum><text>address
				cybersecurity in a comprehensive, risk-based manner;</text>
								</paragraph><paragraph id="ID994df477a80c4de6be6228ad8a0aa49b"><enum>(2)</enum><text>include
				consideration of the cost of implementing such best practices or of
				implementing recommended changes to standards and guidelines;</text>
								</paragraph><paragraph id="ID9bdc88909f0f460b93bed88e55383d2b"><enum>(3)</enum><text>increase the
				ability of the owners or operators of national information infrastructure to
				protect against and mitigate or remediate known vulnerabilities;</text>
								</paragraph><paragraph id="IDc9ec55639d6847108a186747e88d53c3"><enum>(4)</enum><text>are suitable, as
				appropriate, for implementation by small business concerns;</text>
								</paragraph><paragraph id="IDc69d9f7283bc46db9db154680e53e549"><enum>(5)</enum><text>as necessary and
				appropriate, are sector specific;</text>
								</paragraph><paragraph id="IDc17e56ca4c4a4634a6b97cabff36a128"><enum>(6)</enum><text>to the maximum
				extent possible, incorporate standards and guidelines established by private
				sector organizations, recognized international and domestic standards setting
				organizations, and Federal agencies;</text>
								</paragraph><paragraph id="ID55b536854f194d138323a7da6304dfd6"><enum>(7)</enum><text>consider
				voluntary programs by internet service providers to assist individuals using
				the internet service providers in the identification and mitigation of cyber
				threats and vulnerabilities, with the consent of the individual users;
				and</text>
								</paragraph><paragraph id="id677C435DE7F848709F7EF7ED03E2B78A"><enum>(8)</enum><text>provide
				sufficient flexibility to permit a range of security solutions.</text>
								</paragraph></subsection></section><section id="ID59a6ada748504ade8d72a3e673e78ebf"><enum>248.</enum><header>Cyber risks to
				covered critical infrastructure</header>
							<subsection id="ID7f79763b8057495f9653fc2efe20b436"><enum>(a)</enum><header>Identification
				of cyber risks</header>
								<paragraph id="IDdc6a9eea98e64005beb0f420a9ce688e"><enum>(1)</enum><header>In
				general</header><text>Based on the risk-based assessments conducted under
				section 242(f)(1)(T)(i), the Director, in coordination with the head of the
				sector-specific agency with responsibility for covered critical infrastructure
				and the head of any Federal agency that is not a sector-specific agency with
				responsibilities for regulating the covered critical infrastructure, and in
				consultation with the National Cybersecurity Advisory Council and any private
				sector entity determined appropriate by the Director, shall, on a continuous
				and sector-by-sector basis, identify and evaluate the cyber risks to covered
				critical infrastructure.</text>
								</paragraph><paragraph id="ID573969026ef74ffd921bf2d0a732db4b"><enum>(2)</enum><header>Factors to be
				considered</header><text>In identifying and evaluating cyber risks under
				paragraph (1), the Director shall consider—</text>
									<subparagraph id="ID9c6880cb4c4844f18bbae5392ce41f6b"><enum>(A)</enum><text>the actual or
				assessed threat, including a consideration of adversary capabilities and
				intent, preparedness, target attractiveness, and deterrence
				capabilities;</text>
									</subparagraph><subparagraph id="ID7f18ea14bef04970b3e286941229502f"><enum>(B)</enum><text>the extent and
				likelihood of death, injury, or serious adverse effects to human health and
				safety caused by a disruption of the reliable operation of covered critical
				infrastructure;</text>
									</subparagraph><subparagraph id="IDd294eabc0ee242628270fd4ec190d70b"><enum>(C)</enum><text>the threat to or
				impact on national security caused by a disruption of the reliable operation of
				covered critical infrastructure;</text>
									</subparagraph><subparagraph id="ID4a8db3b463c94f50aa2ac10c587e772a"><enum>(D)</enum><text>the extent to
				which the disruption of the reliable operation of covered critical
				infrastructure will disrupt the reliable operation of other covered critical
				infrastructure;</text>
									</subparagraph><subparagraph id="ID1b2c73947ef64ca592542faa450a9709"><enum>(E)</enum><text>the harm to the
				economy that would result from a disruption of the reliable operation of
				covered critical infrastructure; and</text>
									</subparagraph><subparagraph id="ID6579f9f5560349469c87be08af0e726d"><enum>(F)</enum><text>other risk-based
				security factors that the Director, in consultation with the head of the
				sector-specific agency with responsibility for the covered critical
				infrastructure and the head of any Federal agency that is not a sector-specific
				agency with responsibilities for regulating the covered critical
				infrastructure, determine to be appropriate and necessary to protect public
				health and safety, critical infrastructure, or national and economic
				security.</text>
									</subparagraph></paragraph><paragraph id="ID02ad9fefb2824c2e85dfcd77d037b53f"><enum>(3)</enum><header>Report</header>
									<subparagraph id="ID4bcf6f00fe0e4141b93d1d510b8b8ec3"><enum>(A)</enum><header>In
				general</header><text>Not later than 180 days after the date of enactment of
				this subtitle, and annually thereafter, the Director, in coordination with the
				head of the sector-specific agency with responsibility for the covered critical
				infrastructure and the head of any Federal agency that is not a sector-specific
				agency with responsibilities for regulating the covered critical
				infrastructure, shall submit to the appropriate committees of Congress a report
				on the findings of the identification and evaluation of cyber risks under this
				subsection. Each report submitted under this paragraph shall be submitted in an
				unclassified form, but may include a classified annex.</text>
									</subparagraph><subparagraph id="ID58f6022da6354e76b5b17f8d1b400ab2"><enum>(B)</enum><header>Input</header><text>For
				purposes of the reports required under subparagraph (A), the Director shall
				create a process under which owners and operators of covered critical
				infrastructure may provide input on the findings of the reports.</text>
									</subparagraph></paragraph></subsection><subsection id="ID498e9d29ef5a4aec90fb5de0da96867f"><enum>(b)</enum><header>Risk-Based
				security performance requirements</header>
								<paragraph id="ID2549d251a14d43858ad654fb122837d0"><enum>(1)</enum><header>In
				general</header><text>Not later than 270 days after the date of the enactment
				of this subtitle, in coordination with the heads of the sector-specific
				agencies with responsibility for covered critical infrastructure and the head
				of any Federal agency that is not a sector-specific agency with
				responsibilities for regulating the covered critical infrastructure, and in
				consultation with the National Cybersecurity Advisory Council and any private
				sector entity determined appropriate by the Director, the Director shall issue
				interim final regulations establishing risk-based security performance
				requirements to secure covered critical infrastructure against cyber risks
				through the adoption of security measures that satisfy the security performance
				requirements identified by the Director.</text>
								</paragraph><paragraph id="ID5c1dfe12e40948af9fc0b8aabac324ea"><enum>(2)</enum><header>Procedures</header><text>The
				regulations issued under this subsection shall—</text>
									<subparagraph id="ID5016f35b05b84316a16568be62dcb73a"><enum>(A)</enum><text>include a process
				under which owners and operators of covered critical infrastructure are
				informed of identified cyber risks and security performance requirements
				designed to remediate or mitigate the cyber risks, in combination with best
				practices recommended under section 247;</text>
									</subparagraph><subparagraph id="ID68057306c65142fba6e94530de7362f1"><enum>(B)</enum><text>establish a
				process for owners and operators of covered critical infrastructure to select
				security measures, including any best practices recommended under section 247,
				that, in combination, satisfy the security performance requirements established
				by the Director under this subsection;</text>
									</subparagraph><subparagraph id="ID650bf4cb75614895a548895e8082aecb"><enum>(C)</enum><text>establish a
				process for owners and operators of covered critical infrastructure to develop
				response plans for a national cyber emergency declared under section
				249;</text>
									</subparagraph><subparagraph id="IDc2379c124d3647f495ae5afba82e622c"><enum>(D)</enum><text>establish a
				process under which the Director—</text>
										<clause id="ID0ecf0163eb8947d39884c33675913c38"><enum>(i)</enum><text>is notified of
				the security measures selected by the owner or operator of covered critical
				infrastructure under subparagraph (B); and</text>
										</clause><clause id="IDb2d3feb2b8f647c6bbf72f8a96815fce"><enum>(ii)</enum><text>may determine
				whether the proposed security measures satisfy the security performance
				requirements established by the Director under this subsection; and</text>
										</clause></subparagraph><subparagraph id="ID7c2931bb14ed414d8678e9e45d472384"><enum>(E)</enum><text>establish a
				process under which the Director—</text>
										<clause id="ID858a9e440c614188859fcab4ba2c5756"><enum>(i)</enum><text>identifies to
				owners and operators of covered critical infrastructure cyber risks that are
				not capable of effective remediation or mitigation using available best
				practices or security measures;</text>
										</clause><clause id="IDd364c1365dde4b869c2165a3b79203ce"><enum>(ii)</enum><text>provides owners
				and operators of covered critical infrastructure the opportunity to develop
				best practices or security measures to remediate or mitigate the cyber risks
				identified in clause (i) without the prior approval of the Director and without
				affecting the compliance of the covered critical infrastructure with the
				requirements under this section;</text>
										</clause><clause id="ID01442385c39c4742b8e40aa8f77f7e90"><enum>(iii)</enum><text>in accordance
				with applicable law relating to the protection of trade secrets, permits owners
				and operators of covered critical infrastructure to report to the Center the
				development of effective best practices or security measures to remediate or
				mitigate the cyber risks identified under clause (i); and</text>
										</clause><clause id="IDe4775c8dcd55489bbd03393bce3d364e"><enum>(iv)</enum><text>incorporates the
				best practices and security measures developed into the risk-based security
				performance requirements under this section.</text>
										</clause></subparagraph></paragraph><paragraph id="IDeb438c9144304d878e6955b48a57a625"><enum>(3)</enum><header>International
				cooperation on securing covered critical infrastructure</header>
									<subparagraph id="IDd25a50b11b1a4541a642a6cc82f789b3"><enum>(A)</enum><header>In
				general</header><text>The Director, in coordination with the head of the
				sector-specific agency with responsibility for covered critical infrastructure
				and the head of any Federal agency that is not a sector-specific agency with
				responsibilities for regulating the covered critical infrastructure,
				shall—</text>
										<clause id="ID400e3b0e32cd433c9600b2b288525fc6"><enum>(i)</enum><text>consistent with
				the protection of intelligence sources and methods and other sensitive matters,
				inform the owner or operator of information infrastructure located outside the
				United States the disruption of which could result in national or regional
				catastrophic damage in the United States and the government of the country in
				which the information infrastructure is located of any cyber risks to the
				information infrastructure; and</text>
										</clause><clause id="ID3cca632a7e714210a0f2847bd5affa21"><enum>(ii)</enum><text>coordinate with
				the government of the country in which the information infrastructure is
				located and, as appropriate, the owner or operator of the information
				infrastructure, regarding the implementation of security measures or other
				measures to the information infrastructure to mitigate or remediate cyber
				risks.</text>
										</clause></subparagraph><subparagraph id="IDfb265a57aabf427f8f9aba4e02c76a3b"><enum>(B)</enum><header>International
				agreements</header><text>The Director shall carry out this paragraph in a
				manner consistent with applicable international agreements.</text>
									</subparagraph></paragraph><paragraph id="ID4405ea7f99ef4521a59a8648dc2d8f23"><enum>(4)</enum><header>Risk-based
				security performance requirements</header>
									<subparagraph id="ID07f1f5ce24474e80802ee668e427c95d"><enum>(A)</enum><header>In
				general</header><text>The security performance requirements established by the
				Director under this subsection shall be—</text>
										<clause id="id93CC2AD3AE104A86976683FA6A3E11E2"><enum>(i)</enum><text>based on the
				factors listed in subsection (a)(2); and</text>
										</clause><clause id="id27D7ACAFA38D4C0EAF2AB1491ACB9BE8"><enum>(ii)</enum><text>designed to
				remediate or mitigate identified cyber risks and any associated consequences of
				an exploitation based on such risks.</text>
										</clause></subparagraph><subparagraph id="ID17a7875058194908ab1dd38a0994cca1"><enum>(B)</enum><header>Consultation</header><text>In
				establishing security performance requirements under this subsection, the
				Director shall, to the maximum extent practicable, consult with—</text>
										<clause id="id64C3F61D5F8F49649363F73128C8474F"><enum>(i)</enum><text>the Director of
				the National Security Agency;</text>
										</clause><clause id="id0E55C9EBDB4B46A4897F1E37E56A0A1A"><enum>(ii)</enum><text>the Director of
				the National Institute of Standards and Technology;</text>
										</clause><clause id="idE96122E33ADC4B0680380B828B3558EE"><enum>(iii)</enum><text>the National
				Cybersecurity Advisory Council;</text>
										</clause><clause id="id72DB6E3BAD59417DB7989B9CD75852E6"><enum>(iv)</enum><text>the heads of
				sector-specific agencies; and</text>
										</clause><clause id="id1E504D79FDC64098846AA3E2969B1270"><enum>(v)</enum><text>the heads of
				Federal agencies that are not sector-specific agencies with responsibilities
				for regulating the covered critical infrastructure.</text>
										</clause></subparagraph><subparagraph id="ID8f5f82546fa34fa88ae6519eda4a31a0"><enum>(C)</enum><header>Alternative
				measures</header>
										<clause id="id10350478192D468EAEB313425C534AFB"><enum>(i)</enum><header>In
				general</header><text>The owners and operators of covered critical
				infrastructure shall have flexibility to implement any security measure, or
				combination thereof, to satisfy the security performance requirements described
				in subparagraph (A) and the Director may not disapprove under this section any
				proposed security measures, or combination thereof, based on the presence or
				absence of any particular security measure if the proposed security measures,
				or combination thereof, satisfy the security performance requirements
				established by the Director under this section or are consistent with the
				process for addressing new or evolving cyber risks established under paragraph
				(2)(E).</text>
										</clause><clause commented="no" id="idA4D356F8C6D44D898251772013696438"><enum>(ii)</enum><header>Recommended
				security measures</header><text>The Director may recommend to an owner and
				operator of covered critical infrastructure a specific security measure, or
				combination thereof, that will satisfy the security performance requirements
				established by the Director. The absence of the recommended security measures,
				or combination thereof, may not serve as the basis for a disapproval of the
				security measure, or combination thereof, proposed by the owner or operator of
				covered critical infrastructure if the proposed security measure, or
				combination thereof, otherwise satisfies the security performance requirements
				established by the Director under this section.</text>
										</clause></subparagraph></paragraph></subsection></section><section id="ID67ff41b5884a45da9cc1d5cf932541ca"><enum>249.</enum><header>National cyber
				emergencies</header>
							<subsection id="IDe55e703646dc4d848823424df1ccbb6b"><enum>(a)</enum><header>Declaration</header>
								<paragraph id="IDa0d51f05300a49cd8b7507259e03f92c"><enum>(1)</enum><header>In
				general</header><text>The President may issue a declaration of a national cyber
				emergency to covered critical infrastructure if there is an ongoing or imminent
				action by any individual or entity to exploit a cyber risk in a manner that
				disrupts, attempts to disrupt, or poses a significant risk of disruption to the
				operation of the information infrastructure essential to the reliable operation
				of covered critical infrastructure. Any declaration under this section shall
				specify the covered critical infrastructure subject to the national cyber
				emergency.</text>
								</paragraph><paragraph id="IDdaf58f32418840c3a0f159b0fdb5242c"><enum>(2)</enum><header>Notification</header><text>Upon
				issuing a declaration under paragraph (1), the President shall, consistent with
				the protection of intelligence sources and methods, notify the owners and
				operators of the specified covered critical infrastructure and any other
				relevant private sector entity of the nature of the national cyber
				emergency.</text>
								</paragraph><paragraph id="ID64def3f73a0842baa3e04cfc2aeea40d"><enum>(3)</enum><header>Authorities</header><text>If
				the President issues a declaration under paragraph (1), the Director
				shall—</text>
									<subparagraph id="IDecab995df72d45d79d80a7f0a2e6b5dc"><enum>(A)</enum><text>immediately
				direct the owners and operators of covered critical infrastructure subject to
				the declaration under paragraph (1) to implement response plans required under
				section 248(b)(2)(C);</text>
									</subparagraph><subparagraph id="ID157fabd9259747808771457f6e1a5329"><enum>(B)</enum><text>develop and
				coordinate emergency measures or actions necessary to preserve the reliable
				operation, and mitigate or remediate the consequences of the potential
				disruption, of covered critical infrastructure;</text>
									</subparagraph><subparagraph id="ID921a43a99cd94b5296637acaed1db4ea"><enum>(C)</enum><text>ensure that
				emergency measures or actions directed under this section represent the least
				disruptive means feasible to the operations of the covered critical
				infrastructure and to the national information infrastructure;</text>
									</subparagraph><subparagraph id="ID6ede876095a842e0b3e3294b34ec9b23"><enum>(D)</enum><text>subject to
				subsection (g), direct actions by other Federal agencies to respond to the
				national cyber emergency;</text>
									</subparagraph><subparagraph id="ID7e85eb818df5414bad4bf4be52061ddd"><enum>(E)</enum><text>coordinate with
				officials of State and local governments, international partners of the United
				States, owners and operators of covered critical infrastructure specified in
				the declaration, and other relevant private section entities to respond to the
				national cyber emergency;</text>
									</subparagraph><subparagraph id="ID1aab895e3c134078afb8eb6f88b5ab7a"><enum>(F)</enum><text>initiate a
				process under section 248 to address the cyber risk that may be exploited by
				the national cyber emergency; and</text>
									</subparagraph><subparagraph id="IDc2ee2ae7e41d497889164afced9b27b7"><enum>(G)</enum><text>provide voluntary
				technical assistance, if requested, under section 242(f)(1)(S).</text>
									</subparagraph></paragraph><paragraph id="ID831b3913249e4bcfa4a4931b46403f5c"><enum>(4)</enum><header>Reimbursement</header><text>A
				Federal agency shall be reimbursed for expenditures under this section from
				funds appropriated for the purposes of this section. Any funds received by a
				Federal agency as reimbursement for services or supplies furnished under the
				authority of this section shall be deposited to the credit of the appropriation
				or appropriations available on the date of the deposit for the services or
				supplies.</text>
								</paragraph><paragraph id="ID0116973b99db4c549ccc617b54c7c944"><enum>(5)</enum><header>Consultation</header><text>In
				carrying out this section, the Director shall consult with the Secretary, the
				Secretary of Defense, the Director of the National Security Agency, the
				Director of the National Institute of Standards and Technology, and any other
				official, as directed by the President.</text>
								</paragraph><paragraph id="ID3a0d855ca4994341863fb540b2176110"><enum>(6)</enum><header>Prohibited
				actions</header><text>The authority to direct compliance with an emergency
				measure or action under this section shall not authorize the Director, the
				Center, the Department, or any other Federal entity to—</text>
									<subparagraph id="IDc27f601bb760412ba41b23a25cff4f4f"><enum>(A)</enum><text>restrict or
				prohibit communications carried by, or over, covered critical infrastructure
				and not specifically directed to or from the covered critical infrastructure
				unless the Director determines that no other emergency measure or action will
				preserve the reliable operation, and mitigate or remediate the consequences of
				the potential disruption, of the covered critical infrastructure or the
				national information infrastructure;</text>
									</subparagraph><subparagraph id="IDfc6a27e12e7b40a489c0fc8fc31c72ec"><enum>(B)</enum><text>control covered
				critical infrastructure;</text>
									</subparagraph><subparagraph id="IDed65b1ee5dbc4b768f646cf06ececb2b"><enum>(C)</enum><text>compel the
				disclosure of information unless specifically authorized by law; or</text>
									</subparagraph><subparagraph id="IDfa67b94081544ff597c43acf87824889"><enum>(D)</enum><text>intercept a wire,
				oral, or electronic communication (as those terms are defined in section 2510
				of title 18, United States Code), access a stored electronic or wire
				communication, install or use a pen register or trap and trace device, or
				conduct electronic surveillance (as defined in section 101 of the Foreign
				Intelligence Surveillance Act of 1978 (50 U.S.C. 1801)) relating to an
				incident, unless otherwise authorized under chapter 119, chapter 121, or
				chapter 206 of title 18, United States Code, or the Foreign Intelligence
				Surveillance Act of 1978 (50 U.S.C. 1801 et seq.).</text>
									</subparagraph></paragraph><paragraph id="IDf3022b7b878a42788da031b59fda8c8f"><enum>(7)</enum><header>Privacy</header><text>In
				carrying out this section, the Director shall ensure that the privacy and civil
				liberties of United States persons are protected.</text>
								</paragraph></subsection><subsection id="ID340f34eb49634b3cad892f286d84b5af"><enum>(b)</enum><header>Discontinuance
				of emergency measures</header>
								<paragraph id="ID7f81e2471e5448a6800b30e20b256bc4"><enum>(1)</enum><header>In
				general</header><text>Any emergency measure or action developed under this
				section shall cease to have effect not later than 30 days after the date on
				which the President issued the declaration of a national cyber emergency,
				unless—</text>
									<subparagraph id="IDa6115782b7b9455e83740252449d7fe0"><enum>(A)</enum><text>the Director
				details in writing why the emergency measure or action remains necessary to
				address the identified national cyber emergency; and</text>
									</subparagraph><subparagraph id="IDae4ec27f230b400ba72c0e5b4dff3aee"><enum>(B)</enum><text>the President
				issues a written order or directive reaffirming the national cyber emergency,
				the continuing nature of the national cyber emergency, or the need to continue
				the adoption of the emergency measure or action.</text>
									</subparagraph></paragraph><paragraph id="ID767de0c2ef2a476180329e5b43ede3f4"><enum>(2)</enum><header>Extensions</header><text>An
				emergency measure or action extended in accordance with paragraph (1)
				may—</text>
									<subparagraph id="ID7ec31f26fec34559aa8002e5f7b87528"><enum>(A)</enum><text>remain in effect
				for not more than 30 days after the date on which the emergency measure or
				action was to cease to have effect; and</text>
									</subparagraph><subparagraph id="ID706750dd32dc4885b95bc4487a850d77"><enum>(B)</enum><text>unless a joint
				resolution described in subsection (f)(1) is enacted, be extended for not more
				than 3 additional 30-day periods, if the requirements of paragraph (1) and
				subsection (d) are met.</text>
									</subparagraph></paragraph></subsection><subsection id="ID11afa85b1a2743ecb1b64ef48e20a30c"><enum>(c)</enum><header>Compliance with
				emergency measures</header>
								<paragraph id="ID331d43ed5ceb4ac0ab96c7d38263bc6a"><enum>(1)</enum><header>In
				general</header><text>Subject to paragraph (2), the owner or operator of
				covered critical infrastructure shall immediately comply with any emergency
				measure or action developed by the Director under this section during the
				pendency of any declaration by the President under subsection (a)(1) or an
				extension under subsection (b)(2).</text>
								</paragraph><paragraph id="IDcb93fa710eb440cca8fcdcc5e8b30fea"><enum>(2)</enum><header>Alternative
				measures</header>
									<subparagraph id="id3D0241017EDB4A65903746D069380450"><enum>(A)</enum><header>In
				general</header><text>If the Director determines that a proposed security
				measure, or any combination thereof, submitted by the owner or operator of
				covered critical infrastructure in accordance with the process established
				under section 248(b)(2) will effectively mitigate or remediate the cyber risk
				associated with the national cyber emergency that is the subject of the
				declaration under this section, or effectively mitigate or remediate the
				consequences of the potential disruption of the covered critical infrastructure
				based on the cyber risk at least as effectively as the emergency measures or
				actions directed by the Director under this section, the owner or operator may
				comply with paragraph (1) of this subsection by implementing the proposed
				security measure, or combination thereof, approved by the Director under the
				process established under section 248.</text>
									</subparagraph><subparagraph id="id2B93BA3E15924394ABEBEAF0D2715866"><enum>(B)</enum><header>Compliance
				pending submission or approval</header><text>Before submission of a proposed
				security measure, or combination thereof, and during the pendency of any review
				by the Director under the process established under section 248, the owner or
				operator of covered critical infrastructure shall remain in compliance with any
				emergency measure or action developed by the Director under this section during
				the pendency of any declaration by the President under subsection (a)(1) or an
				extension under subsection (b)(2), until such time as the Director has approved
				an alternative proposed security measure, or combination thereof, under this
				paragraph.</text>
									</subparagraph></paragraph><paragraph id="IDbf2d53fe55ad43448673e468f8599c25"><enum>(3)</enum><header>International
				cooperation on national cyber emergencies</header>
									<subparagraph id="ID07b5b697cde2462aa8681111cb623e83"><enum>(A)</enum><header>In
				general</header><text>The Director, in coordination with the head of the
				sector-specific agency with responsibility for covered critical infrastructure
				and the head of any Federal agency that is not a sector-specific agency with
				responsibilities for regulating the covered critical infrastructure,
				shall—</text>
										<clause id="id1476AFA675814FACBA22D28DEBBDCF4F"><enum>(i)</enum><text>consistent with
				the protection of intelligence sources and methods and other sensitive matters,
				inform the owner or operator of information infrastructure located outside the
				United States the disruption of which could result in national or regional
				catastrophic damage in the United States and the government of the country in
				which the information infrastructure is located of any cyber risks to the
				information infrastructure that led to the declaration of a national cyber
				emergency; and</text>
										</clause><clause id="idB705F0D41E3348729C26D46F3DDB245B"><enum>(ii)</enum><text>coordinate with
				the government of the country in which the information infrastructure is
				located and, as appropriate, the owner or operator of the information
				infrastructure, regarding the implementation of emergency measures or actions
				necessary to preserve the reliable operation, and mitigate or remediate the
				consequences of the potential disruption, of covered critical infrastructure
				that is the subject of the national cyber emergency.</text>
										</clause></subparagraph><subparagraph id="idE83E88A7E3B04B4C8A09A301AEC7B215"><enum>(B)</enum><header>International
				agreements</header><text>The Director shall carry out this paragraph in a
				manner consistent with applicable international agreements.</text>
									</subparagraph></paragraph></subsection><subsection id="IDa767692030374190bb04d2f20d5abac2"><enum>(d)</enum><header>Reporting</header>
								<paragraph id="ID3e62f327bda8413f960d321a6ea1288e"><enum>(1)</enum><header>In
				general</header><text>Except as provided in paragraph (2), the President shall
				ensure that any declaration under subsection (a)(1) or any extension under
				subsection (b)(2) is reported to the appropriate committees of Congress before
				the Director mandates any emergency measure or actions under subsection
				(a)(3).</text>
								</paragraph><paragraph id="ID48aeb2151b2e43148a5d1db9bb76358e"><enum>(2)</enum><header>Exception</header><text>If
				notice cannot be given under paragraph (1) before mandating any emergency
				measure or actions under subsection (a)(3), the President shall provide the
				report required under paragraph (1) as soon as possible, along with a statement
				of the reasons for not providing notice in accordance with paragraph
				(1).</text>
								</paragraph><paragraph id="ID10ec05b3286e44018179078fe487734f"><enum>(3)</enum><header>Contents</header><text>Each
				report under this subsection shall describe—</text>
									<subparagraph id="id112F0575F0A0449C9D3699A05415508B"><enum>(A)</enum><text>the nature of the
				national cyber emergency;</text>
									</subparagraph><subparagraph id="idD857E4D240C44A718FEEE93C57DF7E6B"><enum>(B)</enum><text>the reasons that
				risk-based security requirements under section 248 are not sufficient to
				address the national cyber emergency;</text>
									</subparagraph><subparagraph id="idDE2BECD4D5EF4E4189A4634BC9901D3C"><enum>(C)</enum><text>the actions
				necessary to preserve the reliable operation and mitigate the consequences of
				the potential disruption of covered critical infrastructure; and</text>
									</subparagraph><subparagraph id="ID4c07c1e823404bc1905c32084fe11b5f"><enum>(D)</enum><text>in the case of an
				extension of a national cyber emergency under subsection (b)(2)—</text>
										<clause id="ID488cd2793c1047b3bbc5eb3f650edf87"><enum>(i)</enum><text>why the emergency
				measures or actions continue to be necessary to address the national cyber
				emergency; and</text>
										</clause><clause id="IDdfe3f7251b8e479fbae27fe06450e97e"><enum>(ii)</enum><text>when the
				President expects the national cyber emergency to abate.</text>
										</clause></subparagraph></paragraph></subsection><subsection id="IDf8017650600948d5bbf4c7b0be821a76"><enum>(e)</enum><header>Statutory
				defenses and civil liability limitations for compliance with emergency
				measures</header>
								<paragraph id="id822EA42A6A41416E9333D02CB67CF99A"><enum>(1)</enum><header>Definitions</header><text>In
				this subsection—</text>
									<subparagraph id="id78E91F1A9BB240B79F51F67369F51B1B"><enum>(A)</enum><text>the term
				<term>covered civil action</term>—</text>
										<clause id="id0CD1A30024844F86B81B54A5B2E3B04E"><enum>(i)</enum><text>means a civil
				action filed in a Federal or State court against a covered entity; and</text>
										</clause><clause id="id7C0FA85EBC9545C983C346F6D42230CD"><enum>(ii)</enum><text>does not include
				an action brought under section 2520 or 2707 of title 18, United States Code,
				or section 110 or 308 of the Foreign Intelligence Surveillance Act of 1978 (50
				U.S.C. 1810 and 1828);</text>
										</clause></subparagraph><subparagraph id="id9C1C3BC9EFB44AEAAC3F744022CE7248"><enum>(B)</enum><text>the term
				<term>covered entity</term> means any entity that owns or operates covered
				critical infrastructure, including any owner, operator, officer, employee,
				agent, landlord, custodian, provider of information technology, or other person
				acting for or on behalf of that entity with respect to the covered critical
				infrastructure; and</text>
									</subparagraph><subparagraph id="id96903004617F4338B777A608888341E3"><enum>(C)</enum><text>the term
				<term>noneconomic damages</term> means damages for losses for physical and
				emotional pain, suffering, inconvenience, physical impairment, mental anguish,
				disfigurement, loss of enjoyment of life, loss of society and companionship,
				loss of consortium, hedonic damages, injury to reputation, and any other
				nonpecuniary losses.</text>
									</subparagraph></paragraph><paragraph id="ID3982d5d920474e5590f14f15cbacf47d"><enum>(2)</enum><header>Application of
				limitations on civil liability</header><text>The limitations on civil liability
				under paragraph (3) apply if—</text>
									<subparagraph id="IDc35d566d8e034738b44009ef62876dd4"><enum>(A)</enum><text>the President has
				issued a declaration of national cyber emergency under subsection
				(a)(1);</text>
									</subparagraph><subparagraph id="IDeecec5daccc547a79dc1eb2a18ffc0c6"><enum>(B)</enum><text>the Director
				has—</text>
										<clause id="id2E12F2E731E64DF9A815513B460AC401"><enum>(i)</enum><text>issued emergency
				measures or actions for which compliance is required under subsection (c)(1);
				or</text>
										</clause><clause id="id60178AAF9BB0487ABD3D57DC8688ECAF"><enum>(ii)</enum><text>approved
				security measures under subsection (c)(2);</text>
										</clause></subparagraph><subparagraph id="ID063ab167b1394a6cb77bb8bdc7a2c057"><enum>(C)</enum><text>the covered
				entity is in compliance with—</text>
										<clause id="id1F834F414CD64408A893E167989AB7EB"><enum>(i)</enum><text>the emergency
				measures or actions required under subsection (c)(1); or</text>
										</clause><clause id="idB00A425C2C3A4B7FA9F69C9400E8E0A3"><enum>(ii)</enum><text>security
				measures which the Director has approved under subsection (c)(2); and</text>
										</clause></subparagraph><subparagraph id="IDa8ee18f3d49f4797a31906431f682f29"><enum>(D)</enum><clause commented="no" display-inline="yes-display-inline" id="id8AD26A7AF1C645AE882941D41C1EBC72"><enum>(i)</enum><text>the Director certifies
				to the court in which the covered civil action is pending that the actions
				taken by the covered entity during the period covered by the declaration under
				subsection (a)(1) were consistent with—</text>
											<subclause id="idB37324AEC51C465CAD651FF4ACAD4E6D" indent="up1"><enum>(I)</enum><text>emergency measures or actions for which
				compliance is required under subsection (c)(1); or</text>
											</subclause><subclause id="id890C41215C564B15A4BB957A5DA015D3" indent="up1"><enum>(II)</enum><text>security measures which the Director has
				approved under subsection (c)(2); or</text>
											</subclause></clause><clause id="id101A0F2802E446C49FABD97B250C7A8F" indent="up1"><enum>(ii)</enum><text>notwithstanding the lack of a
				certification, the covered entity demonstrates by a preponderance of the
				evidence that the actions taken during the period covered by the declaration
				under subsection (a)(1) are consistent with the implementation of—</text>
											<subclause id="id5EE620A432B94C00B54598D6D5F9B5D8"><enum>(I)</enum><text>emergency measures or actions for which
				compliance is required under subsection (c)(1); or</text>
											</subclause><subclause id="id9133146D138A42B09BC2391F5750652C"><enum>(II)</enum><text>security measures which the Director has
				approved under subsection (c)(2).</text>
											</subclause></clause></subparagraph></paragraph><paragraph id="ID80a341622a50457db587cface0a6ffba"><enum>(3)</enum><header>Limitations on
				civil liability</header><text>In any covered civil action that is related to
				any incident associated with a cyber risk covered by a declaration of a
				national cyber emergency and for which Director has issued emergency measures
				or actions for which compliance is required under subsection (c)(1) or for
				which the Director has approved security measures under subsection (c)(2), or
				that is the direct consequence of actions taken in good faith for the purpose
				of implementing security measures or actions which the Director has approved
				under subsection (c)(2)—</text>
									<subparagraph id="ID7192deb87f3f453db7679f374aac2e6d"><enum>(A)</enum><text>the covered
				entity shall not be liable for any punitive damages intended to punish or
				deter, exemplary damages, or other damages not intended to compensate a
				plaintiff for actual losses; and</text>
									</subparagraph><subparagraph commented="no" id="ID6d66af0fb16b4787afae5380b085b1de"><enum>(B)</enum><text>noneconomic
				damages may be awarded against a defendant only in an amount directly
				proportional to the percentage of responsibility of such defendant for the harm
				to the plaintiff, and no plaintiff may recover noneconomic damages unless the
				plaintiff suffered physical harm.</text>
									</subparagraph></paragraph><paragraph id="ID973822391b16422d9c11eb256ba4eee1"><enum>(4)</enum><header>Civil actions
				arising out of implementation of emergency measures or actions</header><text>A
				covered civil action may not be maintained against a covered entity that is the
				direct consequence of actions taken in good faith for the purpose of
				implementing specific emergency measures or actions for which compliance is
				required under subsection (c)(1), if—</text>
									<subparagraph id="ID75e43349d8a4432c99ca96e49466adf2"><enum>(A)</enum><text>the President has
				issued a declaration of national cyber emergency under subsection (a)(1) and
				the action was taken during the period covered by that declaration;</text>
									</subparagraph><subparagraph id="IDc6342d523485462ebebd08c97bbcd987"><enum>(B)</enum><text>the Director has
				issued emergency measures or actions for which compliance is required under
				subsection (c)(1) or that the Director has approved under subsection
				(c)(2);</text>
									</subparagraph><subparagraph id="IDa96f1fd910c44aa4990d772c9aaacb91"><enum>(C)</enum><text>the covered
				entity is in compliance with the emergency measures required under subsection
				(c)(1) or that the Director has approved under subsection (c)(2); and</text>
									</subparagraph><subparagraph id="ID06807ecc14494c5f916c32a3ce66ae5d"><enum>(D)</enum><clause commented="no" display-inline="yes-display-inline" id="idB3F2E418D3004D01894B42BEF31EEAB2"><enum>(i)</enum><text>the Director certifies
				to the court in which the covered civil action is pending that the actions
				taken by the entity during the period covered by the declaration under
				subsection (a)(1) were consistent with the implementation of emergency measures
				or actions for which compliance is required under subsection (c)(1) or that the
				Director has approved under subsection (c)(2); or</text>
										</clause><clause id="idC69094503E2C4BE981427D296EEA68B6" indent="up1"><enum>(ii)</enum><text>notwithstanding the lack of a
				certification, the entity demonstrates by a preponderance of the evidence that
				the actions taken during the period covered by the declaration under subsection
				(a)(1) are consistent with the implementation of emergency measures or actions
				for which compliance is required under subsection (c)(1) or that the Director
				has approved under subsection (c)(2).</text>
										</clause></subparagraph></paragraph><paragraph id="ID3d68205648c94a4c8ac09a5a687af996"><enum>(5)</enum><header>Certain actions
				not subject to limitations on liability</header>
									<subparagraph id="IDa62198fe3a1f49899b5bdd563f8a77b6"><enum>(A)</enum><header>Additional or
				intervening acts</header><text>Paragraphs (2) through (4) shall not apply to a
				civil action relating to any additional or intervening acts or omissions by any
				covered entity.</text>
									</subparagraph><subparagraph commented="no" id="IDec902ac60bd740b4b77ebf63cd64e138"><enum>(B)</enum><header>Serious or
				substantial damage</header><text>Paragraph (4) shall not apply to any civil
				action brought by an individual—</text>
										<clause commented="no" id="ID2e68b8cabb814909a9d6bbce65f9ffb3"><enum>(i)</enum><text>whose recovery is
				otherwise precluded by application of paragraph (4); and</text>
										</clause><clause commented="no" id="IDb74bfa0b369043b89cc527ed5e7fccf3"><enum>(ii)</enum><text>who has
				suffered—</text>
											<subclause commented="no" id="ID073671fa87d34e0198ff8f3eefdc45b5"><enum>(I)</enum><text>serious physical
				injury or death; or</text>
											</subclause><subclause commented="no" id="id99C4C92DC4344046B6E2A2569F04D11E"><enum>(II)</enum><text>substantial
				damage or destruction to his primary residence.</text>
											</subclause></clause></subparagraph><subparagraph id="ID0a1137bc77584f8b8d0883067079c62a"><enum>(C)</enum><header>Rule of
				construction</header><text>Recovery available under subparagraph (B) shall be
				limited to those damages available under subparagraphs (A) and (B) of paragraph
				(3), except that neither reasonable and necessary medical benefits nor lifetime
				total benefits for lost employment income due to permanent and total disability
				shall be limited herein.</text>
									</subparagraph><subparagraph id="ID45a3329648814452b82b188c42e799a3"><enum>(D)</enum><header>Indemnification</header><text>In
				any civil action brought under subparagraph (B), the United States shall defend
				and indemnify any covered entity. Any covered entity defended and indemnified
				under this subparagraph shall fully cooperate with the United States in the
				defense by the United States in any proceeding and shall be reimbursed the
				reasonable costs associated with such cooperation.</text>
									</subparagraph></paragraph></subsection><subsection commented="no" id="idF486E37C564B4AA98D578CDFFFB6B7FC"><enum>(f)</enum><header>Joint
				resolution To extend cyber emergency</header>
								<paragraph commented="no" id="IDfbbf10ea1955442aa899cc395f53c148"><enum>(1)</enum><header>In
				general</header><text>For purposes of subsection (b)(2)(B), a joint resolution
				described in this paragraph means only a joint resolution—</text>
									<subparagraph commented="no" id="ID33f0998d6f4845798e15d6644e4994c4"><enum>(A)</enum><text>the title of
				which is as follows: <quote>Joint resolution approving the extension of a cyber
				emergency</quote>; and</text>
									</subparagraph><subparagraph commented="no" id="IDf0598201c0d643d684d8fbbde550521b"><enum>(B)</enum><text>the matter after
				the resolving clause of which is as follows: <quote>That Congress approves the
				continuation of the emergency measure or action issued by the Director of the
				National Center for Cybersecurity and Communications on ____________ for not
				longer than an additional 120-day period.</quote>, the blank space being filled
				in with the date on which the emergency measure or action to which the joint
				resolution applies was issued.</text>
									</subparagraph></paragraph><paragraph commented="no" id="ID3a8c314caab744cab2ffabdb455226b0"><enum>(2)</enum><header>Procedure</header>
									<subparagraph commented="no" id="ID89ce83ae88d54aeabf720416964155fe"><enum>(A)</enum><header>No
				referral</header><text>A joint resolution described in paragraph (1) shall not
				be referred to a committee in either House of Congress and shall immediately be
				placed on the calendar.</text>
									</subparagraph><subparagraph commented="no" id="ID493e54cd8e294711b0ecd35530e94b84"><enum>(B)</enum><header>Consideration</header>
										<clause commented="no" id="ID80b51d6e3b574d84b12461da85c9cbf8"><enum>(i)</enum><header>Debate
				limitation</header><text>A motion to proceed to a joint resolution described in
				paragraph (1) is highly privileged in the House of Representatives and is
				privileged in the Senate and is not debatable. The motion is not subject to a
				motion to postpone. In the Senate, consideration of the joint resolution, and
				on all debatable motions and appeals in connection therewith, shall be limited
				to not more than 10 hours, which shall be divided equally between the majority
				leader and the minority leader, or their designees. A motion further to limit
				debate is in order and not debatable. All points of order against the joint
				resolution (and against consideration of the joint resolution) are waived. An
				amendment to, or a motion to postpone, or a motion to proceed to the
				consideration of other business, or a motion to recommit the joint resolution
				is not in order.</text>
										</clause><clause commented="no" id="ID84ea9b5f38b54fcda44d5e6f184cadb5"><enum>(ii)</enum><header>Passage</header><text>In
				the Senate, immediately following the conclusion of the debate on a joint
				resolution described in paragraph (1), and a single quorum call at the
				conclusion of the debate if requested in accordance with the rules of the
				Senate, the vote on passage of the joint resolution shall occur.</text>
										</clause><clause commented="no" id="ID3c4fc59d622e449a8171b2f02e44671f"><enum>(iii)</enum><header>Appeals</header><text>Appeals
				from the decisions of the Chair relating to the application of the rules of the
				Senate to the procedure relating to a joint resolution described in paragraph
				(1) shall be decided without debate.</text>
										</clause></subparagraph><subparagraph commented="no" id="ID69e10188f861490da2ceb15f8bc005f0"><enum>(C)</enum><header>Other House
				acts first</header><text>If, before the passage by 1 House of a joint
				resolution of that House described in paragraph (1), that House receives from
				the other House a joint resolution described in paragraph (1)—</text>
										<clause commented="no" id="ID8bf7f9cb42ca4276bf36196a5d45d0d2"><enum>(i)</enum><text>the procedure in
				that House shall be the same as if no joint resolution had been received from
				the other House; and</text>
										</clause><clause commented="no" id="ID9b93a6aa6e304fe7856300a06816bbaa"><enum>(ii)</enum><text>the vote on
				final passage shall be on the joint resolution of the other House.</text>
										</clause></subparagraph><subparagraph commented="no" id="id27DD051A95D84D9E83E36338C28A3A32"><enum>(D)</enum><header>Majority
				required for adoption</header><text>A joint resolution considered under this
				subsection shall require an affirmative vote of a majority of the Members, duly
				chosen and sworn, for adoption.</text>
									</subparagraph></paragraph><paragraph commented="no" id="idE0E4D90843D34F7390A2E185E9DA6F8B"><enum>(3)</enum><header>Rulemaking</header><text>This
				subsection is enacted by Congress—</text>
									<subparagraph id="ID2e28ef4a87d34d2c867863db6cee91fc"><enum>(A)</enum><text>as an exercise of
				the rulemaking power of the Senate and the House of Representatives,
				respectively, and is deemed to be part of the rules of each House, respectively
				but applicable only with respect to the procedure to be followed in that House
				in the case of a joint resolution described in paragraph (1), and it supersedes
				other rules only to the extent that it is inconsistent with such rules;
				and</text>
									</subparagraph><subparagraph id="ID57271149441841358bb3414ad2622bba"><enum>(B)</enum><text>with full
				recognition of the constitutional right of either House to change the rules (so
				far as they relate to the procedure of that House) at any time, in the same
				manner, and to the same extent as in the case of any other rule of that
				House.</text>
									</subparagraph></paragraph></subsection><subsection id="ID5ddf6381103d42ea9e62eda94da456e1"><enum>(g)</enum><header>Rule of
				construction</header><text>Nothing in this section shall be construed
				to—</text>
								<paragraph id="ID8fc1fad2288f40a1aa780e11a9abc877"><enum>(1)</enum><text>alter or
				supersede the authority of the Secretary of Defense, the Attorney General, or
				the Director of National Intelligence in responding to a national cyber
				emergency; or</text>
								</paragraph><paragraph id="ID3b4d4b2cdcce4045b7afb5a8115da97e"><enum>(2)</enum><text>limit the
				authority of the Director under section 248, after a declaration issued under
				this section expires.</text>
								</paragraph></subsection></section><section id="IDe55bcbe958884fb4a262509e81f8f913"><enum>250.</enum><header>Enforcement</header>
							<subsection id="IDa0e01a1f1f98406985c8caa04ef80745"><enum>(a)</enum><header>Annual
				certification of compliance</header>
								<paragraph id="IDc1ed08ccb82d4f139e867bb15a502acc"><enum>(1)</enum><header>In
				general</header><text>Not later than 6 months after the date on which the
				Director promulgates regulations under section 248(b), and every year
				thereafter, each owner or operator of covered critical infrastructure shall
				certify in writing to the Director whether the owner or operator has developed
				and implemented, or is implementing, security measures approved by the Director
				under section 248 and any applicable emergency measures or actions required
				under section 249 for any cyber risks and national cyber emergencies.</text>
								</paragraph><paragraph id="ID503220269b6542f69a29a3396ebcab45"><enum>(2)</enum><header>Failure to
				comply</header><text>If an owner or operator of covered critical infrastructure
				fails to submit a certification in accordance with paragraph (1), or if the
				certification indicates the owner or operator is not in compliance, the
				Director may issue an order requiring the owner or operator to submit proposed
				security measures under section 248 or comply with specific emergency measures
				or actions under section 249.</text>
								</paragraph></subsection><subsection id="ID3a9439266792435483a1d0d738dc9209"><enum>(b)</enum><header>Risk-Based
				evaluations</header>
								<paragraph id="ID224fd902be1144a4ae5c5d6d852159a2"><enum>(1)</enum><header>In
				general</header><text>Consistent with the factors described in paragraph (3),
				the Director may perform an evaluation of the information infrastructure of any
				specific system or asset constituting covered critical infrastructure to assess
				the validity of a certification of compliance submitted under subsection
				(a)(1).</text>
								</paragraph><paragraph id="ID52a771a9ef554797af6aea60355f65c7"><enum>(2)</enum><header>Document review
				and inspection</header><text>An evaluation performed under paragraph (1) may
				include—</text>
									<subparagraph id="IDf0f4bd4b5dc044ccb2aaa3e363441bba"><enum>(A)</enum><text>a review of all
				documentation submitted to justify an annual certification of compliance
				submitted under subsection (a)(1); and</text>
									</subparagraph><subparagraph id="IDbf56ff79ff104c219e525570e3f0644f"><enum>(B)</enum><text>a physical or
				electronic inspection of relevant information infrastructure to which the
				security measures required under section 248 or the emergency measures or
				actions required under section 249 apply.</text>
									</subparagraph></paragraph><paragraph id="IDc72c39c0b0bf41f8aab61e6f88a6d84b"><enum>(3)</enum><header>Evaluation
				selection factors</header><text>In determining whether sufficient risk exists
				to justify an evaluation under this subsection, the Director shall
				consider—</text>
									<subparagraph id="ID594a1886d982448da2b293e6a49c0dc0"><enum>(A)</enum><text>the specific
				cyber risks affecting or potentially affecting the information infrastructure
				of the specific system or asset constituting covered critical
				infrastructure;</text>
									</subparagraph><subparagraph id="IDf995cf32cd444a5c97c57ab65eec522c"><enum>(B)</enum><text>any reliable
				intelligence or other information indicating a cyber risk or credible national
				cyber emergency to the information infrastructure of the specific system or
				asset constituting covered critical infrastructure;</text>
									</subparagraph><subparagraph id="ID17d1b6813eef4c799f339d04d5506d9b"><enum>(C)</enum><text>actual knowledge
				or reasonable suspicion that the certification of compliance submitted by a
				specific owner or operator of covered critical infrastructure is false or
				otherwise inaccurate;</text>
									</subparagraph><subparagraph id="ID971857ca64a042a38f930f16a517ac1e"><enum>(D)</enum><text>a request by a
				specific owner or operator of covered critical infrastructure for such an
				evaluation; and</text>
									</subparagraph><subparagraph id="ID3f4afab249044573a91512a3112cd265"><enum>(E)</enum><text>such other
				risk-based factors as identified by the Director.</text>
									</subparagraph></paragraph><paragraph id="ID084a30f209ce43a1958f0528533c5578"><enum>(4)</enum><header>Sector-specific
				agencies</header><text>To carry out the risk-based evaluation authorized under
				this subsection, the Director may use the resources of a sector-specific agency
				with responsibility for the covered critical infrastructure or any Federal
				agency that is not a sector-specific agency with responsibilities for
				regulating the covered critical infrastructure with the concurrence of the head
				of the agency.</text>
								</paragraph><paragraph id="IDe40802634d6c40fb9d39102c65bd70b2"><enum>(5)</enum><header>Information
				protection</header><text>Information provided to the Director during the course
				of an evaluation under this subsection shall be protected from disclosure in
				accordance with section 251.</text>
								</paragraph></subsection><subsection commented="no" id="IDfb5e1573a68f4948983232cfa868169a"><enum>(c)</enum><header>Civil
				penalties</header>
								<paragraph commented="no" id="ID23383613f3004c98b5c0d9757602e00f"><enum>(1)</enum><header>In
				general</header><text>Any person who violates section 248 or 249 shall be
				liable for a civil penalty.</text>
								</paragraph><paragraph commented="no" id="ID87cd53dc902b43c5a10b1fa8ad8c48c2"><enum>(2)</enum><header>No private
				right of action</header><text>Nothing in this section confers upon any person,
				except the Director, a right of action against an owner or operator of covered
				critical infrastructure to enforce any provision of this subtitle.</text>
								</paragraph></subsection><subsection id="IDf7469ffe66254205aeb3bf7f2297056a"><enum>(d)</enum><header>Limitation on
				civil liability</header>
								<paragraph id="ID2d8cbab281dc4f5eb51370c40e98e36d"><enum>(1)</enum><header>Definition</header><text>In
				this subsection—</text>
									<subparagraph id="idB6F38C85F67B4FD9B78D3F54CC80A09A"><enum>(A)</enum><text>the term
				<term>covered civil action</term>—</text>
										<clause id="id1018D1123F3444058C6ADC7C45452278"><enum>(i)</enum><text>means a civil
				action filed in a Federal or State court against a covered entity; and</text>
										</clause><clause id="id79B5B60C10604DDDB02877D1474791EE"><enum>(ii)</enum><text>does not include
				an action brought under section 2520 or 2707 of title 18, United States Code,
				or section 110 or 308 of the Foreign Intelligence Surveillance Act of 1978 (50
				U.S.C. 1810 and 1828);</text>
										</clause></subparagraph><subparagraph id="id0625CD532C5B4E7B8A80D4905399C585"><enum>(B)</enum><text>the term
				<term>covered entity</term> means any entity that owns or operates covered
				critical infrastructure, including any owner, operator, officer, employee,
				agent, landlord, custodian, provider of information technology, or other person
				acting for or on behalf of that entity with respect to the covered critical
				infrastructure; and</text>
									</subparagraph><subparagraph id="id77D7C5CE42E64026B7BB7E33749FDFC6"><enum>(C)</enum><text>the term
				<term>noneconomic damages</term> means damages for losses for physical and
				emotional pain, suffering, inconvenience, physical impairment, mental anguish,
				disfigurement, loss of enjoyment of life, loss of society and companionship,
				loss of consortium, hedonic damages, injury to reputation, and any other
				nonpecuniary losses.</text>
									</subparagraph></paragraph><paragraph id="ID34808f3d91b640179e4898be68e7c2cf"><enum>(2)</enum><header>Limitations on
				civil liability</header><text>If a covered entity experiences an incident
				related to a cyber risk identified under section 248(a), in any covered civil
				action for damages directly caused by the incident related to that cyber
				risk—</text>
									<subparagraph id="ID99e4d6cc6d1a4ab19cbb197a0d1c7471"><enum>(A)</enum><text>the covered
				entity shall not be liable for any punitive damages intended to punish or
				deter, exemplary damages, or other damages not intended to compensate a
				plaintiff for actual losses; and</text>
									</subparagraph><subparagraph id="ID8ca257c06d2146ad900b5a6079b7f732"><enum>(B)</enum><text>noneconomic
				damages may be awarded against a defendant only in an amount directly
				proportional to the percentage of responsibility of such defendant for the harm
				to the plaintiff, and no plaintiff may recover noneconomic damages unless the
				plaintiff suffered physical harm.</text>
									</subparagraph></paragraph><paragraph id="ID223aa1c9c2034a28985933e5fbc11628"><enum>(3)</enum><header>Application</header><text>This
				subsection shall apply to claims made by any individual or nongovernmental
				entity, including claims made by a State or local government agency on behalf
				of such individuals or nongovernmental entities, against a covered
				entity—</text>
									<subparagraph id="ID5c50131dbbb84ee1967e83bab8a32b4c"><enum>(A)</enum><text>whose proposed
				security measures, or combination thereof, satisfy the security performance
				requirements established under subsection 248(b) and have been approved by the
				Director;</text>
									</subparagraph><subparagraph id="ID59ab62220ed94adda9446ed7fd0b3930"><enum>(B)</enum><text>that has been
				evaluated under subsection (b) and has been found by the Director to have
				implemented the proposed security measures approved under section 248;
				and</text>
									</subparagraph><subparagraph id="ID66846de40caa4536bd11b67c39f561ce"><enum>(C)</enum><text>that is in actual
				compliance with the approved security measures at the time of the incident
				related to that cyber risk.</text>
									</subparagraph></paragraph><paragraph id="ID53c601ba142e45689be2b3856d350527"><enum>(4)</enum><header>Limitation</header><text>This
				subsection shall only apply to harm directly caused by the incident related to
				the cyber risk and shall not apply to damages caused by any additional or
				intervening acts or omissions by the covered entity.</text>
								</paragraph><paragraph id="ID713bddcc18be41ef8efd3158e715f579"><enum>(5)</enum><header>Rule of
				construction</header><text>Except as provided under paragraph (3), nothing in
				this subsection shall be construed to abrogate or limit any right, remedy, or
				authority that the Federal Government or any State or local government, or any
				entity or agency thereof, may possess under any law, or that any individual is
				authorized by law to bring on behalf of the government.</text>
								</paragraph></subsection><subsection id="IDdbc2dfc6f2014e0298077c67fdbfce0d"><enum>(e)</enum><header>Report to
				Congress</header><text>The Director shall submit an annual report to the
				appropriate committees of Congress on the implementation and enforcement of the
				risk-based security performance requirements of covered critical infrastructure
				under subsection 248(b) and this section including—</text>
								<paragraph id="IDab50b9dc6fc449d28c787bc04cae4365"><enum>(1)</enum><text>the level of
				compliance of covered critical infrastructure with the risk-based security
				performance requirements issued under section 248(b);</text>
								</paragraph><paragraph id="ID1276c917e5fd4276b01552644f0686fd"><enum>(2)</enum><text>how frequently
				the evaluation authority under subsection (b) was utilized and a summary of the
				aggregate results of the evaluations; and</text>
								</paragraph><paragraph id="IDb8f973f6f9de4092ae7d61301dd0781b"><enum>(3)</enum><text>any civil
				penalties imposed on covered critical infrastructure.</text>
								</paragraph></subsection></section><section commented="no" id="IDd1766abbf9ec4ed8ad7d8fe630e5fb0b"><enum>251.</enum><header>Protection of
				information</header>
							<subsection commented="no" id="id33A9583A5D504C8D9662264D2883EDBE"><enum>(a)</enum><header>Definition</header><text>In
				this section, the term <term>covered information</term>—</text>
								<paragraph commented="no" id="idC5E0E0E6E5654B369D5F0B6A057F3763"><enum>(1)</enum><text>means—</text>
									<subparagraph id="IDccf75feacc1d4f5d99cb5d76ba45e313"><enum>(A)</enum><text>any information
				required to be submitted under sections 246, 248, and 249 to the Center by the
				owners and operators of covered critical infrastructure; and</text>
									</subparagraph><subparagraph id="IDdc438606dc9d48eca222f52ec4fe1d31"><enum>(B)</enum><text>any information
				submitted to the Center under the processes and procedures established under
				section 246 by State and local governments, private entities, and international
				partners of the United States regarding threats, vulnerabilities, and incidents
				affecting—</text>
										<clause id="idC27747A13DE541BB932855764ECA0A95"><enum>(i)</enum><text>the Federal
				information infrastructure;</text>
										</clause><clause id="id380C3BE7EF704D40A6310FE677E5B152"><enum>(ii)</enum><text>information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, the Department of Defense, a military department, or another
				element of the intelligence community; or</text>
										</clause><clause id="id1068B71D4E2B4D448FA60F0D33313255"><enum>(iii)</enum><text>the national
				information infrastructure; and</text>
										</clause></subparagraph></paragraph><paragraph id="idF033D591A4144E44B911A24FD99B6591"><enum>(2)</enum><text>shall not include
				any information described under paragraph (1), if that information is submitted
				to—</text>
									<subparagraph id="ID7f5ee556803b481cbc1a45294de225f9"><enum>(A)</enum><text>conceal
				violations of law, inefficiency, or administrative error;</text>
									</subparagraph><subparagraph id="ID02bbb6c573ae4755acb45ac8d905d5ef"><enum>(B)</enum><text>prevent
				embarrassment to a person, organization, or agency; or</text>
									</subparagraph><subparagraph id="IDffc023cef286401a95badd2fd373f5f1"><enum>(C)</enum><text>interfere with
				competition in the private sector.</text>
									</subparagraph></paragraph></subsection><subsection id="id039605E4EE4E48C49B1FDA20565EFB6F"><enum>(b)</enum><header>Voluntarily
				shared critical infrastructure information</header><text>Covered information
				submitted in accordance with this section shall be treated as voluntarily
				shared critical infrastructure information under section 214, except that the
				requirement of section 214 that the information be voluntarily submitted,
				including the requirement for an express statement, shall not be required for
				submissions of covered information.</text>
							</subsection><subsection id="IDeb1c6964124a45aca375ae1da86f008b"><enum>(c)</enum><header>Guidelines</header>
								<paragraph id="IDa8f1351f95004e9f976cd9460e2c6dbb"><enum>(1)</enum><header>In
				general</header><text>Subject to paragraph (2), the Director shall develop and
				issue guidelines, in consultation with the Secretary, the Attorney General, and
				the National Cybersecurity Advisory Council, as necessary to implement this
				section.</text>
								</paragraph><paragraph id="IDb6b8aa77a905471ea62c9dccc3f97ff9"><enum>(2)</enum><header>Requirements</header><text>The
				guidelines developed under this section shall—</text>
									<subparagraph id="ID220dd2673b2448ebac5d14f9f9316ed1"><enum>(A)</enum><text>consistent with
				subsections (e)(2)(D) and (g) of section 214 and the processes, procedures, and
				guidelines developed under section 246(b), include provisions for information
				sharing among Federal, State, and local and officials, private entities, or
				international partners of the United States necessary to carry out the
				authorities and responsibilities of the Director;</text>
									</subparagraph><subparagraph id="ID13d453b5b0724760a90520562bae34b6"><enum>(B)</enum><text>be consistent, to
				the maximum extent possible, with policy guidance and implementation standards
				developed by the National Archives and Records Administration for controlled
				unclassified information, including with respect to marking, safeguarding,
				dissemination and dispute resolution; and</text>
									</subparagraph><subparagraph id="ID26f18291b18d42c99eed4dd31df85288"><enum>(C)</enum><text>describe, with as
				much detail as possible, the categories and type of information entities should
				voluntarily submit under subsections (b) and (c)(1)(B) of section 246.</text>
									</subparagraph></paragraph></subsection><subsection id="IDab43891a056f44ab8580e18d4133858c"><enum>(d)</enum><header>Process for
				reporting security problems</header>
								<paragraph id="IDd2cff708c5dc42b7aae34ada31a20232"><enum>(1)</enum><header>Establishment
				of process</header><text>The Director shall establish through regulation, and
				provide information to the public regarding, a process by which any person may
				submit a report to the Secretary regarding cybersecurity threats,
				vulnerabilities, and incidents affecting—</text>
									<subparagraph id="idB6AF6796AC3843DDB19D19623DD59DAC"><enum>(A)</enum><text>the Federal
				information infrastructure;</text>
									</subparagraph><subparagraph id="id972556AE3FE54D099EEB9346945F826B"><enum>(B)</enum><text>information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, the Department of Defense, a military department, or another
				element of the intelligence community; or</text>
									</subparagraph><subparagraph id="id1CD30243358D4C74B6C45B2348A2D16A"><enum>(C)</enum><text>national
				information infrastructure.</text>
									</subparagraph></paragraph><paragraph id="ID94628805293b4e8da06203d8d7e7fc4b"><enum>(2)</enum><header>Acknowledgment
				of receipt</header><text>If a report submitted under paragraph (1) identifies
				the person making the report, the Director shall respond promptly to such
				person and acknowledge receipt of the report.</text>
								</paragraph><paragraph id="ID5e709b9402244d618ac62cfe8def5d0c"><enum>(3)</enum><header>Steps to
				address problem</header><text>The Director shall review and consider the
				information provided in any report submitted under paragraph (1) and, at the
				sole, unreviewable discretion of the Director, determine what, if any, steps
				are necessary or appropriate to address any problems or deficiencies
				identified.</text>
								</paragraph><paragraph id="ID9dcc6084394b474595c1dabaf407136b"><enum>(4)</enum><header>Disclosure of
				identity</header>
									<subparagraph id="IDec8fda1b23be4a5b928385dbd900668c"><enum>(A)</enum><header>In
				general</header><text>Except as provided in subparagraph (B), or with the
				written consent of the person, the Secretary may not disclose the identity of a
				person who has provided information described in paragraph (1).</text>
									</subparagraph><subparagraph id="ID8ada5e14d26b42e8a2158fccfd194b47"><enum>(B)</enum><header>Referral to the
				Attorney General</header><text>The Secretary shall disclose to the Attorney
				General the identity of a person described under subparagraph (A) if the matter
				is referred to the Attorney General for enforcement. The Director shall provide
				reasonable advance notice to the affected person if disclosure of that person’s
				identity is to occur, unless such notice would risk compromising a criminal or
				civil enforcement investigation or proceeding.</text>
									</subparagraph></paragraph></subsection><subsection id="idCD1EB74779AF4E4982FD7EC5FC55C5FE"><enum>(e)</enum><header>Rules of
				construction</header><text>Nothing in this section shall be construed
				to—</text>
								<paragraph id="id81A4B502BD6F486EB5AA4AD4A0EFF227"><enum>(1)</enum><text>limit or
				otherwise affect the right, ability, duty, or obligation of any entity to use
				or disclose any information of that entity, including in the conduct of any
				judicial or other proceeding;</text>
								</paragraph><paragraph id="id5F5E7654A1F5414996F2C1994650EF5E"><enum>(2)</enum><text>prevent the
				classification of information submitted under this section if that information
				meets the standards for classification under Executive Order 12958 or any
				successor of that order or affect measures and controls relating to the
				protection of classified information as prescribed by Federal statute or under
				Executive Order 12958, or any successor of that order;</text>
								</paragraph><paragraph id="id8B9D1096DB854208A90B4C17712A40BB"><enum>(3)</enum><text>limit the right
				of an individual to make any disclosure—</text>
									<subparagraph id="idEE5598399B3F4669819F9B63597239F5"><enum>(A)</enum><text>protected or
				authorized under section 2302(b)(8) or 7211 of title 5, United States
				Code;</text>
									</subparagraph><subparagraph id="idA115E925D3514281A5D660913F96AB77"><enum>(B)</enum><text>to an appropriate
				official of information that the individual reasonably believes evidences a
				violation of any law, rule, or regulation, gross mismanagement, or substantial
				and specific danger to public health, safety, or security, and that is
				protected under any Federal or State law (other than those referenced in
				subparagraph (A)) that shields the disclosing individual against retaliation or
				discrimination for having made the disclosure if such disclosure is not
				specifically prohibited by law and if such information is not specifically
				required by Executive order to be kept secret in the interest of national
				defense or the conduct of foreign affairs; or</text>
									</subparagraph><subparagraph id="id64DE5F05810A4F22971A3EF460B2E9C3"><enum>(C)</enum><text>to the Special
				Counsel, the inspector general of an agency, or any other employee designated
				by the head of an agency to receive similar disclosures;</text>
									</subparagraph></paragraph><paragraph id="idA7DEB17FD8E346D7AC5BAF6BE1978287"><enum>(4)</enum><text>prevent the
				Director from using information required to be submitted under sections 246,
				248, or 249 for enforcement of this subtitle, including enforcement proceedings
				subject to appropriate safeguards;</text>
								</paragraph><paragraph id="id0C865674BC4A44CC98D35507911ACE02"><enum>(5)</enum><text>authorize
				information to be withheld from Congress, the Government Accountability Office,
				or Inspector General of the Department;</text>
								</paragraph><paragraph id="ID2f198bc37e5742489e754b8da43c90bb"><enum>(6)</enum><text>affect
				protections afforded to trade secrets under any other provision of law;
				or</text>
								</paragraph><paragraph id="id30CC206F36BF4E758C44EF4F44ED4EA2"><enum>(7)</enum><text>create a private
				right of action for enforcement of any provision of this section.</text>
								</paragraph></subsection><subsection id="id7D52F7582E5240AC861FD2897809D43D"><enum>(f)</enum><header>Audit</header>
								<paragraph id="id34E5BBD5DF19414B8EA29E308D72FB62"><enum>(1)</enum><header>In
				general</header><text>Not later than 1 year after the date of enactment of the
				<short-title>Cybersecurity and Internet Freedom Act of
				2011</short-title>, the Inspector General of the Department shall conduct an
				audit of the management of information submitted under subsection (b) and
				report the findings to appropriate committees of Congress.</text>
								</paragraph><paragraph id="idCC9A676FCC4E445D99B7FAAB4EC51C4E"><enum>(2)</enum><header>Contents</header><text>The
				audit under paragraph (1) shall include assessments of—</text>
									<subparagraph id="idDEA645E740A1488FB4766204F9692F6D"><enum>(A)</enum><text>whether the
				information is adequately safeguarded against inappropriate disclosure;</text>
									</subparagraph><subparagraph id="id63CCEA0E71D9452FAB7DE5EDFFE76ACF"><enum>(B)</enum><text>the processes for
				marking and disseminating the information and resolving any disputes;</text>
									</subparagraph><subparagraph id="idB289865CA3844059892846419FEB3DBE"><enum>(C)</enum><text>how the
				information is used for the purposes of this section, and whether that use is
				effective;</text>
									</subparagraph><subparagraph id="id62B7F95E43A0495DB621A96D0210831E"><enum>(D)</enum><text>whether
				information sharing has been effective to fulfill the purposes of this
				section;</text>
									</subparagraph><subparagraph id="id5856F3A79EB4408A83F5C09345EF4BA0"><enum>(E)</enum><text>whether the kinds
				of information submitted have been appropriate and useful, or overbroad or
				overnarrow;</text>
									</subparagraph><subparagraph id="idC655A5C81BCA4F408BDBA31142A7D4FF"><enum>(F)</enum><text>whether the
				information protections allow for adequate accountability and transparency of
				the regulatory, enforcement, and other aspects of implementing this subtitle;
				and</text>
									</subparagraph><subparagraph id="idE1A7C12C4CF4471681F18DBD57436238"><enum>(G)</enum><text>any other factors
				at the discretion of the Inspector General.</text>
									</subparagraph></paragraph></subsection></section><section id="ID1777c88e155140fcbb5a6b412edcb19d"><enum>252.</enum><header>Sector-specific
				agencies</header>
							<subsection id="ID0c01e02d4cc7440ea64a607451e298e5"><enum>(a)</enum><header>In
				general</header><text>The head of each sector-specific agency and the head of
				any Federal agency that is not a sector-specific agency with responsibilities
				for regulating covered critical infrastructure shall coordinate with the
				Director on any activities of the sector-specific agency or Federal agency that
				relate to the efforts of the agency regarding security or resiliency of the
				national information infrastructure, including critical infrastructure and
				covered critical infrastructure, within or under the supervision of the
				agency.</text>
							</subsection><subsection id="IDbf47e88debf9426aa8083e0f5742deaa"><enum>(b)</enum><header>Duplicative
				reporting requirements</header><text>The head of each sector-specific agency
				and the head of any Federal agency that is not a sector-specific agency with
				responsibilities for regulating covered critical infrastructure shall
				coordinate with the Director to eliminate and avoid the creation of duplicate
				reporting or compliance requirements relating to the security or resiliency of
				the national information infrastructure, including critical infrastructure and
				covered critical infrastructure, within or under the supervision of the
				agency.</text>
							</subsection><subsection id="IDa17494fb75b7448a9fcc4ba78bdbcbc8"><enum>(c)</enum><header>Requirements</header>
								<paragraph id="ID273770326923490c97c4a9399a70805e"><enum>(1)</enum><header>In
				general</header><text>To the extent that the head of each sector-specific
				agency and the head of any Federal agency that is not a sector-specific agency
				with responsibilities for regulating covered critical infrastructure has the
				authority to establish regulations, rules, or requirements or other required
				actions that are applicable to the security of national information
				infrastructure, including critical infrastructure and covered critical
				infrastructure, the head of that agency shall—</text>
									<subparagraph id="ID7ca50e873445440db75f82173c049933"><enum>(A)</enum><text>notify the
				Director in a timely fashion of the intent to establish the regulations, rules,
				requirements, or other required actions;</text>
									</subparagraph><subparagraph id="id54785A12E4414C7BA0D8BA5925C7E955"><enum>(B)</enum><text>coordinate with
				the Director to ensure that the regulations, rules, requirements, or other
				required actions are consistent with, and do not conflict or impede, the
				activities of the Director under sections 247, 248, and 249; and</text>
									</subparagraph><subparagraph id="ID570b545c543842f08ce34ac6c00316db"><enum>(C)</enum><text>in coordination
				with the Director, ensure that the regulations, rules, requirements, or other
				required actions are implemented, as they relate to covered critical
				infrastructure, in accordance with subsection (a).</text>
									</subparagraph></paragraph><paragraph id="idC27F1831F68142B68C27E77F726C1D51"><enum>(2)</enum><header>Coordination</header><text>Coordination
				under paragraph (1)(B) shall include the active participation of the Director
				in the process for developing regulations, rules, requirements, or other
				required actions.</text>
								</paragraph><paragraph id="ID9b71f8de16d247578b40ae06fb208d52"><enum>(3)</enum><header>Rule of
				construction</header><text>Nothing in this section shall be construed to
				provide additional authority for any sector-specific agency or any Federal
				agency that is not a sector-specific agency with responsibilities for
				regulating national information infrastructure, including critical
				infrastructure or covered critical infrastructure, to establish standards or
				other measures that are applicable to the security of national information
				infrastructure not otherwise authorized by law.</text>
								</paragraph></subsection></section><section id="IDc6bcff949e2148f3aee117b1b733317f"><enum>253.</enum><header>Strategy for
				Federal cybersecurity supply chain management</header>
							<subsection id="IDa5300c8123fd4831abeb01814f3ba195"><enum>(a)</enum><header>In
				general</header><text>The Secretary, in consultation with the Director of
				Cyberspace Policy, the Director, the Secretary of Defense, the Secretary of
				Commerce, the Secretary of State, the Director of National Intelligence, the
				Administrator of General Services, the Administrator for Federal Procurement
				Policy, the other members of the Chief Information Officers Council established
				under section 3603 of title 44, United States Code, the Chief Acquisition
				Officers Council established under section 1311 of title 41, United States
				Code, the Chief Financial Officers Council established under section 302 of the
				Chief Financial Officers Act of 1990 (31 U.S.C. 901 note), and the private
				sector, shall develop, periodically update, and implement a supply chain risk
				management strategy designed to ensure, based on mission criticality and cost
				effectiveness, the security of the Federal information infrastructure,
				including protection against unauthorized access to, alteration of information
				in, disruption of operations of, interruption of communications or services of,
				and insertion of malicious software, engineering vulnerabilities, or otherwise
				corrupting software, hardware, services, or products intended for use in
				Federal information infrastructure.</text>
							</subsection><subsection id="IDafa916dd57104be088b8c32315a29993"><enum>(b)</enum><header>Contents</header><text>The
				supply chain risk management strategy developed under subsection (a)
				shall—</text>
								<paragraph id="ID8474c3fa8a324d4ea7b66c14757861ef"><enum>(1)</enum><text>address risks in
				the supply chain during the entire life cycle of any part of the Federal
				information infrastructure;</text>
								</paragraph><paragraph id="ID65aba395b65f46b798b3855243a3f6cf"><enum>(2)</enum><text>place particular
				emphasis on—</text>
									<subparagraph id="ID4018eb13265349de9546b4779420564c"><enum>(A)</enum><text>securing critical
				information systems and the Federal information infrastructure;</text>
									</subparagraph><subparagraph id="ID2edefc2d377340ea823c4cfe1d8cc8b4"><enum>(B)</enum><text>developing
				processes that—</text>
										<clause id="IDfb206f9d36cf4a3d8d62b5f7beeb4f46"><enum>(i)</enum><text>incorporate
				all-source intelligence analysis into assessments of the supply chain for the
				Federal information infrastructure;</text>
										</clause><clause id="IDd90a3261c67d464cbaa2dd380b162e7f"><enum>(ii)</enum><text>assess risks
				from potential suppliers providing critical components or services of the
				Federal information infrastructure;</text>
										</clause><clause id="idD8FFD49B815B4BC7B4FCB27AD75BD6D6"><enum>(iii)</enum><text>assess risks
				from individual components, including all subcomponents, or software used in or
				affecting the Federal information infrastructure;</text>
										</clause><clause id="ID83438540a7a1428fa4f8c9192bbea9f1"><enum>(iv)</enum><text>manage the
				quality, configuration, and security of software, hardware, and systems of the
				Federal information infrastructure throughout the life cycle of the software,
				hardware, or system, including components or subcomponents from secondary and
				tertiary sources;</text>
										</clause><clause id="IDd8ee2c35b50f41e7a5df89c58553d80e"><enum>(v)</enum><text>detect the
				occurrence, reduce the likelihood of occurrence, and mitigate or remediate the
				risks associated with products containing counterfeit components or malicious
				functions;</text>
										</clause><clause commented="no" id="ID3883ab3cdc984ba49a852758129cc961"><enum>(vi)</enum><text>enhance
				developmental and operational test and evaluation capabilities, including
				software vulnerability detection methods and automated methods and tools that
				shall be integrated into acquisition policy practices by Federal agencies and,
				where appropriate, make the capabilities available for use by the private
				sector; and</text>
										</clause><clause commented="no" id="id6A1B8B7DEF6949DDA3CBDFA2C2338FC5"><enum>(vii)</enum><text>protect the
				intellectual property and trade secrets of suppliers of information and
				communications technology products and services;</text>
										</clause></subparagraph><subparagraph id="IDb3ebfee8bc4f420697dba1bab28009cb"><enum>(C)</enum><text>the use of
				internationally recognized standards and standards developed by the private
				sector and developing a process, with the National Institute for Standards and
				Technology, to make recommendations for improvements of the standards;</text>
									</subparagraph><subparagraph id="IDac75d88f322e4294898b7521babcf022"><enum>(D)</enum><text>identifying
				acquisition practices of Federal agencies that increase risks in the supply
				chain and developing a process to provide recommendations for revisions to
				those processes; and</text>
									</subparagraph><subparagraph id="IDe50bee2d5597411f9748898651fdc493"><enum>(E)</enum><text>sharing with the
				private sector, to the fullest extent possible, the threats identified in the
				supply chain and working with the private sector to develop responses to those
				threats as identified; and</text>
									</subparagraph></paragraph><paragraph id="ID09ca0a936f514308950c0ec25e3fa225"><enum>(3)</enum><text>to the maximum
				extent practicable, promote the ability of Federal agencies to procure
				authentic commercial off the shelf information and communications technology
				products and services from a diverse pool of suppliers.</text>
								</paragraph></subsection><subsection id="IDd5e8e656b6ce41a19283ab244e7dbcfa"><enum>(c)</enum><header>Implementation</header><text>The
				Federal Acquisition Regulatory Council established under section 1302(a) of
				title 41, United States Code, shall—</text>
								<paragraph id="id4DEB21B8E1F34C83B766ED1715DECDBE"><enum>(1)</enum><text>amend the Federal
				Acquisition Regulation maintained under section 1303(a)(1) of title 41, United
				States Code, to—</text>
									<subparagraph id="idC3CB87739E2D437598924053ACB3E46F"><enum>(A)</enum><text>incorporate,
				where relevant, the supply chain risk management strategy developed under
				subsection (a) to improve security throughout the acquisition process;
				and</text>
									</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id34F2565B73084361A708196C1C7127B8"><enum>(B)</enum><text>direct that all
				software and hardware purchased by the Federal Government shall comply with
				standards developed or be interoperable with automated tools approved by the
				National Institute of Standards and Technology, to continually enhance
				security; and</text>
									</subparagraph></paragraph><paragraph id="ID194ca43d56104aeca955ef1978d58d6a"><enum>(2)</enum><text>develop a clause
				or set of clauses for inclusion in solicitations, contracts, and task and
				delivery orders that sets forth the responsibility of the contractor under the
				Federal Acquisition Regulation provisions implemented under this
				subsection.</text>
								</paragraph></subsection><subsection id="ID9cfbd283ceea4ac19e776619b8f000f4"><enum>(d)</enum><header>Preferences for
				acquisition of commercial items</header><text>The strategy developed under this
				section, and any actions taken under subsection (c), shall be consistent with
				the preferences for the acquisition of commercial items under section 2377 of
				title 10, United States Code, and section 3307 of title 41, United States
				Code.</text>
							</subsection></section></subtitle><after-quoted-block>.</after-quoted-block></quoted-block>
			</section></title><title id="id09378F28821A4536B8E6EBBF1EEFB294"><enum>III</enum><header>Federal
			 information security management</header>
			<section id="id3707C79386544858A9895DA9F4A555BE"><enum>301.</enum><header>Coordination
			 of Federal information policy</header>
				<subsection id="id6F64CFBDC2384F9FBF67FA3B7D1CEBC4"><enum>(a)</enum><header>Findings</header><text>Congress
			 finds that—</text>
					<paragraph commented="no" id="idACE52C41E86644F193FF11BBD8A2CB78"><enum>(1)</enum><text>since 2002 the
			 Federal Government has experienced multiple high-profile incidents that
			 resulted in the theft of sensitive information amounting to more than the
			 entire print collection contained in the Library of Congress, including
			 personally identifiable information, advanced scientific research, and
			 prenegotiated United States diplomatic positions; and</text>
					</paragraph><paragraph commented="no" id="idC80FB60913B74635A9239F6DDF771F0C"><enum>(2)</enum><text>chapter 35 of
			 title 44, United States Code, must be amended to increase the coordination of
			 Federal agency activities and to enhance situational awareness throughout the
			 Federal Government using more effective enterprise-wide automated monitoring,
			 detection, and response capabilities.</text>
					</paragraph></subsection><subsection id="ID57ebba2cbcd446478c984fb13554f8c8"><enum>(b)</enum><header>In
			 general</header><text>Chapter 35 of title 44, United States Code, is amended by
			 striking subchapters II and III and inserting the following:</text>
					<quoted-block display-inline="no-display-inline" id="idDF50DAFF25D448F493B4588D1CF32936" style="USC">
						<subchapter id="id4392C74EF2684F3F8E2DF631D6D38002"><enum>II</enum><header>Information
				security</header>
							<section commented="no" id="id86798A2E91F5435A98B0740945DDE0AE"><enum>3550.</enum><header>Purposes</header><text display-inline="no-display-inline">The purposes of this subchapter are
				to—</text>
								<paragraph commented="no" id="IDde4f8b3ef500401caeab08f770581d18"><enum>(1)</enum><text>provide a
				comprehensive framework for ensuring the effectiveness of information security
				controls over information resources that support the Federal information
				infrastructure and the operations and assets of agencies;</text>
								</paragraph><paragraph commented="no" id="ID62b0587fa3c64b609c7c8daddb10c636"><enum>(2)</enum><text>recognize the
				highly networked nature of the current Federal information infrastructure and
				provide effective Government-wide management and oversight of the related
				information security risks, including coordination of information security
				efforts throughout the civilian, national security, and law enforcement
				communities;</text>
								</paragraph><paragraph commented="no" id="IDaa28b2c39e1341209e4a5fa72a7a4fec"><enum>(3)</enum><text>provide for
				development and maintenance of prioritized and risk-based security controls
				required to protect Federal information infrastructure and information systems;
				and</text>
								</paragraph><paragraph commented="no" id="ID2b723a6176ba4ff09aa20905433f2421"><enum>(4)</enum><text>provide a
				mechanism for improved oversight of Federal agency information security
				programs.</text>
								</paragraph><paragraph id="IDb8d55664431b43608211f57bf2e256ba"><enum>(5)</enum><text>acknowledge that
				commercially developed information security products offer advanced, dynamic,
				robust, and effective information security solutions, reflecting market
				solutions for the protection of critical information infrastructures important
				to the national defense and economic security of the Nation that are designed,
				built, and operated by the private sector; and</text>
								</paragraph><paragraph id="IDdf5b81c7acfb47fd8637e93770e3df8f"><enum>(6)</enum><text>recognize that
				the selection of specific technical hardware and software information security
				solutions should be left to individual agencies from among commercially
				developed products.</text>
								</paragraph></section><section id="IDc8ba711271ae4f3798ebe02e833fbb53"><enum>3551.</enum><header>Definitions</header>
								<subsection id="ID1bd255d4f7be41148c67f071102f1efe"><enum>(a)</enum><header>In
				general</header><text>Except as provided under subsection (b), the definitions
				under section 3502 shall apply to this subchapter.</text>
								</subsection><subsection id="ID873cf2fe84bb4516b3135fd2db0a89ca"><enum>(b)</enum><header>Additional
				definitions</header><text>In this subchapter:</text>
									<paragraph commented="no" id="ID5bcd060c620d46438a496b04b58c52e9"><enum>(1)</enum><text>The term
				<term>agency information infrastructure</term>—</text>
										<subparagraph commented="no" id="id6D44F082481441BCB5648A7FF32AF37D"><enum>(A)</enum><text>means information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, an agency, including information systems used or operated by
				another entity on behalf of the agency; and</text>
										</subparagraph><subparagraph commented="no" id="id67215396996B4044A06AFFA4825C0E94"><enum>(B)</enum><text>does not include
				national security systems.</text>
										</subparagraph></paragraph><paragraph id="ID4312e04df8cc4080ad6737ec913c5701"><enum>(2)</enum><text>The term
				<term>automated and continuous monitoring</term> means monitoring at a
				frequency and sufficiency such that the data exchange requires little to no
				human involvement and is not interrupted.</text>
									</paragraph><paragraph id="ID923c8ec49eb14b4690bb4240ca89284e"><enum>(3)</enum><text>The term
				<term>incident</term> means an occurrence that—</text>
										<subparagraph id="ID2315d96e85d84b82a293c8fc1f1e0064"><enum>(A)</enum><text>actually or
				imminently jeopardizes—</text>
											<clause id="ID9b218ba5b7a54fdba4c771a78ccffeab"><enum>(i)</enum><text>the information
				security of information infrastructure; or</text>
											</clause><clause id="IDa6557342c09f4499874dfcc3a2f6a562"><enum>(ii)</enum><text>the information
				that information infrastructure processes, stores, receives, or transmits;
				or</text>
											</clause></subparagraph><subparagraph id="IDd5b9d51c52694427a59b6f8dd945919a"><enum>(B)</enum><text>constitutes a
				violation of security policies, security procedures, or acceptable use policies
				applicable to information infrastructure.</text>
										</subparagraph></paragraph><paragraph id="ID58579594c892445ab20b4a6a015c207a"><enum>(4)</enum><text>The term
				<term>information infrastructure</term> means the underlying framework that
				information systems and assets rely on to process, transmit, receive, or store
				information electronically, including programmable electronic devices and
				communications networks and any associated hardware, software, or data.</text>
									</paragraph><paragraph id="id9B1E0B02852B46BA9C31A2C782D88B81"><enum>(5)</enum><text>The term
				<term>information security</term> means protecting information and information
				systems from disruption or unauthorized access, use, disclosure, modification,
				or destruction in order to provide—</text>
										<subparagraph id="idFEAF96E0AEA742468EA368E370DD59DE"><enum>(A)</enum><text>integrity, by
				guarding against improper information modification or destruction, including by
				ensuring information nonrepudiation and authenticity;</text>
										</subparagraph><subparagraph id="id1B7D4EAB4AD049B78C466835794BDF71"><enum>(B)</enum><text>confidentiality,
				by preserving authorized restrictions on access and disclosure, including means
				for protecting personal privacy and proprietary information; and</text>
										</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id71C9F8DDF56847F9B01434BF9650B294"><enum>(C)</enum><text>availability, by
				ensuring timely and reliable access to and use of information.</text>
										</subparagraph></paragraph><paragraph id="ID2ff0f9306ede4abda84cda4b58a66133"><enum>(6)</enum><text>The term
				<term>information technology</term> has the meaning given that term in section
				11101 of title 40.</text>
									</paragraph><paragraph id="id179758DE608046CD855B41FA48D7A07A"><enum>(7)</enum><text>The term
				<term>management controls</term> means safeguards or countermeasures for an
				information system that focus on the management of risk and the management of
				information system security.</text>
									</paragraph><paragraph id="IDf38bafe9940e43ca8ecf0771a1ddfcf5"><enum>(8)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="id159D9F93E5B84908BD0982049214B9D1"><enum>(A)</enum><text>The term <term>national
				security system</term> means any information system (including any
				telecommunications system) used or operated by an agency or by a contractor of
				an agency, or other organization on behalf of an agency—</text>
											<clause id="id8B7853F055E349508D7D55104CC481C6" indent="up1"><enum>(i)</enum><text>the function, operation, or use of
				which—</text>
												<subclause id="idC24EC25569D94321898C49DBFFB54C84"><enum>(I)</enum><text>involves intelligence activities;</text>
												</subclause><subclause id="idF770277F263D42BF91EBCC8AE140CF8A"><enum>(II)</enum><text>involves cryptologic activities related
				to national security;</text>
												</subclause><subclause id="idD67F9A5C951F42AABBF484EED0606A69"><enum>(III)</enum><text>involves command and control of
				military forces;</text>
												</subclause><subclause id="id98550383FD204403AB59EF070A21F67E"><enum>(IV)</enum><text>involves equipment that is an integral
				part of a weapon or weapons system; or</text>
												</subclause><subclause id="idDCCB159893B4491487A144A55211CB0B"><enum>(V)</enum><text>subject to subparagraph (B), is critical
				to the direct fulfillment of military or intelligence missions; or</text>
												</subclause></clause><clause id="idFEF0A5865F1D41BD90B54CBE641F83C3" indent="up1"><enum>(ii)</enum><text>that is protected at all times by
				procedures established for information that have been specifically authorized
				under criteria established by an Executive order or an Act of Congress to be
				kept classified in the interest of national defense or foreign policy.</text>
											</clause></subparagraph><subparagraph id="idD19360504BD5454F95044A6DEC3E3F13" indent="up1"><enum>(B)</enum><text>Subparagraph (A)(i)(V) does not
				include a system that is to be used for routine administrative and business
				applications (including payroll, finance, logistics, and personnel management
				applications).</text>
										</subparagraph></paragraph><paragraph id="id30A074443D23410ABD9543DE6BAE2CAE"><enum>(9)</enum><text>The term
				<term>operational controls</term> means the safeguards and countermeasures for
				an information system that are primarily implemented and executed by
				individuals, not systems.</text>
									</paragraph><paragraph id="ID0ac352e974134af0b7bb828df24d509c"><enum>(10)</enum><text>The term
				<term>risk</term> means the potential for an unwanted outcome resulting from an
				incident, as determined by the likelihood of the occurrence of the incident and
				the associated consequences, including potential for an adverse outcome
				assessed as a function of threats, vulnerabilities, and consequences associated
				with an incident.</text>
									</paragraph><paragraph id="ID4231683fc3eb4884ade65af9cb4513b5"><enum>(11)</enum><text>The term
				<term>risk-based security</term> means security commensurate with the risk and
				magnitude of harm resulting from the loss, misuse, or unauthorized access to,
				or modification, of information, including assuring that systems and
				applications used by the agency operate effectively and provide appropriate
				confidentiality, integrity, and availability.</text>
									</paragraph><paragraph id="ID8c4760145e884140bc39ee5c53c7a540"><enum>(12)</enum><text>The term
				<term>security controls</term> means the management, operational, and technical
				controls prescribed for an information system to protect the information
				security of the system.</text>
									</paragraph><paragraph id="ID544da3a5fc8844c382b0783801a3d669"><enum>(13)</enum><text>The term
				<term>technical controls</term> means the safeguards or countermeasures for an
				information system that are primarily implemented and executed by the
				information system through mechanism contained in the hardware, software, or
				firmware components of the system.</text>
									</paragraph></subsection></section><section id="idD1178BA90EFF4C839175401A3996F679"><enum>3552.</enum><header>Authority and
				functions of the National Center for Cybersecurity and Communications</header>
								<subsection id="ID4c94f957973a4d41a15e05c297e58581"><enum>(a)</enum><header>In
				general</header><text>The Director of the National Center for Cybersecurity and
				Communications shall—</text>
									<paragraph id="ID3628b85b3cae47bfad829bf6426fcaa6"><enum>(1)</enum><text>develop, oversee
				the implementation of, and enforce policies, principles, and guidelines on
				information security, including through ensuring timely agency adoption of and
				compliance with standards developed under section 20 of the National Institute
				of Standards and Technology Act (15 U.S.C. 278g–3) and subtitle E of title II
				of the Homeland Security Act of 2002;</text>
									</paragraph><paragraph id="IDe0e9b6e3629a44d583ca066a847b89b8"><enum>(2)</enum><text>provide to
				agencies security controls that agencies shall be required to be implemented to
				mitigate and remediate vulnerabilities, attacks, and exploitations discovered
				as a result of activities required under this subchapter or subtitle E of title
				II of the Homeland Security Act of 2002;</text>
									</paragraph><paragraph id="IDe3fd80bffbf1460ebb5ea79bc5a8889a"><enum>(3)</enum><text>to the extent
				practicable—</text>
										<subparagraph id="ID3ab9a4d4d70748a1a13ee8bc50a453a7"><enum>(A)</enum><text>prioritize the
				policies, principles, standards, and guidelines promulgated under section 20 of
				the National Institute of Standards and Technology Act (15 U.S.C. 278g–3),
				paragraph (1), and subtitle E of title II of the Homeland Security Act of 2002,
				based upon the risk of an incident; and</text>
										</subparagraph><subparagraph id="ID4a18c3a9d186462bba1fb87a3d7eec0a"><enum>(B)</enum><text>develop guidance
				that requires agencies to monitor, including automated and continuous
				monitoring of, the effective implementation of policies, principles, standards,
				and guidelines developed under section 20 of the National Institute of
				Standards and Technology Act (15 U.S.C. 278g–3), paragraph (1), and subtitle E
				of title II of the Homeland Security Act of 2002;</text>
										</subparagraph><subparagraph id="ID7bd3e863c6a14fa5973f86c84e0f3e6b"><enum>(C)</enum><text>ensure the
				effective operation of technical capabilities within the National Center for
				Cybersecurity and Communications to enable automated and continuous monitoring
				of any information collected as a result of the guidance developed under
				subparagraph (B) and use the information to enhance the risk-based security of
				the Federal information infrastructure; and</text>
										</subparagraph><subparagraph id="IDfa5cc2d0fb1047d2b6de9e2f0845637e"><enum>(D)</enum><text>ensure the
				effective operation of a secure system that satisfies information reporting
				requirements under sections 3553(c) and 3556(c);</text>
										</subparagraph></paragraph><paragraph id="IDf15b6719e07549768a642e888eef66ea"><enum>(4)</enum><text>require agencies,
				consistent with the standards developed under section 20 of the National
				Institute of Standards and Technology Act (15 U.S.C. 278g–3) or paragraph (1)
				and the requirements of this subchapter, to identify and provide information
				security protections commensurate with the risk resulting from the disruption
				or unauthorized access, use, disclosure, modification, or destruction
				of—</text>
										<subparagraph id="ID9406eed1046d4ca3be2e1b2d5dc4b23f"><enum>(A)</enum><text>information
				collected or maintained by or on behalf of an agency; or</text>
										</subparagraph><subparagraph id="ID387f1e4d8666490d80556487fe112308"><enum>(B)</enum><text>information
				systems used or operated by an agency or by a contractor of an agency or other
				organization on behalf of an agency;</text>
										</subparagraph></paragraph><paragraph id="ID9d47c68b43db469e80902f9288e43f2b"><enum>(5)</enum><text>oversee agency
				compliance with the requirements of this subchapter, including coordinating
				with the Office of Management and Budget to use any authorized action under
				section 11303 of title 40 to enforce accountability for compliance with such
				requirements;</text>
									</paragraph><paragraph id="ID41f5e5ae9e084301862f39e1224395c9"><enum>(6)</enum><text>review, at least
				annually, and approve or disapprove, agency information security programs
				required under section 3553(b); and</text>
									</paragraph><paragraph id="IDec3feb3f86ba42c6a0b7f1246ad60e83"><enum>(7)</enum><text>coordinate
				information security policies and procedures with the Administrator for
				Electronic Government and the Administrator for the Office of Information and
				Regulatory Affairs with related information resources management policies and
				procedures.</text>
									</paragraph></subsection><subsection id="ID292b9b73932a4f80824c5ac1e1c4bf78"><enum>(b)</enum><header>National
				security systems</header><text>The authorities of the Director of the National
				Center for Cybersecurity and Communications under this section shall not apply
				to national security systems.</text>
								</subsection></section><section id="ID5447676884944c8f8dad2030f2c72383"><enum>3553.</enum><header>Agency
				responsibilities</header>
								<subsection id="IDacdf9d613f814b399f31c8741153503b"><enum>(a)</enum><header>In
				general</header><text>The head of each agency shall—</text>
									<paragraph id="IDa3319f9d2fcf42218ec4350f9703cf55"><enum>(1)</enum><text>be responsible
				for—</text>
										<subparagraph id="ID17e824fe43544b01afcc3355115f3f7d"><enum>(A)</enum><text>providing
				information security protections commensurate with the risk and magnitude of
				the harm resulting from unauthorized access, use, disclosure, disruption,
				modification, or destruction of—</text>
											<clause id="IDb1c319e82ea84a4fa75f6c6bf0cd32c6"><enum>(i)</enum><text>information
				collected or maintained by or on behalf of the agency; and</text>
											</clause><clause id="IDf0fc8edc96054cd39ece7bbd5f5a7a81"><enum>(ii)</enum><text>agency
				information infrastructure;</text>
											</clause></subparagraph><subparagraph id="ID14251fb704c146d883e7493c94766a75"><enum>(B)</enum><text>complying with
				the requirements of this subchapter and related policies, procedures,
				standards, and guidelines, including—</text>
											<clause id="ID370e553777b7418eb57a3a08dcbc0375"><enum>(i)</enum><text>information
				security requirements, including security controls, developed by the Director
				of the National Center for Cybersecurity and Communications under section 3552,
				subtitle E of title II of the Homeland Security Act of 2002, or any other
				provision of law;</text>
											</clause><clause id="ID13d10134b4b24335a277cd1ede03fb17"><enum>(ii)</enum><text>information
				security policies, principles, standards, and guidelines promulgated under
				section 20 of the National Institute of Standards and Technology Act (15 U.S.C.
				278g–3) and section 3552(a)(1);</text>
											</clause><clause id="ID85a110c064114ecb893c9245ae0fa010"><enum>(iii)</enum><text>information
				security standards and guidelines for national security systems issued in
				accordance with law and as directed by the President; and</text>
											</clause><clause id="ID210c736c939e4e6a8513b03a13dd481f"><enum>(iv)</enum><text>ensuring the
				standards implemented for information systems and national security systems of
				the agency are complementary and uniform, to the extent practicable;</text>
											</clause></subparagraph><subparagraph id="ID15ddaf451c8a4f82a3bf8ea1cffb35e8"><enum>(C)</enum><text>ensuring that
				information security management processes are integrated with agency strategic
				and operational planning and budget processes, including policies, procedures,
				and practices described in subsection (c)(1)(C);</text>
										</subparagraph><subparagraph id="id2AC959378B2B431691E031227CE99A63"><enum>(D)</enum><text>as appropriate,
				maintaining secure facilities that have the capability of accessing, sending,
				receiving, and storing classified information;</text>
										</subparagraph><subparagraph id="id8444D6A9F2BE4116B127E7B4B27D9646"><enum>(E)</enum><text>maintaining a
				sufficient number of personnel with security clearances, at the appropriate
				levels, to access, send, receive and analyze classified information to carry
				out the responsibilities of this subchapter; and</text>
										</subparagraph><subparagraph id="id9127544BEA36466BA4AEBF60D1C0D977"><enum>(F)</enum><text>ensuring that
				information security performance indicators and measures are included in the
				annual performance evaluations of all managers, senior managers, senior
				executive service personnel, and political appointees;</text>
										</subparagraph></paragraph><paragraph id="ID8d4072efcdd34dcc8e9efc99dde74788"><enum>(2)</enum><text>ensure that
				senior agency officials provide information security for the information and
				information systems that support the operations and assets under the control of
				those officials, including through—</text>
										<subparagraph id="IDd2e8c399d4e742d0a262df36986aa611"><enum>(A)</enum><text>assessing the
				risk and magnitude of the harm that could result from the disruption or
				unauthorized access, use, disclosure, modification, or destruction of such
				information or information systems;</text>
										</subparagraph><subparagraph id="IDf87a19a6533d4e24829790a2963af273"><enum>(B)</enum><text>determining the
				levels of information security appropriate to protect such information and
				information systems in accordance with policies, principles, standards, and
				guidelines promulgated under section 20 of the National Institute of Standards
				and Technology Act (15 U.S.C. 278g–3), section 3552(a)(1), and subtitle E of
				title II of the Homeland Security Act of 2002, for information security
				categorizations and related requirements;</text>
										</subparagraph><subparagraph id="IDb95cc9db453848e1a4f246c4ec137402"><enum>(C)</enum><text>implementing
				policies and procedures to cost effectively reduce risks to an acceptable
				level;</text>
										</subparagraph><subparagraph id="ID2d628fa78ccc426abb0a898a4cbd1f65"><enum>(D)</enum><text>periodically
				testing and evaluating information security controls and techniques to ensure
				that such controls and techniques are operating effectively; and</text>
										</subparagraph><subparagraph id="IDa36719afdae340c882dae6ec43dd6598"><enum>(E)</enum><text>withholding all
				bonus and cash awards to senior agency officials accountable for the operation
				of such agency information infrastructure that are recognized by the Chief
				Information Security Officer as impairing the risk-based security information,
				information system, or agency information infrastructure;</text>
										</subparagraph></paragraph><paragraph id="IDf2ca0c3b96e0433087d4e29c6db276a6"><enum>(3)</enum><text>delegate to a
				senior agency officer designated as the Chief Information Security Officer the
				authority and budget necessary to ensure and enforce compliance with the
				requirements imposed on the agency under this subchapter, subtitle E of title
				II of the Homeland Security Act of 2002, or any other provision of law,
				including—</text>
										<subparagraph id="IDae27c4bfb1fe4fff97b4c5e1cd2830d1"><enum>(A)</enum><text>overseeing the
				establishment, maintenance, and management of a security operations center that
				has technical capabilities that can, through automated and continuous
				monitoring—</text>
											<clause id="ID802107aef3894ed29683969d3c2f313b"><enum>(i)</enum><text>detect, report,
				respond to, contain, remediate, and mitigate incidents that impair risk-based
				security of the information, information systems, and agency information
				infrastructure, in accordance with policy provided by the Director of the
				National Center for Cybersecurity and Communications;</text>
											</clause><clause id="ID216615e552324f84829bc3872790675b"><enum>(ii)</enum><text>monitor and, on
				a risk-based basis, mitigate and remediate the vulnerabilities of every
				information system within the agency information infrastructure;</text>
											</clause><clause id="ID6d7412f0af1a4acca638119293be2f48"><enum>(iii)</enum><text>continually
				evaluate risks posed to information collected or maintained by or on behalf of
				the agency and information systems and hold senior agency officials accountable
				for ensuring the risk-based security of such information and information
				systems;</text>
											</clause><clause id="ID605d2640ba3f46b286e7443499183f3e"><enum>(iv)</enum><text>collaborate with
				the Director of the National Center for Cybersecurity and Communications and
				appropriate public and private sector security operations centers to address
				incidents that impact the security of information and information systems that
				extend beyond the control of the agency; and</text>
											</clause><clause id="IDa17f9605efe2485b8b5dd384419f0dcd"><enum>(v)</enum><text>report any
				incident described under clauses (i) and (ii), as directed by the policy of the
				Director of the National Center for Cybersecurity and Communications and the
				Inspector General of the agency;</text>
											</clause></subparagraph><subparagraph id="ID1a78f18e0c6b4f5eb427afd54e09fa90"><enum>(B)</enum><text>collaborating
				with the Administrator for E–Government and the Chief Information Officer to
				establish, maintain, and update an enterprise network, system, storage, and
				security architecture, that can be accessed by the National Cybersecurity
				Communications Center and includes—</text>
											<clause id="ID74626bc3e452441ca8fbbbba429f0aa9"><enum>(i)</enum><text>information on
				how security controls are implemented throughout the agency information
				infrastructure; and</text>
											</clause><clause id="ID2d969bf15d6c423b82287092fd574895"><enum>(ii)</enum><text>information on
				how the controls described under subparagraph (A) maintain the appropriate
				level of confidentiality, integrity, and availability of information and
				information systems based on—</text>
												<subclause id="IDdb28f1c4d4e446c09a5438ef1c0cbd23"><enum>(I)</enum><text>the policy of the
				Director of the National Center for Cybersecurity and Communications;
				and</text>
												</subclause><subclause id="ID560c3e131e1441ae8eb85572f1f3809d"><enum>(II)</enum><text>the standards or
				guidance developed by the National Institute of Standards and
				Technology;</text>
												</subclause></clause></subparagraph><subparagraph id="IDca5ccd78bf2e4f3caee8594f7a711ff8"><enum>(C)</enum><text>developing,
				maintaining, and overseeing an agency-wide information security program as
				required by subsection (b);</text>
										</subparagraph><subparagraph id="IDe96622e45a2e4f6788a42d3d4bac58b5"><enum>(D)</enum><text>developing,
				maintaining, and overseeing information security policies, procedures, and
				control techniques to address all applicable requirements, including those
				issued under section 3552;</text>
										</subparagraph><subparagraph id="IDe1fdc9e41ccd493585538407fd94e50a"><enum>(E)</enum><text>training,
				consistent with the requirements of section 406 of the
				<short-title>Cybersecurity and Internet Freedom Act of
				2011</short-title>, and overseeing personnel with significant responsibilities
				for information security with respect to such responsibilities; and</text>
										</subparagraph><subparagraph id="ID1d4ab761881e407791632fef41ec51d7"><enum>(F)</enum><text>assisting senior
				agency officers concerning their responsibilities under paragraph (2);</text>
										</subparagraph></paragraph><paragraph id="ID6fa60a3c21fc49d681d96f8db82a114f"><enum>(4)</enum><text>ensure that the
				Chief Information Security Officer has a sufficient number of cleared and
				trained personnel with technical skills identified by the Director of the
				National Center for Cybersecurity and Communications as critical to maintaining
				the risk-based security of agency information infrastructure as required by the
				subchapter and other applicable laws;</text>
									</paragraph><paragraph id="ID83aba2141d7447989becaaaee843e712"><enum>(5)</enum><text>ensure that the
				agency Chief Information Security Officer, in coordination with appropriate
				senior agency officials, reports not less than annually to the head of the
				agency on the effectiveness of the agency information security program,
				including progress of remedial actions;</text>
									</paragraph><paragraph id="IDfe11108929f0464b835e0fae7ae23bd1"><enum>(6)</enum><text>ensure that the
				Chief Information Security Officer—</text>
										<subparagraph id="id79F7AA3B3E6541FA834F19339C717B4D"><enum>(A)</enum><text>possesses
				necessary qualifications, including education, professional certifications,
				training, experience, and the security clearance required to administer the
				functions described under this subchapter; and</text>
										</subparagraph><subparagraph id="id150343E6B5F04325AAFE2B6063EA03A1"><enum>(B)</enum><text>has information
				security duties as the primary duty of that officer; and</text>
										</subparagraph></paragraph><paragraph id="ID10c6c734d4494a4fb22e59c74b36196d"><enum>(7)</enum><text>ensure that
				components of that agency establish and maintain an automated reporting
				mechanism that allows the Chief Information Security Officer with
				responsibility for the entire agency, and all components thereof, to implement,
				monitor, and hold senior agency officers accountable for the implementation of
				appropriate security policies, procedures, and controls of agency
				components.</text>
									</paragraph></subsection><subsection id="ID6e88cf21e2e74608aac5e6ff952c16b4"><enum>(b)</enum><header>Agency-Wide
				information security program</header><text>Each agency shall develop, document,
				and implement an agency-wide information security program, approved by the
				Director of the National Center for Cybersecurity and Communications under
				section 3552(a)(6) and consistent with components across and within agencies,
				to provide information security for the information and information systems
				that support the operations and assets of the agency, including those provided
				or managed by another agency, contractor, or other source, that
				includes—</text>
									<paragraph id="ID9b53e9933d7248c5b6caa7b9448b085c"><enum>(1)</enum><text>frequent
				assessments, at least twice each month—</text>
										<subparagraph id="ID41e73dc773164aefa8097caf3f93ec61"><enum>(A)</enum><text>of the risk and
				magnitude of the harm that could result from the disruption or unauthorized
				access, use, disclosure, modification, or destruction of information and
				information systems that support the operations and assets of the agency;
				and</text>
										</subparagraph><subparagraph id="ID317572030d494b8790a110578cf6f71f"><enum>(B)</enum><text>that assess
				whether information or information systems should be removed or migrated to
				more secure networks or standards and make recommendations to the head of the
				agency and the Director of the National Center for Cybersecurity and
				Communications based on that assessment;</text>
										</subparagraph></paragraph><paragraph id="ID47eb8e7ba7d443cbbfd3083b82e7dc2e"><enum>(2)</enum><text>consistent with
				guidance developed under section 3554, vulnerability assessments and
				penetration tests commensurate with the risk posed to an agency information
				infrastructure;</text>
									</paragraph><paragraph id="IDb7502e2025764c04b23bf81cd43146e0"><enum>(3)</enum><text>ensure that
				information security vulnerabilities are remediated or mitigated based on the
				risk posed to the agency;</text>
									</paragraph><paragraph id="ID31d8cf08e7d145d8a3ce69c629ff4ef2"><enum>(4)</enum><text>policies and
				procedures that—</text>
										<subparagraph id="ID9fde2dfa4de742b7b109372880b1dff8"><enum>(A)</enum><text>are informed and
				revised by the assessments required under paragraphs (1) and (2);</text>
										</subparagraph><subparagraph id="ID6d18d92c08d84369a545b75011df6a3a"><enum>(B)</enum><text>cost effectively
				reduce information security risks to an acceptable level;</text>
										</subparagraph><subparagraph id="IDb98a0a4f0ea648e39789f43e24c370df"><enum>(C)</enum><text>ensure that
				information security is addressed throughout the life cycle of each agency
				information system; and</text>
										</subparagraph><subparagraph id="ID81950f26f90444f18cc4c26234fde5da"><enum>(D)</enum><text>ensure compliance
				with—</text>
											<clause id="ID4a6d48517b694246a5416789748acd06"><enum>(i)</enum><text>the requirements
				of this subchapter;</text>
											</clause><clause id="ID6e57eee1eb5c464fb2648ee1c1a4e943"><enum>(ii)</enum><text>policies and
				procedures prescribed by the Director of the National Center for Cybersecurity
				and Communications;</text>
											</clause><clause id="ID51bbfea992784f86a1eeebfc71e94591"><enum>(iii)</enum><text>minimally
				acceptable system configuration requirements, as determined by the Director of
				the National Center for Cybersecurity and Communications; and</text>
											</clause><clause id="ID1481a8f8005a44dfb0a5da52a4dbc50a"><enum>(iv)</enum><text>any other
				applicable requirements, including standards and guidelines for national
				security systems issued in accordance with law and as directed by the
				President;</text>
											</clause></subparagraph></paragraph><paragraph id="IDbab3c2de0e7c4ed683b490613abf99d1"><enum>(5)</enum><text>subordinate plans
				for providing risk-based information security for networks, facilities, and
				systems or groups of information systems, as appropriate;</text>
									</paragraph><paragraph id="IDc459e9053c7f43f6ac7ac439c98453fc"><enum>(6)</enum><text>role-based
				security awareness training, consistent with the requirements of section 406 of
				the <short-title>Cybersecurity and Internet Freedom Act of
				2011</short-title>, to inform personnel with access to the agency network,
				including contractors and other users of information systems that support the
				operations and assets of the agency, of—</text>
										<subparagraph id="IDf584a8761de84ccda16e139db06a594c"><enum>(A)</enum><text>information
				security risks associated with agency activities; and</text>
										</subparagraph><subparagraph id="ID077b26e3765545e5afcc195e04ad59f5"><enum>(B)</enum><text>agency
				responsibilities in complying with agency policies and procedures designed to
				reduce those risks;</text>
										</subparagraph></paragraph><paragraph id="IDbb34dcd7cc7b44cd8d9c3c64e72d14f3"><enum>(7)</enum><text>periodic testing
				and evaluation of the effectiveness of information security policies,
				procedures, and practices, to be performed with a rigor and frequency depending
				on risk, which shall include—</text>
										<subparagraph id="IDbd416e16f8f4465cb458df069b8ed752"><enum>(A)</enum><text>testing and
				evaluation not less than twice each year of security controls of information
				collected or maintained by or on behalf of the agency and every information
				system identified in the inventory required under section 3505(c);</text>
										</subparagraph><subparagraph id="ID688f78a5d97246fdb547e6c62956391c"><enum>(B)</enum><text>the effectiveness
				of ongoing monitoring, including automated and continuous monitoring,
				vulnerability scanning, and intrusion detection and prevention of incidents
				posed to the risk-based security of information and information systems as
				required under subsection (a)(3); and</text>
										</subparagraph><subparagraph id="ID72f11224f0f34f72b65d90f8a34ce560"><enum>(C)</enum><text>testing relied on
				in—</text>
											<clause id="IDc934375f059240db97b2d37fc7591a51"><enum>(i)</enum><text>an operational
				evaluation under section 3554;</text>
											</clause><clause id="id191F117757A04C2588B0DBC6F9DBF0F2"><enum>(ii)</enum><text>an independent
				assessment under section 3556; or</text>
											</clause><clause id="ID908e2cf199144c3bac6e8644165a6f05"><enum>(iii)</enum><text>another
				evaluation, to the extent specified by the Director of the National Center for
				Cybersecurity and Communications;</text>
											</clause></subparagraph></paragraph><paragraph id="IDfa01eb6a107349118346050a6f5426d5"><enum>(8)</enum><text>a process for
				planning, implementing, evaluating, and documenting remedial action to address
				any deficiencies in the information security policies, procedures, and
				practices of the agency;</text>
									</paragraph><paragraph id="ID42eafe2b3e9a4c06aba4192f5298bc1a"><enum>(9)</enum><text>procedures for
				detecting, reporting, and responding to incidents, consistent with requirements
				issued under section 3552, that include—</text>
										<subparagraph id="ID1b512de589184029ac86a7c4c7455938"><enum>(A)</enum><text>to the extent
				practicable, automated and continuous monitoring of the use of information and
				information systems;</text>
										</subparagraph><subparagraph id="ID812075cd3718480f909ba07147df0d2a"><enum>(B)</enum><text>requirements for
				mitigating risks and remediating vulnerabilities associated with such incidents
				systemically within the agency information infrastructure before substantial
				damage is done; and</text>
										</subparagraph><subparagraph id="IDb66bcd25f36543709f1994312f073c22"><enum>(C)</enum><text>notifying and
				coordinating with the Director of the National Center for Cybersecurity and
				Communications, as required by this subchapter, subtitle E of title II of the
				Homeland Security Act of 2002, and any other provision of law; and</text>
										</subparagraph></paragraph><paragraph id="IDe4962f0bc29b43ea9cf630a3936c6107"><enum>(10)</enum><text>plans and
				procedures to ensure continuity of operations for information systems that
				support the operations and assets of the agency.</text>
									</paragraph></subsection><subsection id="ID56ca4e52b5804efca772795e76983beb"><enum>(c)</enum><header>Agency
				reporting</header>
									<paragraph id="idEF42038200FC4DC3897D47C6738E2ACD"><enum>(1)</enum><header>In
				general</header><text>Each agency shall—</text>
										<subparagraph id="ID2882baa7545e49ae89e69874d3688aa1"><enum>(A)</enum><text>ensure that
				information relating to the adequacy and effectiveness of information security
				policies, procedures, and practices, is available to the entities identified
				under paragraph (2) through the system developed under section 3552(a)(3),
				including information relating to—</text>
											<clause id="ID7037479704b44a20a03f6bd8b6772112"><enum>(i)</enum><text>compliance with
				the requirements of this subchapter;</text>
											</clause><clause id="ID4be8449098d248258d3b33bf54b7d4a0"><enum>(ii)</enum><text>the
				effectiveness of the information security policies, procedures, and practices
				of the agency based on a determination of the aggregate effect of identified
				deficiencies and vulnerabilities;</text>
											</clause><clause id="ID26de764eb31e479887a4054742798d91"><enum>(iii)</enum><text>an
				identification and analysis of any significant deficiencies identified in such
				policies, procedures, and practices;</text>
											</clause><clause id="ID8aea152b4d694c8196ccbea9277c72c1"><enum>(iv)</enum><text>an
				identification of any vulnerability that could impair the risk-based security
				of the agency information infrastructure; and</text>
											</clause><clause id="IDb00d686197904c7d966ed7125654bfeb"><enum>(v)</enum><text>results of any
				operational evaluation conducted under section 3554 and plans of action to
				address the deficiencies and vulnerabilities identified as a result of such
				operational evaluation;</text>
											</clause></subparagraph><subparagraph id="IDe52cd6a715474e8ab5ed0b777ef62ebc"><enum>(B)</enum><text>follow the
				policy, guidance, and standards of the Director of the National Center for
				Cybersecurity and Communications, in consultation with the Federal Information
				Security Taskforce, to continually update, and ensure the electronic
				availability of both a classified and unclassified version of the information
				required under subparagraph (A);</text>
										</subparagraph><subparagraph id="IDa97b1f9083cc42ce97923d9aaf73a4b9"><enum>(C)</enum><text>ensure the
				information under subparagraph (A) addresses the adequacy and effectiveness of
				information security policies, procedures, and practices in plans and reports
				relating to—</text>
											<clause id="IDe46bdad837204e31b499c8cdd139c2c8"><enum>(i)</enum><text>annual agency
				budgets;</text>
											</clause><clause id="ID3763b00e26a642778094047ecb354626"><enum>(ii)</enum><text>information
				resources management of this subchapter;</text>
											</clause><clause id="IDeaab4c0b54ad40788914e4cb63987b57"><enum>(iii)</enum><text>information
				technology management and procurement under this chapter or any other
				applicable provision of law;</text>
											</clause><clause id="id0314F91655C443B081F52F778E194A05"><enum>(iv)</enum><text>subtitle E of
				title II of the Homeland Security Act of 2002;</text>
											</clause><clause id="ID4997179614d4466fa4ce42c1757fd388"><enum>(v)</enum><text>program
				performance under sections 1105 and 1115 through 1119 of title 31, and sections
				2801 and 2805 of title 39;</text>
											</clause><clause id="IDc25f147b9d834b1897beeae635210125"><enum>(vi)</enum><text>financial
				management under chapter 9 of title 31, and the Chief Financial Officers Act of
				1990 (31 U.S.C. 501 note; Public Law 101–576) (and the amendments made by that
				Act);</text>
											</clause><clause id="IDb7bfb042fbbb41589164c19502a7be2f"><enum>(vii)</enum><text>financial
				management systems under the Federal Financial Management Improvement Act (31
				U.S.C. 3512 note);</text>
											</clause><clause id="ID10e876c1663a455dbdb289584381fc66"><enum>(viii)</enum><text>internal
				accounting and administrative controls under section 3512 of title 31;
				and</text>
											</clause><clause id="IDf77697176f5247b0998ab290bb86caa4"><enum>(ix)</enum><text>performance
				ratings, salaries, and bonuses provided to the senior managers and supporting
				personnel taking into account program performance as it relates to complying
				with this subchapter; and</text>
											</clause></subparagraph><subparagraph id="ID32c8dda4754944c094f1aecca11ff6d0"><enum>(D)</enum><text>report any
				significant deficiency in a policy, procedure, or practice identified under
				subparagraph (A) or (B)—</text>
											<clause id="ID4e152de6e2d645e288976dd988e7bbd7"><enum>(i)</enum><text>as a material
				weakness in reporting under section 3512 of title 31; and</text>
											</clause><clause id="IDd912b8c4dc724a649e93cdbde83c469b"><enum>(ii)</enum><text>if relating to
				financial management systems, as an instance of a lack of substantial
				compliance under the Federal Financial Management Improvement Act (31 U.S.C.
				3512 note).</text>
											</clause></subparagraph></paragraph><paragraph id="ID0c8c5421d2924d77af3e3d42d1bf18c1"><enum>(2)</enum><header>Adequacy and
				effectiveness information</header><text>Information required under paragraph
				(1)(A) shall, to the extent possible and in accordance with applicable law,
				policy, guidance, and standards, be available on an automated and continuous
				basis to—</text>
										<subparagraph id="ID63b4a8ca8788416ca46ccf543a7f7f7a"><enum>(A)</enum><text>the Director of
				the National Center for Cybersecurity and Communications;</text>
										</subparagraph><subparagraph id="id31B9AD7E0A1E479E9E7BDCE34EECEE85"><enum>(B)</enum><text>the Office of
				Management and Budget;</text>
										</subparagraph><subparagraph id="ID0503de084f784dcd8bcc3d15b8791d7b"><enum>(C)</enum><text>the Committee on
				Homeland Security and Governmental Affairs of the Senate;</text>
										</subparagraph><subparagraph id="ID1192ff097eab4b938ceec1df335df8e9"><enum>(D)</enum><text>the Committee on
				Government Oversight and Reform of the House of Representatives;</text>
										</subparagraph><subparagraph id="IDfcde616d29f84dcf80acff3feb3830ea"><enum>(E)</enum><text>the Committee on
				Homeland Security of the House of Representatives;</text>
										</subparagraph><subparagraph id="ID12b48808e8694bbf98f89e49908bdfc2"><enum>(F)</enum><text>other appropriate
				authorization and appropriations committees of Congress;</text>
										</subparagraph><subparagraph id="IDe7a17390f6a246f9bc228d3a7461020d"><enum>(G)</enum><text>the Inspector
				General of the Federal agency; and</text>
										</subparagraph><subparagraph id="ID8997a42123d5452894292a54977b07e5"><enum>(H)</enum><text>the Comptroller
				General.</text>
										</subparagraph></paragraph></subsection><subsection id="id34D91660A21C44C9991459232146A9C3"><enum>(d)</enum><header>Inclusions in
				performance plans</header>
									<paragraph id="idE29999026CD34AF28BEE3CF58A09D144"><enum>(1)</enum><header>In
				General</header><text>In addition to the requirements of subsection (c), each
				agency, in consultation with the Director of the National Center for
				Cybersecurity and Communications, shall include as part of the performance plan
				required under section 1115 of title 31 a description of the time periods the
				resources, including budget, staffing, and training, that are necessary to
				implement the program required under subsection (b).</text>
									</paragraph><paragraph id="id2881F42A96ED4AD6AD9E1AF4D5FE45D9"><enum>(2)</enum><header>Risk
				assessments</header><text>The description under paragraph (1) shall be based on
				the risk and vulnerability assessments required under subsection (b) and
				evaluations required under section 3554.</text>
									</paragraph></subsection><subsection id="IDdeb16e01ca7640798c1cd8ba6b71361c"><enum>(e)</enum><header>Notice and
				comment</header><text>Each agency shall provide the public with timely notice
				and opportunities for comment on proposed information security policies and
				procedures to the extent that such policies and procedures affect communication
				with the public.</text>
								</subsection><subsection id="IDbaf4770c7159424ab7d3cde23b882a4f"><enum>(f)</enum><header>More stringent
				standards</header><text>The head of an agency may employ standards for the cost
				effective information security for information systems within or under the
				supervision of that agency that are more stringent than the standards the
				Director of the National Center for Cybersecurity and Communications prescribes
				under this subchapter, subtitle E of title II of the Homeland Security Act of
				2002, or any other provision of law, if the more stringent standards—</text>
									<paragraph id="ID2945ca37b46c4712b06e995457467e4c"><enum>(1)</enum><text>contain at least
				the applicable standards made compulsory and binding by the Director of the
				National Center for Cybersecurity and Communications; and</text>
									</paragraph><paragraph id="IDd5ae3e7956324bca8c12e7e2ecc0159d"><enum>(2)</enum><text>are otherwise
				consistent with policies and guidelines issued under section 3552.</text>
									</paragraph></subsection></section><section commented="no" id="IDc87ce2a4409c497d87942ca575ddb89d"><enum>3554.</enum><header>Annual
				operational evaluation</header>
								<subsection commented="no" id="idD7ED9CA2606443C7814A634895D447D0"><enum>(a)</enum><header>Guidance</header>
									<paragraph commented="no" id="id3DB4DAECB79D42C5A64C6CF52869EB7E"><enum>(1)</enum><header>In
				general</header><text>Not later than 1 year after the date of enactment of the
				<short-title>Cybersecurity and Internet Freedom Act of
				2011</short-title> and each year thereafter, the Director of the National
				Center for Cybersecurity and Communications shall oversee, coordinate, and
				develop guidance for the effective implementation of operational evaluations of
				the Federal information infrastructure and agency information security programs
				and practices to determine the effectiveness of such program and
				practices.</text>
									</paragraph><paragraph commented="no" id="idE32EF266B8D64797B2BEB347AFA77ECF"><enum>(2)</enum><header>Collaboration
				in development</header><text>In developing guidance for the operational
				evaluations described under this section, the Director of the National Center
				for Cybersecurity and Communications shall collaborate with the Federal
				Information Security Taskforce and the Council of Inspectors General on
				Integrity and Efficiency, and other agencies as necessary, to develop and
				update risk-based performance indicators and measures that assess the adequacy
				and effectiveness of information security of an agency and the Federal
				information infrastructure.</text>
									</paragraph><paragraph commented="no" id="id68D928C6E8E3462A98B9997BA202528F"><enum>(3)</enum><header>Contents of
				operational evaluation</header><text>Each operational evaluation under this
				section—</text>
										<subparagraph commented="no" id="id311F6D1E99694E719D52DBF85DA401EF"><enum>(A)</enum><text>shall be
				prioritized based on risk; and</text>
										</subparagraph><subparagraph commented="no" id="id7FEA8630230C48A49C0AD4BC4103E5E3"><enum>(B)</enum><text>shall—</text>
											<clause commented="no" id="id86E62572359D448E90B7E369B9EB1783"><enum>(i)</enum><text>test the
				effectiveness of agency information security policies, procedures, and
				practices of the information systems of the agency, or a representative subset
				of those information systems;</text>
											</clause><clause commented="no" id="id31F07F3222EB40E9839F960A9C968F25"><enum>(ii)</enum><text>assess (based on
				the results of the testing) compliance with—</text>
												<subclause commented="no" id="id542F8D897FBB4C73B85AAA907009F7BC"><enum>(I)</enum><text>the requirements
				of this subchapter; and</text>
												</subclause><subclause commented="no" id="idCE4B95B69AE947C0A09231C89817F44B"><enum>(II)</enum><text>related
				information security policies, procedures, standards, and guidelines;</text>
												</subclause></clause><clause commented="no" id="id7F63BAFECF6F47818F9D8F625AD2A1C6"><enum>(iii)</enum><text>evaluate
				whether agencies—</text>
												<subclause commented="no" id="id0C1899C81EE04351BD4F3C80472DF384"><enum>(I)</enum><text>effectively
				monitor, detect, analyze, protect, report, and respond to vulnerabilities and
				incidents;</text>
												</subclause><subclause commented="no" id="id10AACC2E36AE4EE4A2D27060789B23DB"><enum>(II)</enum><text>report to and
				collaborate with the appropriate public and private security operation centers,
				the Director of the National Center for Cybersecurity and Communications, and
				law enforcement agencies; and</text>
												</subclause><subclause commented="no" id="id76A992E59871495C9C6AA2C94EB1D363"><enum>(III)</enum><text>remediate or
				mitigate the risk posed by attacks and exploitations in a timely fashion in
				order to prevent future vulnerabilities and incidents; and</text>
												</subclause></clause><clause commented="no" id="id8381C1F0A3EE4804A02F9475AF532DEA"><enum>(iv)</enum><text>identify
				deficiencies of agency information security policies, procedures, and controls
				on the agency information infrastructure.</text>
											</clause></subparagraph></paragraph></subsection><subsection commented="no" id="id13A9E98EA3294F1BAF2B1254B9C95549"><enum>(b)</enum><header>Conduct an
				operational evaluation</header>
									<paragraph commented="no" id="id9C638FBF196443F992C6B2FF146B234B"><enum>(1)</enum><header>In
				general</header><text>Except as provided under paragraph (2), and in
				consultation with the Chief Information Officer and senior officials
				responsible for the affected systems, the Chief Information Security Officer of
				each agency shall not less than annually—</text>
										<subparagraph commented="no" id="id4D0DF12CD9654FCA8F305B8477F9E213"><enum>(A)</enum><text>conduct an
				operational evaluation of the agency information infrastructure for
				vulnerabilities, attacks, and exploitations of the agency information
				infrastructure;</text>
										</subparagraph><subparagraph commented="no" id="idB9AC89793B46423D975D4E73BA8EC531"><enum>(B)</enum><text>evaluate the
				ability of the agency to monitor, detect, correlate, analyze, report, and
				respond to incidents; and</text>
										</subparagraph><subparagraph commented="no" id="id681D5E09D49A4509B0EB242F1BF84CD3"><enum>(C)</enum><text>report to the
				head of the agency, the Director of the National Center for Cybersecurity and
				Communications, the Chief Information Officer, and the Inspector General for
				the agency the findings of the operational evaluation.</text>
										</subparagraph></paragraph><paragraph commented="no" id="id81606B4C546C486F8AB725CE7B5FF8A8"><enum>(2)</enum><header>Satisfaction of
				requirements by other evaluation</header><text>Unless otherwise specified by
				the Director of the National Center for Cybersecurity and Communications, if
				the Director of the National Center for Cybersecurity and Communications
				conducts an operational evaluation of the agency information infrastructure
				under section 245(b)(2)(A) of the Homeland Security Act of 2002, the Chief
				Information Security Officer may deem the requirements of paragraph (1)
				satisfied for the year in which the operational evaluation described under this
				paragraph is conducted.</text>
									</paragraph></subsection><subsection id="ID49114d97f77b4b00bb198b06fae9b19e"><enum>(c)</enum><header>Corrective
				measures mitigation and remediation plans</header>
									<paragraph id="id2C2F0F1298C44076861DB17EA265629B"><enum>(1)</enum><header>In
				general</header><text>In consultation with the Director of the National Center
				for Cybersecurity and Communications and the Chief Information Officer, Chief
				Information Security Officers shall remediate or mitigate vulnerabilities in
				accordance with this subsection.</text>
									</paragraph><paragraph id="IDa3ebd25e2bd84a3cb942828ac4b66ec2"><enum>(2)</enum><header>Risk-based
				plan</header><text>After an operational evaluation is conducted under this
				section or under section 245(b) of the Homeland Security Act of 2002, the
				agency shall submit to the Director of the National Center for Cybersecurity
				and Communications in a timely fashion a risk-based plan for addressing
				recommendations and mitigating and remediating vulnerabilities identified as a
				result of such operational evaluation, including a timeline and budget for
				implementing such plan.</text>
									</paragraph><paragraph id="ID09a6049ef3344be69693b671993a9ef3"><enum>(3)</enum><header>Approval or
				disapproval</header><text>Not later than 15 days after receiving a plan
				submitted under paragraph (2), the Director of the National Center for
				Cybersecurity and Communications shall—</text>
										<subparagraph id="id5568EBBD928E492DA78314656731BBC2"><enum>(A)</enum><text>approve or
				disprove the agency plan; and</text>
										</subparagraph><subparagraph id="id050E84B3C9824A31A7A2C0B9ABD9569C"><enum>(B)</enum><text>comment on the
				adequacy and effectiveness of the plan.</text>
										</subparagraph></paragraph><paragraph commented="no" id="id5A68C77CDD9A4FA7857122659D39968A"><enum>(4)</enum><header>Isolation from
				infrastructure</header>
										<subparagraph commented="no" id="idFBF1369484444D0ABD7111E0D23408B5"><enum>(A)</enum><header>In
				general</header><text>The Director of the National Center for Cybersecurity and
				Communications may, consistent with the contingency or continuity of operation
				plans applicable to such agency information infrastructure, order the isolation
				of any component of the Federal information infrastructure from any other
				Federal information infrastructure, if—</text>
											<clause commented="no" id="id5DBD59DA94B647B0BDF77B47A1F6A3A5"><enum>(i)</enum><text>an agency does
				not implement measures in a risk-based plan approved under this subsection;
				and</text>
											</clause><clause commented="no" id="idFDADF2164942447C81BBCE5F4CEDCFC3"><enum>(ii)</enum><text>the failure to
				comply presents a significant danger to the Federal information
				infrastructure.</text>
											</clause></subparagraph><subparagraph commented="no" id="idB8832670C08446AC9E2DDA37A7B5EF4F"><enum>(B)</enum><header>Duration</header><text>An
				isolation under subparagraph (A) shall remain in effect until—</text>
											<clause commented="no" id="id31B4A111F80448E791140C264C3EB17E"><enum>(i)</enum><text>the Director of
				the National Center for Cybersecurity and Communications determines that
				corrective measures have been implemented; or</text>
											</clause><clause commented="no" id="idC6D231ECF26B469689E114A311DEE995"><enum>(ii)</enum><text>an updated
				risk-based plan is approved by the Director of the National Center for
				Cybersecurity and Communications and implemented by the agency.</text>
											</clause></subparagraph></paragraph></subsection><subsection id="ID5bc8799a18db403db3bdc3daa2fd99bb"><enum>(d)</enum><header>Operational
				guidance</header><text>The Director of the National Center for Cybersecurity
				and Communications shall—</text>
									<paragraph id="ID7f2af9569779490f872378520970d0ac"><enum>(1)</enum><text>not later than
				180 days after the date of enactment of the <short-title>Cybersecurity and Internet Freedom Act of
				2011</short-title>, develop operational guidance for operational evaluations as
				required under this section that are risk-based and cost effective; and</text>
									</paragraph><paragraph id="ID4bbceec4e48a454a9c4981eb943a2bce"><enum>(2)</enum><text>periodically
				evaluate and ensure information is available on an automated and continuous
				basis through the system required under section 3552(a)(3)(D) to Congress
				on—</text>
										<subparagraph id="ID112a1f65dbe0491ab6e1ab055c5eabfd"><enum>(A)</enum><text>the adequacy and
				effectiveness of the operational evaluations conducted under this section or
				section 245(b) of the Homeland Security Act of 2002; and</text>
										</subparagraph><subparagraph id="IDe3f7a0ec293846529d1d116a7e91a4c5"><enum>(B)</enum><text>possible
				executive and legislative actions for cost-effectively managing the risks to
				the Federal information infrastructure.</text>
										</subparagraph></paragraph></subsection></section><section id="ID267c7a1a27b540d68392f3d4c335ed47"><enum>3555.</enum><header>Federal
				Information Security Taskforce</header>
								<subsection id="IDc386248b2be84fe18ec70921506b11f7"><enum>(a)</enum><header>Establishment</header><text>There
				is established in the executive branch a Federal Information Security
				Taskforce.</text>
								</subsection><subsection id="IDec45c9a8953b407488caff5d1429b4fa"><enum>(b)</enum><header>Membership</header><text>The
				members of the Federal Information Security Taskforce shall be full-time senior
				Government employees and shall be as follows:</text>
									<paragraph id="ID131444a0640f484994930c47ac0b71b3"><enum>(1)</enum><text>The Director of
				the National Center for Cybersecurity and Communications.</text>
									</paragraph><paragraph id="IDfefa8b09741a4e60a85d169527c25c19"><enum>(2)</enum><text>The Administrator
				of the Office of Electronic Government of the Office of Management and
				Budget.</text>
									</paragraph><paragraph id="ID00945902ef4f4545836187600dd9e9c5"><enum>(3)</enum><text>The Chief
				Information Security Officer of each agency described under section 901(b) of
				title 31.</text>
									</paragraph><paragraph id="ID2412e46269ba4b6683a6beeed3bebffa"><enum>(4)</enum><text>The Chief
				Information Security Officer of the Department of the Army, the Department of
				the Navy, and the Department of the Air Force.</text>
									</paragraph><paragraph id="IDf8d00677140c40b19f0e014292a61364"><enum>(5)</enum><text>A representative
				from the Office of Cyberspace Policy.</text>
									</paragraph><paragraph id="ID26de4124c4d54d1b80fc5d7be2f546ae"><enum>(6)</enum><text>A representative
				from the Office of the Director of National Intelligence.</text>
									</paragraph><paragraph id="ID89db119e1f9d4ee890bd92d4a36483f8"><enum>(7)</enum><text>A representative
				from the United States Cyber Command.</text>
									</paragraph><paragraph id="ID2b9330ebba7a4de8b5503b9c906dd53e"><enum>(8)</enum><text>A representative
				from the National Security Agency.</text>
									</paragraph><paragraph id="ID0092419a85cd41ff92ec4993b2223b1e"><enum>(9)</enum><text>A representative
				from the United States Computer Emergency Readiness Team.</text>
									</paragraph><paragraph id="ID224d0360d6eb49b881612108914bf033"><enum>(10)</enum><text>A representative
				from the Intelligence Community Incident Response Center.</text>
									</paragraph><paragraph id="ID07848b49326347e78f3e21df7324f69b"><enum>(11)</enum><text>A representative
				from the Committee on National Security Systems.</text>
									</paragraph><paragraph id="IDbf5bf6bd539d4fbda18e9f812676e755"><enum>(12)</enum><text>A representative
				from the National Institute for Standards and Technology.</text>
									</paragraph><paragraph id="ID939305cf3a364b72b6f29c65911112f9"><enum>(13)</enum><text>A representative
				from the Council of Inspectors General on Integrity and Efficiency.</text>
									</paragraph><paragraph id="IDa0c2ceed2379417196303139bc346502"><enum>(14)</enum><text>A representative
				from State and local government.</text>
									</paragraph><paragraph id="ID8135072996e84d02bd4012913055b288"><enum>(15)</enum><text>Any other
				officer or employee of the United States designated by the chairperson.</text>
									</paragraph></subsection><subsection id="idCD1322BE0FA8454FA80B0A2666EAB1A4"><enum>(c)</enum><header>Chairperson and
				Vice-Chairperson</header>
									<paragraph id="idBE03BFAB8696483DA8319D3431771AA7"><enum>(1)</enum><header>Chairperson</header><text>The
				Director of the National Center for Cybersecurity and Communications shall act
				as chairperson of the Federal Information Security Taskforce.</text>
									</paragraph><paragraph id="id7193068B8010456C8F279CC1D048A472"><enum>(2)</enum><header>Vice-chairperson</header><text>The
				vice-chairperson of the Federal Information Security Taskforce shall—</text>
										<subparagraph id="id7D0913BF667E4F55B21FAAE94D9D3034"><enum>(A)</enum><text>be selected by
				the Federal Information Security Taskforce from among its members;</text>
										</subparagraph><subparagraph id="id95DA596D7E874AEE9EA0C5A31F0A1A23"><enum>(B)</enum><text>serve a 1-year
				term and may serve multiple terms; and</text>
										</subparagraph><subparagraph id="id75A402207528444EAAF2C2B8917ABC55"><enum>(C)</enum><text>serve as a
				liaison to the Chief Information Officer, Council of the Inspectors General on
				Integrity and Efficiency, Committee on National Security Systems, and other
				councils or committees as appointed by the chairperson.</text>
										</subparagraph></paragraph></subsection><subsection id="idD02E37A4871A49A9B47C60EEF45E51FD"><enum>(d)</enum><header>Functions</header><text>The
				Federal Information Security Taskforce shall—</text>
									<paragraph id="idDF2433BCA9664B9E99F54E2FEF9B4354"><enum>(1)</enum><text>be the principal
				interagency forum for collaboration regarding best practices and
				recommendations for agency information security and the security of the Federal
				information infrastructure;</text>
									</paragraph><paragraph id="ID43f437d93daa4716a16ac24332e5c4f3"><enum>(2)</enum><text>assist in the
				development of and annually evaluate guidance to fulfill the requirements under
				sections 3554 and 3556;</text>
									</paragraph><paragraph id="id4C468D5BDD124BB880D5ABD66BF4EEC8"><enum>(3)</enum><text>share experiences
				and innovative approaches relating to threats against the Federal information
				infrastructure, information sharing and information security best practices,
				penetration testing regimes, and incident response, mitigation, and
				remediation;</text>
									</paragraph><paragraph id="idBBF00A09AD344846B9F4E6370CE656D3"><enum>(4)</enum><text>promote the
				development and use of standard performance indicators and measures for agency
				information security that—</text>
										<subparagraph id="id9379DF86EA5B4AAA8050C711B9F5F084"><enum>(A)</enum><text>are
				outcome-based;</text>
										</subparagraph><subparagraph id="id11D436618E404EF78BFD9C0281BBCC2D"><enum>(B)</enum><text>focus on risk
				management;</text>
										</subparagraph><subparagraph id="id4BC3C1B432F14553AEA354168CC718BA"><enum>(C)</enum><text>align with the
				business and program goals of the agency;</text>
										</subparagraph><subparagraph id="id0DEE66B44B8F41E3AF0FD1503E1D4875"><enum>(D)</enum><text>measure
				improvements in the agency security posture over time; and</text>
										</subparagraph><subparagraph id="id35B5530186374E398AA069BC75A8772D"><enum>(E)</enum><text>reduce burdensome
				and inefficient performance indicators and measures;</text>
										</subparagraph></paragraph><paragraph id="id7C7ED8233CE3449BBE3BC676679AD9F9"><enum>(5)</enum><text>recommend to the
				Office of Personnel Management the necessary qualifications to be established
				for Chief Information Security Officers to be capable of administering the
				functions described under this subchapter including education, training, and
				experience;</text>
									</paragraph><paragraph id="idDF7C0BBB4ABC498CAF6728B8E03BB499"><enum>(6)</enum><text>enhance
				information system processes by establishing a prioritized baseline of
				information security measures and controls that can be continuously monitored
				through automated mechanisms; and</text>
									</paragraph><paragraph id="ID584455d0a073428f824cc75a9e65497b"><enum>(7)</enum><text>evaluate the
				effectiveness and efficiency of any reporting and compliance requirements that
				are required by law related to the information security of Federal information
				infrastructure; and</text>
									</paragraph><paragraph id="id55AF6678D07D431990ADE5792AEEF76A"><enum>(8)</enum><text>submit proposed
				enhancements developed under paragraphs (1) through (7) to the Director of the
				National Center for Cybersecurity and Communications.</text>
									</paragraph></subsection><subsection id="idEDE3742DD5ED4901B96C6758B4B8CC08"><enum>(e)</enum><header>Termination</header>
									<paragraph id="idD4AAB35A7DEC4E0EAEC8171C4A05F81B"><enum>(1)</enum><header>In
				general</header><text>Except as provided under paragraph (2), the Federal
				Information Security Taskforce shall terminate 4 years after the date of
				enactment of the <short-title>Cybersecurity and Internet
				Freedom Act of 2011</short-title>.</text>
									</paragraph><paragraph id="idBE3348B269DD482FAD1602E8385C5F09"><enum>(2)</enum><header>Extension</header><text>The
				President may—</text>
										<subparagraph id="id68BCC85934484807A6CD4C338942270C"><enum>(A)</enum><text>extend the
				Federal Information Security Taskforce by executive order; and</text>
										</subparagraph><subparagraph id="idDD41A6CBE5224572B199BBC0F12FA26D"><enum>(B)</enum><text>make more than 1
				extension under this paragraph for any period as the President may
				determine.</text>
										</subparagraph></paragraph></subsection></section><section id="IDab422109378045c690aa6e9ce6137662"><enum>3556.</enum><header>Independent
				Assessments</header>
								<subsection id="IDcec2436620c2451293eba2383e726645"><enum>(a)</enum><header>In
				general</header>
									<paragraph id="ID94648eb5542e46d388b029f991ae6810"><enum>(1)</enum><header>Inspectors
				General assessments</header><text>Not less than every 2 years, each agency with
				an Inspector General appointed under the Inspector General Act of 1978 (5
				U.S.C. App.) or any other law shall assess the adequacy and effectiveness of
				the information security program developed under section 3553 (b) and (c), and
				evaluations conducted under section 3554.</text>
									</paragraph><paragraph id="IDc83d6a4bd72e45a296664dae83cdc6a6"><enum>(2)</enum><header>Independent
				assessments</header><text>For each agency to which paragraph (1) does not
				apply, the head of the agency shall engage an independent external auditor to
				perform the assessment.</text>
									</paragraph></subsection><subsection id="ID6ce5869299b34dfcaa9bad52d7adeec9"><enum>(b)</enum><header>Standards</header><text>The
				assessments required under subsection (a) shall be performed in accordance with
				standards developed by the Government Accountability Office, in collaboration
				with the Council of Inspectors General on Integrity and Efficiency and with
				assistance from the Federal Information Security Taskforce.</text>
								</subsection><subsection id="ID2c42f0b342a7400f9f49b1e33367b458"><enum>(c)</enum><header>Existing
				assessments</header><text>The assessments required under this section may be
				based in whole or in part on an audit, evaluation, or report relating to
				programs or practices of the applicable agency.</text>
								</subsection><subsection id="id23F6E22F265D4E40A02CEFEFDA33F440"><enum>(d)</enum><header>Reporting of
				Information</header>
									<paragraph id="IDa026f61cc12e4911a04ac62e2e7d776c"><enum>(1)</enum><header>Inspectors
				general reporting</header><text>Each Inspector General shall ensure information
				obtained as a result of the assessment required under this section, or any
				other relevant information, is—</text>
										<subparagraph id="IDb79d32f570224d7684b3b69b00ebd79c"><enum>(A)</enum><text>provided to the
				head of the agency, the agency Chief Information Security Officer, and the
				agency Chief Information Officer; and</text>
										</subparagraph><subparagraph id="ID82c19fcb28304402b2df2c4b45f54260"><enum>(B)</enum><text>available through
				the system required under section 3552(a)(3)(D) to Congress and the Director of
				the National Center for Cybersecurity and Communications.</text>
										</subparagraph></paragraph><paragraph id="id8E000C96576F4F5BB4AA943360DE41AB"><enum>(2)</enum><header>Heads of
				agencies reporting</header><text>If an assessment described under subsection
				(a)(2) is performed, the head of the agency shall comply with the requirements
				of paragraph (1) (A) and (B).</text>
									</paragraph></subsection></section><section id="ID858957c639094e3b8d8f59f7a3f8a57c"><enum>3557.</enum><header>Protection of
				Information</header><text display-inline="no-display-inline">In complying with
				this subchapter, agencies, evaluators, and Inspectors General shall take
				appropriate actions to ensure the protection of information which, if
				disclosed, may adversely affect information security. Protections under this
				chapter shall be commensurate with the risk and comply with all applicable laws
				and regulations.</text>
							</section><section id="id7CA272BA68B04EADB5207B0A909583E9"><enum>3558.</enum><header>Department of
				Defense and Central Intelligence Agency systems</header>
								<subsection id="IDff32cedbb4264ca58c1a9af269bc11d5"><enum>(a)</enum><header>In
				general</header><text>The authorities of the Director of the National Center
				for Cybersecurity and Communications under this subchapter shall be delegated
				to—</text>
									<paragraph id="id37B0D0C854EC4C408F24BF95A362D129"><enum>(1)</enum><text>the Secretary of
				Defense in the case of systems described under subsection (b); and</text>
									</paragraph><paragraph id="idF216FFD4CAEA49FD82E510630A1203FA"><enum>(2)</enum><text>the Director of
				the Central Intelligence Agency in the case of systems described under
				subsection (c).</text>
									</paragraph></subsection><subsection id="ID8ff26555804e4600a31a5447090a1467"><enum>(b)</enum><header>Department of
				Defense systems</header><text>The systems described under this subsection are
				systems that are operated by the Department of Defense, a contractor of the
				Department of Defense, or another entity on behalf of the Department of Defense
				that processes any information the unauthorized access, use, disclosure,
				disruption, modification, or destruction of which would have a debilitating
				impact on the mission of the Department of Defense.</text>
								</subsection><subsection id="ID800c3c9510154a06b472abd525c31108"><enum>(c)</enum><header>Central
				Intelligence Agency systems</header><text>The systems described under this
				subsection are systems that are operated by the Central Intelligence Agency, a
				contractor of the Central Intelligence Agency, or another entity on behalf of
				the Central Intelligence Agency that processes any information the unauthorized
				access, use, disclosure, disruption, modification, or destruction of which
				would have a debilitating impact on the mission of the Central Intelligence
				Agency.</text>
								</subsection></section></subchapter><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="ID52a57eea5acf43df881611687cc4d241"><enum>(c)</enum><header>Technical and
			 conforming amendments</header>
					<paragraph id="ID9b8cff99002a4a6d90812195d44ab935"><enum>(1)</enum><header>Table of
			 sections</header><text>The table of sections for chapter 35 of title 44, United
			 States Code, is amended by striking the matter relating to subchapters II and
			 III and inserting the following:</text>
						<quoted-block display-inline="no-display-inline" id="id46C2AB1A82BA4E2190F324D806CD944A" style="OLC">
							<toc>
								<toc-entry idref="id4392C74EF2684F3F8E2DF631D6D38002" level="subchapter">SUBCHAPTER II—Information security</toc-entry>
								<toc-entry idref="id86798A2E91F5435A98B0740945DDE0AE" level="section">3550. Purposes.</toc-entry>
								<toc-entry idref="IDc8ba711271ae4f3798ebe02e833fbb53" level="section">3551. Definitions.</toc-entry>
								<toc-entry idref="idD1178BA90EFF4C839175401A3996F679" level="section">3552. Authority and functions of the National Center for
				Cybersecurity and Communications.</toc-entry>
								<toc-entry idref="ID5447676884944c8f8dad2030f2c72383" level="section">3553. Agency responsibilities.</toc-entry>
								<toc-entry idref="IDc87ce2a4409c497d87942ca575ddb89d" level="section">3554. Annual operational evaluation.</toc-entry>
								<toc-entry idref="ID267c7a1a27b540d68392f3d4c335ed47" level="section">3555. Federal Information Security Taskforce.</toc-entry>
								<toc-entry bold="off" idref="ID267c7a1a27b540d68392f3d4c335ed47" level="section">3556. Independent assessments.</toc-entry>
								<toc-entry bold="off" idref="ID267c7a1a27b540d68392f3d4c335ed47" level="section">3557. Protection of information.</toc-entry>
								<toc-entry bold="off" level="section">3558. Department of Defense and
				Central Intelligence Agency
				systems.</toc-entry>
							</toc>
							<after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph><paragraph commented="no" id="ID875291d07f8f4d17ade01ee23ed1249a"><enum>(2)</enum><header>Other
			 references</header>
						<subparagraph id="ID185c5a46e7c94f42b1baeb22ab0f9756"><enum>(A)</enum><text>Section
			 1001(c)(1)(A) of the Homeland Security Act of 2002 (6 U.S.C. 511(c)(1)(A)) is
			 amended by striking <quote>section 3532(3)</quote> and inserting <quote>section
			 3551(b)</quote>.</text>
						</subparagraph><subparagraph id="ID974caa3941db446eaeca0a508a68af75"><enum>(B)</enum><text>Section
			 2222(j)(6) of title 10, United States Code, is amended by striking
			 <quote>section 3542(b)(2))</quote> and inserting <quote>section
			 3551(b)</quote>.</text>
						</subparagraph><subparagraph id="ID8767fb2333e443d4a28d3cfd33121ca6"><enum>(C)</enum><text>Section
			 2223(c)(3) of title 10, United States Code, is amended, by striking
			 <quote>section 3542(b)(2))</quote> and inserting <quote>section
			 3551(b)</quote>.</text>
						</subparagraph><subparagraph id="ID4549ab1d6e9e43e0abeb57425afd6e30"><enum>(D)</enum><text>Section 2315 of
			 title 10, United States Code, is amended by striking <quote>section
			 3542(b)(2))</quote> and inserting <quote>section 3551(b)</quote>.</text>
						</subparagraph><subparagraph id="ID2090629a43c4482db206bbe04d7149a5"><enum>(E)</enum><text>Section 20(a)(2)
			 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) is
			 amended by striking <quote>section 3532(b)(2)</quote> and inserting
			 <quote>section 3551(b)</quote>.</text>
						</subparagraph><subparagraph commented="no" id="ID61aeed6938fd4556bd1d92de0fa97426"><enum>(F)</enum><text>Section 21(b)(2)
			 of the National Institute of Standards and Technology Act (15 U.S.C.
			 278g–4(b)(2)) is amended by striking <quote>Institute and</quote> and inserting
			 <quote>Institute, the Director of the National Center on Cybersecurity and
			 Communications, and</quote>.</text>
						</subparagraph><subparagraph commented="no" id="ID46cfef36ece04f018ce2c73f5f60c17b"><enum>(G)</enum><text>Section 21(b)(3)
			 of the National Institute of Standards and Technology Act (15 U.S.C.
			 278g–4(b)(3)) is amended by inserting <quote>the Director of the National
			 Center on Cybersecurity and Communications,</quote> after <quote>the Director
			 of the National Security Agency,</quote>.</text>
						</subparagraph><subparagraph id="IDbdd0f3cefc20409285fa9fafb926106d"><enum>(H)</enum><text>Section 8(d)(1)
			 of the Cyber Security Research and Development Act (15 U.S.C. 7406(d)(1)) is
			 amended by striking <quote>section 3534(b)</quote> and inserting <quote>section
			 3553(b)</quote>.</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDb79634762ccb47b39139822ea1079119"><enum>(3)</enum><header>Homeland
			 Security Act of 2002</header>
						<subparagraph commented="no" display-inline="no-display-inline" id="id1AA75132685C40169654B0C8FC2157AC"><enum>(A)</enum><header>Title
			 X</header><text>The Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is
			 amended by striking title X.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idA3E0EAE2BCB24921BFAF0A466C9CE4D1"><enum>(B)</enum><header>Table of
			 contents</header><text>The table of contents in section 1(b) of the Homeland
			 Security Act of 2002 (6 U.S.C. 101 et seq.) is amended by striking the matter
			 relating to title X.</text>
						</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id0593313AE13B4C8D8D174D3078DF4C16"><enum>(d)</enum><header>Repeal of other
			 standards</header>
					<paragraph commented="no" display-inline="no-display-inline" id="id95117B809E0D4233BE1C9F4C1584EE0B"><enum>(1)</enum><header>In
			 general</header><text>Section 11331 of title 40, United States Code, is
			 repealed.</text>
					</paragraph><paragraph id="id00BD98F125FA4C8DB9306FF419C884B0"><enum>(2)</enum><header>Technical and
			 conforming amendments</header>
						<subparagraph id="idDE4C0B8C98A04FFC8909B710706BEE91"><enum>(A)</enum><text>Section 20(c)(3)
			 of the National Institute of Standards and Technology Act (15 U.S.C.
			 278g–3(c)(3)) is amended by striking <quote>under section 11331 of title 40,
			 United States Code</quote>.</text>
						</subparagraph><subparagraph id="idF44C4DB181A249A3902FB6AE44832287"><enum>(B)</enum><text>Section 20(d)(1)
			 of the National Institute of Standards and Technology Act (15 U.S.C.
			 278g–3(d)(1)) is amended by striking <quote>the Director of the Office of
			 Management and Budget for promulgation under section 11331 of title 40, United
			 States Code</quote> and inserting <quote>the Secretary of Commerce for
			 promulgation</quote>.</text>
						</subparagraph><subparagraph id="id00C9F38359394A0B99574565CB04D8FF"><enum>(C)</enum><text>Section 11302(d)
			 of title 40, United States Code, is amended by striking <quote>under section
			 11331 of this title and</quote>.</text>
						</subparagraph><subparagraph id="idD825D32E702B412F8597FB32001C8AEF"><enum>(D)</enum><text>Section 1874A
			 (e)(2)(A)(ii) of the Social Security Act (42 U.S.C.1395kk-1 (e)(2)(A)(ii)) is
			 amended by striking <quote>section 11331 of title 40, United States
			 Code</quote> and inserting <quote>section 3552 of title 44, United States
			 Code</quote>.</text>
						</subparagraph><subparagraph id="id847BEFC734D5423FACA75547A9FCF5B7"><enum>(E)</enum><text>Section
			 3504(g)(2) of title 44, United States Code, is amended by striking
			 <quote>section 11331 of title 40</quote> and inserting <quote>section 3552 of
			 title 44</quote>.</text>
						</subparagraph><subparagraph id="id2C2632FB04294C2888C0117E51F097C9"><enum>(F)</enum><text>Section
			 3504(h)(1) of title 44, United States Code, is amended by inserting “, the
			 Director of the National Center for Cybersecurity and Communications,” after
			 <quote>the National Institute of Standards and Technology</quote>.</text>
						</subparagraph><subparagraph id="id75E52C9A59614643A453F750863D4163"><enum>(G)</enum><text>Section
			 3504(h)(1)(B) of title 44, United States Code, is amended by striking
			 <quote>under section 11331 of title 40</quote> and inserting <quote>section
			 3552 of title 44</quote>.</text>
						</subparagraph><subparagraph id="id8541760196E24289A32C283101832627"><enum>(H)</enum><text>Section 3518(d)
			 of title 44, United States Code, is amended by striking <quote>sections 11331
			 and 11332</quote> and inserting <quote>section 11332</quote>.</text>
						</subparagraph><subparagraph id="idDA30D985079F418C9D234AF6B644361B"><enum>(I)</enum><text>Section
			 3602(f)(8) of title 44, United States Code, is amended by striking “under
			 section 11331 of title 40.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id9F2E96CFCA974375AA79F4173A429583"><enum>(J)</enum><text>Section
			 3603(f)(5) of title 44, United States Code, is amended by striking <quote>and
			 promulgated under section 11331 of title 40,</quote>.</text>
						</subparagraph></paragraph></subsection></section></title><title id="idB3615AE252CB4FF5A86D4143B6D5DE6D"><enum>IV</enum><header>Recruitment and
			 professional development</header>
			<section id="ID29c72cb85cb54b4aaddeab346c193576"><enum>401.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text>
				<paragraph id="id2ACB17BF254B42E39178BDDE1C320C51"><enum>(1)</enum><header>Cybersecurity
			 mission</header><text display-inline="yes-display-inline">The term
			 <term>cybersecurity mission</term> means the activities of the Federal
			 Government that encompass the full range of threat reduction, vulnerability
			 reduction, deterrence, international engagement, incident response, resiliency,
			 and recovery policies and activities, including computer network operations,
			 information assurance, law enforcement, diplomacy, military, and intelligence
			 missions as such activities relate to the security and stability of
			 cyberspace.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id68EC11B624EB4058BE6C9774109CDD2D"><enum>(2)</enum><header display-inline="yes-display-inline">Federal agency’s cybersecurity
			 mission</header><text display-inline="yes-display-inline">The term
			 <term>Federal agency's cybersecurity mission</term> means, with respect to any
			 Federal agency, the portion of the cybersecurity mission that is the
			 responsibility of the Federal agency.</text>
				</paragraph></section><section id="ID8b3dfe337f3249459729da301ac9a864"><enum>402.</enum><header>Assessment of
			 cybersecurity workforce</header>
				<subsection id="IDe17b2b9b03a046c781b784eaa07b6bad"><enum>(a)</enum><header>In
			 general</header><text>The Director of the Office of Personnel Management and
			 the Director shall assess the readiness and capacity of the Federal workforce
			 to meet the needs of the cybersecurity mission of the Federal
			 Government.</text>
				</subsection><subsection id="ID50ac42d28d54477e888155f73ef11cd2"><enum>(b)</enum><header>Strategy</header>
					<paragraph id="ID444eeccb7e1c4de8b319f9d8951e06a0"><enum>(1)</enum><header>In
			 general</header><text>The Director of the Office of Personnel Management, in
			 consultation with the Director and the Director of the Office of Management and
			 Budget, shall develop a comprehensive workforce strategy that enhances the
			 readiness, capacity, training, and recruitment and retention of Federal
			 cybersecurity personnel.</text>
					</paragraph><paragraph id="IDe451922ffa1c474185a57ae1ce08e317"><enum>(2)</enum><header>Contents</header><text>The
			 strategy developed under paragraph (1) shall include—</text>
						<subparagraph id="ID477e1839c3a440c099e6ff028238f121"><enum>(A)</enum><text>a 5-year plan on
			 recruitment of personnel for the Federal workforce; and</text>
						</subparagraph><subparagraph id="ID4d317bee033c4db3a7ce580a02def832"><enum>(B)</enum><text>10-year and
			 20-year projections of workforce needs.</text>
						</subparagraph></paragraph><paragraph id="IDda862586e5ce4a04ad73c3e4fc77c2a3"><enum>(3)</enum><header>Dates for
			 completion</header><text>The strategy under this subsection shall be—</text>
						<subparagraph id="idBA20CFBB276E4D69958DF2ECE86A971D"><enum>(A)</enum><text>completed not
			 later than 180 days after the date of enactment of this Act; and</text>
						</subparagraph><subparagraph id="idDDC893BCD214469E96C2DA5FFF9F685B"><enum>(B)</enum><text>updated as
			 needed.</text>
						</subparagraph></paragraph></subsection></section><section id="IDf9e9b7375eb844dda53fb996371978dc"><enum>403.</enum><header>Strategic
			 cybersecurity workforce planning</header>
				<subsection id="ID32dddcf0c3f74321b73dde1ccf28d7ca"><enum>(a)</enum><header>Federal agency
			 development of strategic cybersecurity workforce plans</header><text>Not later
			 than 180 days after the date of enactment of this Act and in every subsequent
			 year, and subject to subsection (c)(2), the head of each Federal agency shall
			 develop a strategic cybersecurity workforce plan as part of the Federal agency
			 performance plan required under section 1115 of title 31, United States
			 Code.</text>
				</subsection><subsection id="ID1d6ac866d1344e2891f2cec0fd7a8549"><enum>(b)</enum><header>Basis and
			 guidance for plans</header><text>Each Federal agency shall develop a plan
			 prepared under subsection (a) on the basis of the assessment developed under
			 section 402 and any subsequent guidance issued by the Director of the Office of
			 Personnel Management, in consultation with the Director and the Director of the
			 Office of Management and Budget.</text>
				</subsection><subsection id="ID4f5b0313a19b4a1583e9d5c10f7ede16"><enum>(c)</enum><header>Contents of the
			 plan</header>
					<paragraph id="IDedce0b11ebd74cb9b493e808a5e2cd09"><enum>(1)</enum><header>In
			 general</header><text>Subject to paragraph (2), each plan prepared under
			 subsection (a) shall include—</text>
						<subparagraph id="ID99d694ca9a9941078179d18a604cc48f"><enum>(A)</enum><text>a description of
			 the Federal agency’s cybersecurity mission;</text>
						</subparagraph><subparagraph id="IDd40039b768f145dfa385e52c7ab55e0e"><enum>(B)</enum><text>a description and
			 analysis, relating to the specialized workforce needed by the Federal agency to
			 fulfill the Federal agency’s cybersecurity mission, including—</text>
							<clause id="ID05c8d5f0bb104608a553dc5f3ca5e171"><enum>(i)</enum><text>the
			 workforce needs of the Federal agency on the date of the report, and 10-year
			 and 20-year projections of workforce needs;</text>
							</clause><clause id="IDd28b50b245354c328271170b5b9820fd"><enum>(ii)</enum><text>hiring
			 projections to meet workforce needs, including, for at least a 2-year period,
			 specific occupation and grade levels;</text>
							</clause><clause id="ID0c904e2572fa4fb1890f534583cbc9a0"><enum>(iii)</enum><text>long-term and
			 short-term strategic goals to address critical skills deficiencies, including
			 analysis of the numbers of and reasons for attrition of employees;</text>
							</clause><clause id="IDc2a6950c7260486098a4af2143b5bcf9"><enum>(iv)</enum><text>recruitment
			 strategies, including the use of student internships, part-time employment,
			 student loan reimbursement, and telework, to attract highly qualified
			 candidates from diverse backgrounds and geographic locations;</text>
							</clause><clause id="ID124830ec71ff4d2882876d44af85b044"><enum>(v)</enum><text>an
			 assessment of the sources and availability of individuals with needed
			 expertise;</text>
							</clause><clause id="ID843ebb9be4224bb88f66ab3a034adf0a"><enum>(vi)</enum><text>ways to
			 streamline the hiring process;</text>
							</clause><clause id="ID18f81df975f849d59e4e3cd6a2c92901"><enum>(vii)</enum><text>the barriers to
			 recruiting and hiring individuals qualified in cybersecurity and
			 recommendations to overcome the barriers; and</text>
							</clause><clause id="ID78c330fb9b354e3898bf6f2e3029dbea"><enum>(viii)</enum><text>a training and
			 development plan, consistent with the curriculum developed under section 406,
			 to enhance and improve the knowledge of employees.</text>
							</clause></subparagraph></paragraph><paragraph id="ID33d50f5e64814669acd86b916053bb3e"><enum>(2)</enum><header>Federal
			 agencies with small specialized workforce</header><text>In accordance with
			 guidance issued under subsection (b), a Federal agency that needs only a small
			 specialized workforce to fulfill the Federal agency’s cybersecurity mission
			 may, in lieu of developing a separate strategic cybersecurity workforce plan,
			 present the workforce plan component referred to in paragraph (1)(A) and those
			 components referred to in paragraph (1)(B) that are relevant and appropriate to
			 the circumstances of the agency as part of the Federal agency performance plan
			 required under section 1115 of title 31, United States Code.</text>
					</paragraph></subsection></section><section id="ID6cf6c953481e43b1b5392b0476e88005"><enum>404.</enum><header>Cybersecurity
			 occupation classifications</header>
				<subsection id="ID60e09bb307c3481cb081b0a484accbbe"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, the Director of the Office of Personnel Management, in coordination with
			 the Director, shall develop and issue comprehensive occupation classifications
			 for Federal employees engaged in cybersecurity missions.</text>
				</subsection><subsection id="IDda5a2a389ff941538b8d4a82d6f90b10"><enum>(b)</enum><header>Applicability
			 of classifications</header><text>The Director of the Office of Personnel
			 Management shall ensure that the comprehensive occupation classifications
			 issued under subsection (a) may be used throughout the Federal
			 Government.</text>
				</subsection></section><section id="ID1a6d962aedca4c549183ecb2bde165af"><enum>405.</enum><header>Measures of
			 cybersecurity hiring effectiveness</header>
				<subsection id="ID6d652ee3921c46b399fdb90e91e9defa"><enum>(a)</enum><header>In
			 general</header><text>The head of each Federal agency shall measure, and
			 collect information on, indicators of the effectiveness of the recruitment and
			 hiring by the Federal agency of a workforce needed to fulfill the Federal
			 agency’s cybersecurity mission.</text>
				</subsection><subsection id="ID7fe41d2943544ff9b6e157da6de8747a"><enum>(b)</enum><header>Types of
			 information</header><text>The indicators of effectiveness measured and subject
			 to collection of information under subsection (a) shall include indicators with
			 respect to the following:</text>
					<paragraph id="ID72c143df5d31496699c07603b42fc8d9"><enum>(1)</enum><header>Recruiting and
			 hiring</header><text>In relation to recruiting and hiring by the Federal
			 agency—</text>
						<subparagraph id="IDd5d66570400c4e7590238ae498a9fd01"><enum>(A)</enum><text>the ability to
			 reach and recruit well-qualified individuals from diverse talent pools;</text>
						</subparagraph><subparagraph id="ID83468fa411f945c0b72a450ae0c9ba75"><enum>(B)</enum><text>the use and
			 impact of special hiring authorities and flexibilities to recruit the most
			 qualified applicants, including the use of student internship and scholarship
			 programs for permanent hires;</text>
						</subparagraph><subparagraph id="IDbf50ff42d2eb481eb3fe8c669e3e1385"><enum>(C)</enum><text>the use and
			 impact of special hiring authorities and flexibilities to recruit diverse
			 candidates, including criteria such as the veteran status, race, ethnicity,
			 gender, disability, or national origin of the candidates; and</text>
						</subparagraph><subparagraph id="ID2092e3ef8be445dea15e9d509b9cf1bc"><enum>(D)</enum><text>the educational
			 level, and source of applicants.</text>
						</subparagraph></paragraph><paragraph id="IDa52bffd8542c4946bc7a869dc0759aae"><enum>(2)</enum><header>Supervisors</header><text>In
			 relation to the supervisors of the positions being filled—</text>
						<subparagraph id="ID9edfcc045d84414bb059ba8518d408f9"><enum>(A)</enum><text>satisfaction with
			 the quality of the applicants interviewed and hired;</text>
						</subparagraph><subparagraph id="ID2a396224342e4623b675bc8eb7a3bbdb"><enum>(B)</enum><text>satisfaction with
			 the match between the skills of the individuals and the needs of the Federal
			 agency;</text>
						</subparagraph><subparagraph id="IDc4a87c4cefb047adb36d37e2d1d4f34e"><enum>(C)</enum><text>satisfaction of
			 the supervisors with the hiring process and hiring outcomes;</text>
						</subparagraph><subparagraph id="IDa31ebab8f234420b8d0f6ba1d6841836"><enum>(D)</enum><text>whether any
			 mission-critical deficiencies were addressed by the individuals and the
			 connection between the deficiencies and the performance of the Federal agency;
			 and</text>
						</subparagraph><subparagraph id="ID2db9927a3d624cd390e7841ecac9b2b8"><enum>(E)</enum><text>the satisfaction
			 of the supervisors with the period of time elapsed to fill the
			 positions.</text>
						</subparagraph></paragraph><paragraph id="ID79cadc81345040c89db69e9e4f64f3b1"><enum>(3)</enum><header>Applicants</header><text>The
			 satisfaction of applicants with the hiring process, including clarity of job
			 announcements, any reasons for withdrawal of an application, the
			 user-friendliness of the application process, communication regarding status of
			 applications, and the timeliness of offers of employment.</text>
					</paragraph><paragraph id="ID47eb6e833b774e2c8edd0335b9788e78"><enum>(4)</enum><header>Hired
			 individuals</header><text>In relation to the individuals hired—</text>
						<subparagraph id="ID7a230bf73b4848908da3f0abe6a70089"><enum>(A)</enum><text>satisfaction with
			 the hiring process;</text>
						</subparagraph><subparagraph id="ID69fa9f1e27a342d08f09c8250a9deb28"><enum>(B)</enum><text>satisfaction with
			 the process of starting employment in the position for which the individual was
			 hired;</text>
						</subparagraph><subparagraph id="ID0e7608caf9bb41e3ac12131dfe42ae4c"><enum>(C)</enum><text>attrition;
			 and</text>
						</subparagraph><subparagraph id="IDb9403d55da6549a09024afb1f21ef061"><enum>(D)</enum><text>the results of
			 exit interviews.</text>
						</subparagraph></paragraph></subsection><subsection id="ID20ec8c9e788c47b7a4cca254c2f53732"><enum>(c)</enum><header>Reports</header>
					<paragraph id="ID9d8fe88030734857bdefa2ee0677d9c1"><enum>(1)</enum><header>In
			 general</header><text>The head of each Federal agency shall submit the
			 information collected under this section to the Director of the Office of
			 Personnel Management on an annual basis and in accordance with the regulations
			 issued under subsection (d).</text>
					</paragraph><paragraph id="ID1c6bc482ca9947daa33399e42ed02eb0"><enum>(2)</enum><header>Availability of
			 recruiting and hiring information</header>
						<subparagraph id="ID91ac71683edf41939a7a6ef35a53fe2e"><enum>(A)</enum><header>In
			 general</header><text>The Director of the Office of Personnel Management shall
			 prepare an annual report containing the information received under paragraph
			 (1) in a consistent format to allow for a comparison of hiring effectiveness
			 and experience across demographic groups and Federal agencies.</text>
						</subparagraph><subparagraph id="ID0099f08773b0491c8a2b0193676ddef0"><enum>(B)</enum><header>Submission</header><text>The
			 Director of the Office of Personnel Management shall—</text>
							<clause id="ID6cda34d826be44a5a26f12d9ce1a06ea"><enum>(i)</enum><text>not
			 later than 90 days after the receipt of all information required to be
			 submitted under paragraph (1), make the report prepared under subparagraph (A)
			 publicly available, including on the website of the Office of Personnel
			 Management; and</text>
							</clause><clause id="IDd137322af8d04e2eac09975deb2b0626"><enum>(ii)</enum><text>before the date
			 on which the report prepared under subparagraph (A) is made publicly available,
			 submit the report to Congress.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="IDa89f06051b05438f88a40055d169a0d8"><enum>(d)</enum><header>Regulations</header>
					<paragraph id="ID7979d55f919643d99a3be2e985d3f463"><enum>(1)</enum><header>In
			 general</header><text>Not later than 180 days after the date of enactment of
			 this Act, the Director of the Office of Personnel Management shall issue
			 regulations establishing the methodology, timing, and reporting of the data
			 required to be submitted under this section.</text>
					</paragraph><paragraph id="ID86136f770b0647438da65f1eff54fdf9"><enum>(2)</enum><header>Scope and
			 detail of required information</header><text>The regulations under paragraph
			 (1) shall delimit the scope and detail of the information that a Federal agency
			 is required to collect and submit under this section, taking account of the
			 size and complexity of the workforce that the Federal agency needs to fulfill
			 the Federal agency’s cybersecurity mission.</text>
					</paragraph></subsection></section><section id="ID319a942788be46748fd9c586718d6182"><enum>406.</enum><header>Training and
			 education</header>
				<subsection id="ID3d286b9811614a8f82a193b1f7b11cf5"><enum>(a)</enum><header>Training</header>
					<paragraph id="ID07e69ab8dcb34f3888b12f3563a1f9c9"><enum>(1)</enum><header>Federal
			 Government employees and Federal contractors</header><text>The Director of the
			 Office of Personnel Management, in conjunction with the Director of the
			 National Center for Cybersecurity and Communications, the Director of National
			 Intelligence, the Secretary of Defense, and the Chief Information Officers
			 Council established under section 3603 of title 44, United States Code, shall
			 establish a cybersecurity awareness and education curriculum that shall be
			 required for all Federal employees and contractors engaged in the design,
			 development, or operation of agency information infrastructure, as defined
			 under section 3551 of title 44, United States Code.</text>
					</paragraph><paragraph id="ID7d8fa4768d6449d6ab837323244d04e7"><enum>(2)</enum><header>Contents</header><text>The
			 curriculum established under paragraph (1) may include—</text>
						<subparagraph id="IDfb26e63235744626903578c4026c1006"><enum>(A)</enum><text>role-based
			 security awareness training;</text>
						</subparagraph><subparagraph id="ID4c2580c77f0c4dd686f9675f182beb68"><enum>(B)</enum><text>recommended
			 cybersecurity practices;</text>
						</subparagraph><subparagraph id="ID95d7ebc6d394443fa77fc7f1caef073d"><enum>(C)</enum><text>cybersecurity
			 recommendations for traveling abroad;</text>
						</subparagraph><subparagraph id="ID22f993a333bb4fe58d2875ce0d2ea5a8"><enum>(D)</enum><text>unclassified
			 counterintelligence information;</text>
						</subparagraph><subparagraph id="IDc0bb9acc7e6c425098d39e63d3ea9678"><enum>(E)</enum><text>information
			 regarding industrial espionage;</text>
						</subparagraph><subparagraph id="IDb3b60e3b9d0641fe87dc7fda57e85630"><enum>(F)</enum><text>information
			 regarding malicious activity online;</text>
						</subparagraph><subparagraph id="IDea74c55e3afb4924a8e1f57d94f91ebb"><enum>(G)</enum><text>information
			 regarding cybersecurity and law enforcement;</text>
						</subparagraph><subparagraph id="ID9ac5ea2a018a42c7b608e054886e923c"><enum>(H)</enum><text>identity
			 management information;</text>
						</subparagraph><subparagraph id="ID99b17a206f394fd5b0620e3d9cd3b5a9"><enum>(I)</enum><text>information
			 regarding supply chain security;</text>
						</subparagraph><subparagraph id="IDbf1a2b36e09d46ee8ade26f81ea75b3c"><enum>(J)</enum><text>information
			 security risks associated with the activities of Federal employees; and</text>
						</subparagraph><subparagraph id="IDda32081f6a354cd697baf0e7ebb57d32"><enum>(K)</enum><text>the
			 responsibilities of Federal employees in complying with policies and procedures
			 designed to reduce information security risks identified under subparagraph
			 (J).</text>
						</subparagraph></paragraph><paragraph id="ID294534f00a1e4a9f83f3f208947f41b4"><enum>(3)</enum><header>Federal
			 cybersecurity professionals</header><text>The Director of the Office of
			 Personnel Management in conjunction with the Director of the National Center
			 for Cybersecurity and Communications, the Director of National Intelligence,
			 the Secretary of Defense, the Director of the Office of Management and Budget,
			 and, as appropriate, colleges, universities, and nonprofit organizations with
			 cybersecurity training expertise, shall develop a program, to provide training
			 to improve and enhance the skills and capabilities of Federal employees engaged
			 in the cybersecurity mission, including training specific to the acquisition
			 workforce.</text>
					</paragraph><paragraph id="ID5182bb82ea22422ab30d174ce0aa4fe1"><enum>(4)</enum><header>Heads of
			 Federal agencies</header><text>Not later than 30 days after the date on which
			 an individual is appointed to a position at level I or II of the Executive
			 Schedule, the Director of the National Center for Cybersecurity and
			 Communications and the Director of National Intelligence, or their designees,
			 shall provide that individual with a cybersecurity threat briefing.</text>
					</paragraph><paragraph id="ID6e0406d77382479f8a2c649fd7ec6b4b"><enum>(5)</enum><header>Certification</header><text>The
			 head of each Federal agency shall include in the annual report required under
			 section 3553(c) of title 44, United States Code, a certification regarding
			 whether all officers, employees, and contractors of the Federal agency have
			 completed the training required under this subsection.</text>
					</paragraph></subsection><subsection id="ID18d83989ec524b98b4c7fc99870877ac"><enum>(b)</enum><header>Education</header>
					<paragraph id="IDef3ecef3151d450682eb1709d5dc9a7a"><enum>(1)</enum><header>Federal
			 employees</header><text>The Director of the Office of Personnel Management, in
			 coordination with the Secretary of Education, the Director of the National
			 Science Foundation, and the Director, shall develop and implement a strategy to
			 provide Federal employees who work in cybersecurity missions with the
			 opportunity to obtain additional education.</text>
					</paragraph><paragraph id="ID8e2cf331f1f54697be57ad41acd0f602"><enum>(2)</enum><header>K through
			 12</header><text>The Secretary of Education, in coordination with the Director
			 of the National Center for Cybersecurity and Communications and State and local
			 governments, shall develop curriculum standards, guidelines, and recommended
			 courses to address cyber safety, cybersecurity, and cyber ethics for students
			 in kindergarten through grade 12.</text>
					</paragraph><paragraph id="IDb8f1bf8461a0421d8e05dcab8b114654"><enum>(3)</enum><header>Undergraduate,
			 graduate, vocational, and technical institutions</header>
						<subparagraph id="ID55d56260feb04eb3a990dee64849593a"><enum>(A)</enum><header>Secretary of
			 education</header><text>The Secretary of Education, in coordination with the
			 Director of the National Center for Cybersecurity and Communications,
			 shall—</text>
							<clause id="ID7228dcfa16554d938134fd25f99886c9"><enum>(i)</enum><text>develop
			 curriculum standards and guidelines to address cyber safety, cybersecurity, and
			 cyber ethics for all students enrolled in undergraduate, graduate, vocational,
			 and technical institutions in the United States; and</text>
							</clause><clause id="IDec3a7a2a68664ebc93857b4a3deed5da"><enum>(ii)</enum><text>analyze and
			 develop recommended courses for students interested in pursuing careers in
			 information technology, communications, computer science, engineering, math,
			 and science, as those subjects relate to cybersecurity.</text>
							</clause></subparagraph><subparagraph id="IDe22a1dbb290745a4a54ee0fc37611acd"><enum>(B)</enum><header>Office of
			 personnel management</header><text>The Director of the Office of Personnel
			 Management, in coordination with the Director, shall develop strategies and
			 programs—</text>
							<clause id="ID6585fd7f265c4f4cbd19be27c9844199"><enum>(i)</enum><text>to
			 recruit students from undergraduate, graduate, vocational, and technical
			 institutions in the United States to serve as Federal employees engaged in
			 cyber missions; and</text>
							</clause><clause id="IDba040702711b4ca68287ee1932a7c675"><enum>(ii)</enum><text>that provide
			 internship and part-time work opportunities with the Federal Government for
			 students at the undergraduate, graduate, vocational, and technical institutions
			 in the United States.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="ID0c7a420fc4c246dd962a61fe30440f42"><enum>(c)</enum><header>Cyber talent
			 competitions and challenges</header>
					<paragraph id="ID6f27fc4fee964b51b9aad174980a5e2a"><enum>(1)</enum><header>In
			 general</header><text>The Director of the National Center for Cybersecurity and
			 Communications shall establish a program to ensure the effective operation of
			 national and statewide competitions and challenges that seek to identify,
			 develop, and recruit talented individuals to work in Federal agencies, State
			 and local government agencies, and the private sector to perform duties
			 relating to the security of the Federal information infrastructure or the
			 national information infrastructure.</text>
					</paragraph><paragraph id="ID8708eec31fb4465f95eba8024cd7a417"><enum>(2)</enum><header>Groups and
			 individuals</header><text>The program under this subsection shall
			 include—</text>
						<subparagraph id="ID1668185c027045a5abd86dc6649f8e5a"><enum>(A)</enum><text>high school
			 students;</text>
						</subparagraph><subparagraph id="ID8c6f101c29774583b3b16d156758417f"><enum>(B)</enum><text>undergraduate
			 students;</text>
						</subparagraph><subparagraph id="ID5bc395ec3f774575871f3d088565536b"><enum>(C)</enum><text>graduate
			 students;</text>
						</subparagraph><subparagraph id="ID89a5516820354e26abcacf8f30d5363a"><enum>(D)</enum><text>academic and
			 research institutions;</text>
						</subparagraph><subparagraph id="ID1a5f11f4d12e4dc4b5f0e9886c64d601"><enum>(E)</enum><text>veterans;
			 and</text>
						</subparagraph><subparagraph id="id54DB4AE368FB453994C033011EC99662"><enum>(F)</enum><text>other groups or
			 individuals as the Director may determine.</text>
						</subparagraph></paragraph><paragraph id="IDe5f06b0b9ff84642b74e008ff0465a9d"><enum>(3)</enum><header>Support of
			 other competitions and challenges</header><text>The program under this
			 subsection may support other competitions and challenges not established under
			 this subsection through affiliation and cooperative agreements with—</text>
						<subparagraph id="idFF1A21761DDE45748B55E4AA2FA7B511"><enum>(A)</enum><text>Federal
			 agencies;</text>
						</subparagraph><subparagraph id="idE28D361F488F459AA5889B74D6A7F7B5"><enum>(B)</enum><text>regional, State,
			 or community school programs supporting the development of cyber professionals;
			 or</text>
						</subparagraph><subparagraph id="idA4C862FA1A8749E7958243746C3619F1"><enum>(C)</enum><text>other private
			 sector organizations.</text>
						</subparagraph></paragraph><paragraph id="ID5bdd110da196443e89a77b216adff849"><enum>(4)</enum><header>Areas of
			 talent</header><text>The program under this subsection shall seek to identify,
			 develop, and recruit exceptional talent relating to—</text>
						<subparagraph id="IDeb0bbae1b5dd49fbbe602cd6ee9983c6"><enum>(A)</enum><text>ethical
			 hacking;</text>
						</subparagraph><subparagraph id="ID85168d5ca37d4b04b09aa080577f0e80"><enum>(B)</enum><text>penetration
			 testing;</text>
						</subparagraph><subparagraph id="ID584df3ba90fe45648e404a965d3451f7"><enum>(C)</enum><text>vulnerability
			 assessment;</text>
						</subparagraph><subparagraph id="IDf5857fcaf58e46a8a45b8a5b3942ab2d"><enum>(D)</enum><text>continuity of
			 system operations;</text>
						</subparagraph><subparagraph id="ID695bc93e858f4537aca7a397fdf36d16"><enum>(E)</enum><text>cyber forensics;
			 and</text>
						</subparagraph><subparagraph id="ID68f25abe90914354843ce2890d011e13"><enum>(F)</enum><text>offensive and
			 defensive cyber operations.</text>
						</subparagraph></paragraph></subsection></section><section id="IDc32ea0eb8e1d4438abec09ef41835570"><enum>407.</enum><header>Cybersecurity
			 incentives</header>
				<subsection id="ID4de72e969f15411f8a357ac9df2999cf"><enum>(a)</enum><header>Awards</header><text>In
			 making cash awards under chapter 45 of title 5, United States Code, the
			 President or the head of a Federal agency, in consultation with the Director,
			 shall consider the success of an employee in fulfilling the objectives of the
			 National Strategy, in a manner consistent with any policies, guidelines,
			 procedures, instructions, or standards established by the President.</text>
				</subsection><subsection id="IDdfdeb947f5674a04857867f89f90707e"><enum>(b)</enum><header>Other
			 incentives</header><text>The head of each Federal agency shall adopt best
			 practices, developed by the Director of the National Center for Cybersecurity
			 and Communications and the Office of Management and Budget, regarding effective
			 ways to educate and motivate employees of the Federal Government to demonstrate
			 leadership in cybersecurity, including—</text>
					<paragraph id="ID5cbd2decdfec46618e0520de79fec127"><enum>(1)</enum><text>promotions and
			 other nonmonetary awards; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID07d9e763ea7644bea127f1acc085e66f"><enum>(2)</enum><text>publicizing
			 information sharing accomplishments by individual employees and, if
			 appropriate, the tangible benefits that resulted.</text>
					</paragraph></subsection></section><section id="ID12ffe66f0c774e17916ead94399dacfc"><enum>408.</enum><header>Recruitment
			 and retention program for the National Center for Cybersecurity and
			 Communications</header>
				<subsection id="id23FFFD8B815B4858887BA773458F4BE7"><enum>(a)</enum><header>Definitions</header><text>In
			 this section:</text>
					<paragraph id="idCB31CB798A6844F8A26A2A3CFC7182FC"><enum>(1)</enum><header>Center</header><text>The
			 term <term>Center</term> means the National Center for Cybersecurity and
			 Communications.</text>
					</paragraph><paragraph id="id47CE3C98349140C086C8F96017968F20"><enum>(2)</enum><header>Department</header><text>The
			 term <term>Department</term> means the Department of Homeland Security.</text>
					</paragraph><paragraph id="idC68A62198C1846C696F7C0DDA2072069"><enum>(3)</enum><header>Director</header><text>The
			 term <term>Director</term> means the Director of the Center.</text>
					</paragraph><paragraph id="id06B58ECAB3F04151A2410A6ABF13815B"><enum>(4)</enum><header>Entry level
			 position</header><text>The term <term>entry level position</term> means a
			 position that—</text>
						<subparagraph id="id3D51E1DA164B40748BA6628C80DDD66F"><enum>(A)</enum><text>is established by
			 the Director in the Center; and</text>
						</subparagraph><subparagraph id="id83BEE3C360EE4FDDBD6BF84B12859E14"><enum>(B)</enum><text>is classified at
			 GS–7, GS–8, or GS–9 of the General Schedule.</text>
						</subparagraph></paragraph><paragraph id="idC6F4E847074F4846AC8F9710912E87FA"><enum>(5)</enum><header>Secretary</header><text>The
			 term <term>Secretary</term> means the Secretary of Homeland Security.</text>
					</paragraph><paragraph id="idFFC9811AD9184E2C9DF5037C5659DB59"><enum>(6)</enum><header>Senior
			 position</header><text>The term <term>senior position</term> means a position
			 that—</text>
						<subparagraph id="idECE02F10622341C38B4C4BD7FD4EEC8B"><enum>(A)</enum><text>is established by
			 the Director in the Center; and</text>
						</subparagraph><subparagraph id="idDCAC8B67D8E247EE97E3B76D6E004E0B"><enum>(B)</enum><text>is not
			 established under section 5108 of title 5, United States Code, but is similar
			 in duties and responsibilities for positions established under that
			 section.</text>
						</subparagraph></paragraph></subsection><subsection id="IDf91919f4567944a7901d8053909a7a79"><enum>(b)</enum><header>Recruitment and
			 retention program</header>
					<paragraph id="id30B8A62E1C1547929EC1464C318C57F0"><enum>(1)</enum><header>Establishment</header><text>The
			 Director may establish a program to assist in the recruitment and retention of
			 highly skilled personnel to carry out the functions of the Center.</text>
					</paragraph><paragraph id="idE0DCD5763DD545B4913870829D4CE929"><enum>(2)</enum><header>Consultation
			 and considerations</header><text>In establishing a program under this section,
			 the Director shall—</text>
						<subparagraph id="id1983A7F59210456EB610527901953E2A"><enum>(A)</enum><text>consult with the
			 Secretary; and</text>
						</subparagraph><subparagraph id="idD11AEF352D4D4E65BA7C474F47DB474D"><enum>(B)</enum><text>consider—</text>
							<clause id="id9E5711D601F547B09A3716D41ABC07BC"><enum>(i)</enum><text>national and
			 local employment trends;</text>
							</clause><clause id="id40F205B00FC54FD8BB54DF3D78881E9C"><enum>(ii)</enum><text>the availability
			 and quality of candidates;</text>
							</clause><clause id="idEC73BBBC676E43E9839A7A4DB4B1069F"><enum>(iii)</enum><text>any specialized
			 education or certifications required for positions;</text>
							</clause><clause id="idDA32A764BAD74905ABA2EDDD12262AF9"><enum>(iv)</enum><text>whether there is
			 a shortage of certain skills; and</text>
							</clause><clause id="id50E2849A8BAD4B57BD22A29EA0D2391C"><enum>(v)</enum><text>such other
			 factors as the Director determines appropriate.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="idA16FE2451A9D4305A8ABA55A0AB53347"><enum>(c)</enum><header>Hiring and
			 special pay authorities</header>
					<paragraph id="idD0A59EEE0D4440D1B0449E6BA30E69E3"><enum>(1)</enum><header>Direct hire
			 authority</header><text>Without regard to the civil service laws (other than
			 sections 3303 and 3328 of title 5, United States Code), the Director may
			 appoint not more than 500 employees under this subsection to carry out the
			 functions of the Center.</text>
					</paragraph><paragraph id="id63B31D5760BE477ABAE0419BA25610EC"><enum>(2)</enum><header>Rates of
			 pay</header>
						<subparagraph id="id80F97B3266154134A466DBE3612198DC"><enum>(A)</enum><header>Entry level
			 positions</header><text>The Director may fix the pay of the employees appointed
			 to entry level positions under this subsection without regard to chapter 51 and
			 subchapter III of chapter 53 of title 5, United States Code, relating to
			 classification of positions and General Schedule pay rates, except that the
			 rate of pay for any such employee may not exceed the maximum rate of basic pay
			 payable for a position at GS–10 of the General Schedule while that employee is
			 in an entry level position.</text>
						</subparagraph><subparagraph id="ID73d2aba3c78a465cb948b0d760b711a3"><enum>(B)</enum><header>Senior
			 positions</header>
							<clause id="ID6bc3c828771140fcbcc7cc160a217b6f"><enum>(i)</enum><header>In
			 general</header><text>The Director may fix the pay of the employees appointed
			 to senior positions under this subsection without regard to chapter 51 and
			 subchapter III of chapter 53 of title 5, United States Code, relating to
			 classification of positions and General Schedule pay rates, except that the
			 rate of pay for any such employee may not exceed the maximum rate of basic pay
			 payable under section 5376 of title 5, United States Code.</text>
							</clause><clause id="IDfe9077e1618a4af3bf897984bfbcb32a"><enum>(ii)</enum><header>Higher maximum
			 rates</header>
								<subclause id="id69B970A8AEA94825934AA3CBCA492A63"><enum>(I)</enum><header>In
			 general</header><text>Notwithstanding the limitation on rates of pay under
			 clause (i)—</text>
									<item id="ID422e1d69fb764a11b8299234dba8335e"><enum>(aa)</enum><text>not
			 more than 20 employees, identified by the Director, may be paid at a rate of
			 pay not to exceed the maximum rate of basic pay payable for a position at level
			 I of the Executive Schedule under section 5312 of title 5, United States Code;
			 and</text>
									</item><item id="IDd517917af15843268bcf736338ffa19c"><enum>(bb)</enum><text>not
			 more than 5 employees, identified by the Director with the approval of the
			 Secretary, may be paid at a rate of pay not to exceed the maximum rate of basic
			 pay payable for the Vice President under section 104 of title 3, United States
			 Code.</text>
									</item></subclause><subclause id="idBF18B6BDF00B46EF9D79C59E2C22C9B7"><enum>(II)</enum><header>Nondelegation
			 of authority</header><text>The Secretary or the Director may not delegate any
			 authority under this clause.</text>
								</subclause></clause></subparagraph></paragraph></subsection><subsection id="ID84bec3072f244e228c21cb42ce010c2f"><enum>(d)</enum><header>Conversion to
			 Competitive Service</header>
					<paragraph id="id6BB9CC6DAD804EA18DB6AD29F76B27A0"><enum>(1)</enum><header>Definition</header><text>In
			 this subsection, the term <term>qualified employee</term> means any individual
			 appointed to an excepted service position in the Department who performs
			 functions relating to the security of the Federal information infrastructure or
			 national information infrastructure.</text>
					</paragraph><paragraph id="id108A9180A6744968B42ADDC01E7E5FB5"><enum>(2)</enum><header>Competitive
			 civil service status</header><text>In consultation with the Director, the
			 Secretary may grant competitive civil service status to a qualified employee if
			 that employee is—</text>
						<subparagraph id="idBD34E97B857C42D9B85447819A0FBF06"><enum>(A)</enum><text>employed in the
			 Center; or</text>
						</subparagraph><subparagraph id="idAF5644449F584785887FB91EDAE899F5"><enum>(B)</enum><text>transferring to
			 the Center.</text>
						</subparagraph></paragraph></subsection><subsection id="IDf70a9d9e3ed84f7c80f483166dff7616"><enum>(e)</enum><header>Retention
			 Bonuses</header>
					<paragraph id="id6F3F34497E5A47149F891C34ECE0340D"><enum>(1)</enum><header>Authority</header><text>Notwithstanding
			 section 5754 of title 5, United States Code, the Director may—</text>
						<subparagraph id="id07ECFD248FFA43B1BA66166D0D58F4DD"><enum>(A)</enum><text>pay a retention
			 bonus under that section to any individual appointed under this subsection, if
			 the Director determines that, in the absence of a retention bonus, there is a
			 high risk that the individual would likely leave employment with the
			 Department; and</text>
						</subparagraph><subparagraph id="idB9996BE32159447EB50BCF0DDDC76738"><enum>(B)</enum><text>exercise the
			 authorities of the Office of Personnel Management and the head of an agency
			 under that section with respect to retention bonuses paid under this
			 subsection.</text>
						</subparagraph></paragraph><paragraph id="id8B81B7E20C5C4B2EB924DC31BE59AABF"><enum>(2)</enum><header>Limitations on
			 amount of annual bonuses</header>
						<subparagraph id="id7BA9A8F0497642ADA07518849A25B6FB"><enum>(A)</enum><header>Definitions</header><text>In
			 this paragraph:</text>
							<clause id="id3367F410911D4364AE919C099BF8990B"><enum>(i)</enum><header>Maximum total
			 pay</header><text>The term <term>maximum total pay</term> means—</text>
								<subclause id="id7210055D0E944C92BCA832896E3EC4BC"><enum>(I)</enum><text>in the case of an
			 employee described under subsection (c)(2)(B)(i), the total amount of pay paid
			 in a calendar year at the maximum rate of basic pay payable for a position at
			 level I of the Executive Schedule under section 5312 of title 5, United States
			 Code;</text>
								</subclause><subclause id="idC0F36B0CA19348F9B80C01966800EE0B"><enum>(II)</enum><text>in the case of
			 an employee described under subsection (c)(2)(B)(ii)(I)(aa), the total amount
			 of pay paid in a calendar year at the maximum rate of basic pay payable for a
			 position at level I of the Executive Schedule under section 5312 of title 5,
			 United States Code; and</text>
								</subclause><subclause id="idFB4E5C94B6824D06ADC911BA80253477"><enum>(III)</enum><text>in the case of
			 an employee described under subsection (c)(2)(B)(ii)(I)(bb), the total amount
			 of pay paid in a calendar year at the maximum rate of basic pay payable for the
			 Vice President under section 104 of title 3, United States Code.</text>
								</subclause></clause><clause id="id27A400855FE2423D8C88577F46622476"><enum>(ii)</enum><header>Total
			 compensation</header><text>The term <term>total compensation</term>
			 means—</text>
								<subclause id="idD489F6E4D92F446C984C589A356288D2"><enum>(I)</enum><text>the amount of pay
			 paid to an employee in any calendar year; and</text>
								</subclause><subclause id="id8827705496244A1598C05F6358F3CADE"><enum>(II)</enum><text>the amount of
			 all retention bonuses paid to an employee in any calendar year.</text>
								</subclause></clause></subparagraph><subparagraph id="id34177C112BB44BBCA497E8370744BD84"><enum>(B)</enum><header>Limitation</header><text>The
			 Director may not pay a retention bonus under this subsection to an employee
			 that would result in the total compensation of that employee exceeding maximum
			 total pay.</text>
						</subparagraph></paragraph></subsection><subsection id="IDbd110fb1745b4ff1b3bbf080ea7ff36d"><enum>(f)</enum><header>Termination of
			 Authority</header><text>The authority to make appointments and pay retention
			 bonuses under this section shall terminate 3 years after the date of enactment
			 of this Act.</text>
				</subsection><subsection id="ID36befb35439444f2b7edac53ce6acee5"><enum>(g)</enum><header>Reports</header>
					<paragraph id="ID10f2c382d3b1418abef2e694df4da42b"><enum>(1)</enum><header>Plan for
			 execution of authorities</header><text>Not later than 120 days after the date
			 of enactment of this Act, the Director shall submit a report to the appropriate
			 committees of Congress with a plan for the execution of the authorities
			 provided under this section.</text>
					</paragraph><paragraph id="ID90e92494da3649248dd349d9efef3603"><enum>(2)</enum><header>Annual
			 report</header><text>Not later than 6 months after the date of enactment of
			 this Act, and every year thereafter, the Director shall submit to the
			 appropriate committees of Congress a detailed report that—</text>
						<subparagraph id="ID86578361054a484c8631422406ed2f3f"><enum>(A)</enum><text>discusses how the
			 actions taken during the period of the report are fulfilling the critical
			 hiring needs of the Center;</text>
						</subparagraph><subparagraph id="ID631544cac9e942faa26ad78836a5c244"><enum>(B)</enum><text>assesses metrics
			 relating to individuals hired under the authority of this section,
			 including—</text>
							<clause id="IDc9cd9e93da2147a68f4f62ab9c0276f2"><enum>(i)</enum><text>the
			 numbers of individuals hired;</text>
							</clause><clause id="ID2960f788a382475c92f594a15c2c441f"><enum>(ii)</enum><text>the turnover in
			 relevant positions;</text>
							</clause><clause id="IDfbe836361ee64cc58a38a784ab3928e1"><enum>(iii)</enum><text>with respect to
			 each individual hired—</text>
								<subclause id="IDe4db734d7b2f45a4804dbdb33106c346"><enum>(I)</enum><text>the position for
			 which hired;</text>
								</subclause><subclause id="ID31737311899f43f78e463110968ac6e1"><enum>(II)</enum><text>the salary
			 paid;</text>
								</subclause><subclause id="IDe7569d52d5b8468899bdc26ce1ebccbb"><enum>(III)</enum><text>any retention
			 bonus paid and the amount of the bonus;</text>
								</subclause><subclause id="ID0e134fcd0d464714894baa60e7567510"><enum>(IV)</enum><text>the geographic
			 location from which hired;</text>
								</subclause><subclause id="ID10a0d4314f054150a7c84e008844591b"><enum>(V)</enum><text>the immediate
			 past salary; and</text>
								</subclause><subclause id="IDe87653f0f3eb47a59b4cb4c30bdfc8b4"><enum>(VI)</enum><text>whether the
			 individual was a noncareer appointee in the Senior Executive Service or an
			 appointee to a position of a confidential or policy-determining character under
			 schedule C of subpart C of part 213 of title 5 of the Code of Federal
			 Regulations before the hiring; and</text>
								</subclause></clause><clause id="ID51e28132a425454b8c5e4bdc09852155"><enum>(iv)</enum><text>whether public
			 notice for recruitment was made, and if so—</text>
								<subclause id="IDe36d28d4d013471ba05ed25c68dbf337"><enum>(I)</enum><text>the total number
			 of qualified applicants;</text>
								</subclause><subclause id="IDe7755f9c40404331a28c4b668e479465"><enum>(II)</enum><text>the number of
			 veteran preference eligible candidates who applied;</text>
								</subclause><subclause id="ID55c833082311444ab379f04dd7843fc7"><enum>(III)</enum><text>the time from
			 posting to job offer; and</text>
								</subclause><subclause id="IDf41a149bd28243cf9e7d830baf87a4f5"><enum>(IV)</enum><text>statistics on
			 diversity, including age, disability, race, gender, and national origin, of
			 individuals hired under the authority of this section to the extent such
			 statistics are available; and</text>
								</subclause></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID2f332d0890f54668a409e78abb1fe049"><enum>(C)</enum><text>includes rates of
			 pay set in accordance with subsection (c).</text>
						</subparagraph></paragraph></subsection></section></title><title id="id72901E10981A4D4996240B88D11E79CA"><enum>V</enum><header>Other
			 provisions</header>
			<section id="ID8341c072a47f4eb68e8739799f60c4fc"><enum>501.</enum><header>Cybersecurity
			 research and development</header><text display-inline="no-display-inline">Subtitle D of title II of the Homeland
			 Security Act of 2002 (6 U.S.C. 161 et seq.) is amended by adding at the end the
			 following:</text>
				<quoted-block display-inline="no-display-inline" id="idDBD4BC1D3A7848E1AFFD7A4B354622C8" style="OLC">
					<section id="ID23bdfb04ec794441a67efbeeea474767"><enum>238.</enum><header>Cybersecurity
				research and development</header>
						<subsection id="ID06fc9254a9f341289558c4523585f82d"><enum>(a)</enum><header>Establishment
				of research and development program</header><text>The Under Secretary for
				Science and Technology, in coordination with the Director of the National
				Center for Cybersecurity and Communications, shall carry out a research and
				development program for the purpose of improving the security of information
				infrastructure.</text>
						</subsection><subsection id="ID02738c86ed5d4cde91d77aceed8eb6da"><enum>(b)</enum><header>Eligible
				projects</header><text>The research and development program carried out under
				subsection (a) may include projects to—</text>
							<paragraph id="ID81d5b36e03a14b8bac5c2adc5b000f64"><enum>(1)</enum><text>advance the
				development and accelerate the deployment of more secure versions of
				fundamental Internet protocols and architectures, including for the secure
				domain name addressing system and routing security;</text>
							</paragraph><paragraph id="IDb60a9def70ec483399aca55f51b49e6c"><enum>(2)</enum><text>improve and
				create technologies for detecting and analyzing attacks or intrusions,
				including analysis of malicious software;</text>
							</paragraph><paragraph id="IDd8743e2264f84f04acc8c7b3beebbcf4"><enum>(3)</enum><text>improve and
				create mitigation and recovery methodologies, including techniques for
				containment of attacks and development of resilient networks and
				systems;</text>
							</paragraph><paragraph id="ID0c85c8bb68204dbea81a0b23aeb0ccd5"><enum>(4)</enum><text>develop and
				support infrastructure and tools to support cybersecurity research and
				development efforts, including modeling, testbeds, and data sets for assessment
				of new cybersecurity technologies;</text>
							</paragraph><paragraph id="ID52f98da747b34b559dbf6615b99ead29"><enum>(5)</enum><text>assist the
				development and support of technologies to reduce vulnerabilities in process
				control systems;</text>
							</paragraph><paragraph id="ID44e41b52520141ab8b3cdf9e8275356e"><enum>(6)</enum><text>understand human
				behavioral factors that can affect cybersecurity technology and
				practices;</text>
							</paragraph><paragraph id="ID10c76ac1da8f4027bbbe70f9d759acc9"><enum>(7)</enum><text>test, evaluate,
				and facilitate, with appropriate protections for any proprietary information
				concerning the technologies, the transfer of technologies associated with the
				engineering of less vulnerable software and securing the information technology
				software development lifecycle;</text>
							</paragraph><paragraph id="IDa8595bbdf3f54884b34097683d0e5468"><enum>(8)</enum><text>assist the
				development of identity management and attribution technologies;</text>
							</paragraph><paragraph id="IDa4180a23f1324fb580fe5c04e1a1ac9c"><enum>(9)</enum><text>assist the
				development of technologies designed to increase the security and resiliency of
				telecommunications networks;</text>
							</paragraph><paragraph id="IDf4ee5e9c9435495b9587e4ad30c2f32d"><enum>(10)</enum><text>advance the
				protection of privacy and civil liberties in cybersecurity technology and
				practices; and</text>
							</paragraph><paragraph id="IDc4faf3e0a39445ac9b8de48d1bff9815"><enum>(11)</enum><text>address other
				risks identified by the Director of the National Center for Cybersecurity and
				Communications.</text>
							</paragraph></subsection><subsection id="ID8f95d324452b40a9bfa0fef652c7e5aa"><enum>(c)</enum><header>Coordination
				with other research initiatives</header><text>The Under Secretary—</text>
							<paragraph id="IDdf131205f09f4a8f9e126a75629c274c"><enum>(1)</enum><text>shall ensure that
				the research and development program carried out under subsection (a) is
				consistent with the national strategy to increase the security and resilience
				of cyberspace developed by the Director of Cyberspace Policy under section 101
				of the <short-title>Cybersecurity and Internet Freedom Act
				of 2011</short-title>, or any succeeding strategy;</text>
							</paragraph><paragraph id="ID907d8ad00b1f44649db30906131af867"><enum>(2)</enum><text>shall, to the
				extent practicable, coordinate the research and development activities of the
				Department with other ongoing research and development security-related
				initiatives, including research being conducted by—</text>
								<subparagraph id="ID51e72beb148946158aebce287b917450"><enum>(A)</enum><text>the National
				Institute of Standards and Technology;</text>
								</subparagraph><subparagraph id="id2CC31728A5C24E90AB48B196B8AC8382"><enum>(B)</enum><text>the National
				Science Foundation;</text>
								</subparagraph><subparagraph id="ID22dffc2a471e482ba7fa9454f9cc68c6"><enum>(C)</enum><text>the National
				Academy of Sciences;</text>
								</subparagraph><subparagraph id="ID97ed197155714c42a89bf711bb652a69"><enum>(D)</enum><text>other Federal
				agencies, as defined under section 241;</text>
								</subparagraph><subparagraph id="IDe93c6fc4cd2c436286e52d1ff4cca8f7"><enum>(E)</enum><text>other Federal and
				private research laboratories, research entities, and universities and
				institutions of higher education, and relevant nonprofit organizations;
				and</text>
								</subparagraph><subparagraph id="ID68010f94ee0b4f9da4200d995c42b4f9"><enum>(F)</enum><text>international
				partners of the United States;</text>
								</subparagraph></paragraph><paragraph id="ID73ade35822ad4993905fb2dcbf6b524b"><enum>(3)</enum><text>shall carry out
				any research and development project under subsection (a) through a
				reimbursable agreement with an appropriate Federal agency, as defined under
				section 241, if the Federal agency—</text>
								<subparagraph id="ID99abb2a83bd84afdb13bf33bb867ff64"><enum>(A)</enum><text>is sponsoring a
				research and development project in a similar area; or</text>
								</subparagraph><subparagraph id="IDd7f2b111eed54e848f585ec6e8f93221"><enum>(B)</enum><text>has a unique
				facility or capability that would be useful in carrying out the project;</text>
								</subparagraph></paragraph><paragraph id="ID0eade9193a2e485690634c305347c5fd"><enum>(4)</enum><text>may make grants
				to, or enter into cooperative agreements, contracts, other transactions, or
				reimbursable agreements with, the entities described in paragraph (2);
				and</text>
							</paragraph><paragraph id="ID8ff3c7711207440e88a263c4ead204df"><enum>(5)</enum><text>shall submit a
				report to the appropriate committees of Congress on a review of the
				cybersecurity activities, and the capacity, of the national laboratories and
				other research entities available to the Department to determine if the
				establishment of a national laboratory dedicated to cybersecurity research and
				development is necessary.</text>
							</paragraph></subsection><subsection id="IDca2fff9e4a874f61b7d0fbfebb0764d2"><enum>(d)</enum><header>Privacy and
				civil rights and civil liberties issues</header>
							<paragraph id="ID8828e3a95f7645ccbdccac20256060c5"><enum>(1)</enum><header>Consultation</header><text>In
				carrying out research and development projects under subsection (a), the Under
				Secretary shall consult with the Privacy Officer appointed under section 222
				and the Officer for Civil Rights and Civil Liberties of the Department
				appointed under section 705.</text>
							</paragraph><paragraph id="ID238b0af235c54a78950ca4d196b7f7e6"><enum>(2)</enum><header>Privacy impact
				assessments</header><text>In accordance with sections 222 and 705, the Privacy
				Officer shall conduct privacy impact assessments and the Officer for Civil
				Rights and Civil Liberties shall conduct reviews, as appropriate, for research
				and development projects carried out under subsection (a) that the Under
				Secretary determines could have an impact on privacy, civil rights, or civil
				liberties.</text>
							</paragraph></subsection></section><section id="IDc4507bc902be44319405267c796e05d9"><enum>239.</enum><header>National
				Cybersecurity Advisory Council</header>
						<subsection id="IDa51cc08b1111482da5ecacdadaa550d8"><enum>(a)</enum><header>Establishment</header><text>Not
				later than 90 days after the date of enactment of this section, the Secretary
				shall establish an advisory committee under section 871 on private sector
				cybersecurity, to be known as the National Cybersecurity Advisory Council (in
				this section referred to as the <quote>Council</quote>).</text>
						</subsection><subsection id="ID3d39cbb77f634dd09a911cdaba5f0fd3"><enum>(b)</enum><header>Responsibilities</header>
							<paragraph id="ID36fc7d2be43c4ef0aec37fbc222afe9e"><enum>(1)</enum><header>In
				general</header><text>The Council shall advise the Director of the National
				Center for Cybersecurity and Communications on the implementation of the
				cybersecurity provisions affecting the private sector under this subtitle and
				subtitle E.</text>
							</paragraph><paragraph id="ID5de312726853494dbdd79739d0bcb409"><enum>(2)</enum><header>Incentives and
				regulations</header><text>The Council shall advise the Director of the National
				Center for Cybersecurity and Communications and appropriate committees of
				Congress (as defined in section 241) and any other congressional committee with
				jurisdiction over the particular matter regarding how market incentives and
				regulations may be implemented to enhance the cybersecurity and economic
				security of the Nation.</text>
							</paragraph></subsection><subsection id="ID1376f3de9a1b4bb3a2f96d580a9d4d8a"><enum>(c)</enum><header>Membership</header>
							<paragraph id="ID074eb95ab3cc4aacb7bfe31e3ebabee0"><enum>(1)</enum><header>In
				general</header><text>The members of the Council shall be appointed the
				Director of the National Center for Cybersecurity and Communications and shall,
				to the extent practicable, represent a geographic and substantive cross-section
				of owners and operators of critical infrastructure and others with expertise in
				cybersecurity, including, as appropriate—</text>
								<subparagraph id="IDf3091f7e94f144e693becfab5c4a29bd"><enum>(A)</enum><text>representatives
				of covered critical infrastructure (as defined under section 241);</text>
								</subparagraph><subparagraph id="ID2a2e2ce9ce4c4e468803c1876fd4332e"><enum>(B)</enum><text>academic
				institutions with expertise in cybersecurity;</text>
								</subparagraph><subparagraph id="ID4b6164cf771743ab998cabebf9f48d53"><enum>(C)</enum><text>Federal, State,
				and local government agencies with expertise in cybersecurity;</text>
								</subparagraph><subparagraph id="ID2763987553824d5188dc5c2e17fc7a21"><enum>(D)</enum><text>a representative
				of the National Security Telecommunications Advisory Council, as established by
				Executive Order 12382 (47 Fed. Reg. 40531; relating to the establishment of the
				advisory council), as amended by Executive Order 13286 (68 Fed. Reg. 10619), as
				in effect on August 3, 2009, or any successor entity;</text>
								</subparagraph><subparagraph id="ID3b65dcd62ffe4922b6b60e2034382988"><enum>(E)</enum><text>a representative
				of the Communications Sector Coordinating Council, or any successor
				entity;</text>
								</subparagraph><subparagraph id="ID6b4e0f1434db4fd5a6c8dec422770610"><enum>(F)</enum><text>a representative
				of the Information Technology Sector Coordinating Council, or any successor
				entity;</text>
								</subparagraph><subparagraph id="ID2c8acfda35004f9392bc0ccca314a848"><enum>(G)</enum><text>individuals,
				acting in their personal capacity, with demonstrated technical expertise in
				cybersecurity; and</text>
								</subparagraph><subparagraph id="ID804e943dc3e04b8a863692e305966be8"><enum>(H)</enum><text>such other
				individuals as the Director determines to be appropriate, including owners of
				small business concerns (as defined under section 3 of the Small Business Act
				(15 U.S.C. 632)).</text>
								</subparagraph></paragraph><paragraph id="id4CAFF6B7298D4DC1A044CA418E4A8376"><enum>(2)</enum><header>Term</header><text>The
				members of the Council shall be appointed for 2 year terms and may be appointed
				to consecutive terms.</text>
							</paragraph><paragraph id="ID88e636ce7ec040a69ed5fc61a214341b"><enum>(3)</enum><header>Leadership</header><text>The
				Chairperson and Vice-Chairperson of the Council shall be selected by members of
				the Council from among the members of the Council and shall serve 2-year
				terms.</text>
							</paragraph></subsection><subsection id="ID49a58fcdbbd840ab9be7d4e168f455ac"><enum>(d)</enum><header>Applicability
				of Federal Advisory Committee Act</header><text>The Federal Advisory Committee
				Act (5 U.S.C. App.) shall not apply to the
				Council.</text>
						</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</section><section id="IDb051d2fdb28844a09118be8409f42b36"><enum>502.</enum><header>Prioritized
			 critical information infrastructure</header>
				<subsection id="id31BEC778D6B641AB9301FEA90D0B0130"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Section 210E(a)(2) of
			 the Homeland Security Act of 2002 (6 U.S.C. 124l(a)(2)) is amended—</text>
					<paragraph id="ID619308cbbf2e441d8d9d6b55476aa8f1"><enum>(1)</enum><text>by striking
			 <quote>In accordance</quote> and inserting the following:</text>
						<quoted-block display-inline="no-display-inline" id="idE58F347C19424D5CBC00BB1C4EA781E2" style="OLC">
							<subparagraph id="ID20d50032a54f4343b4ac75f9f364413d"><enum>(A)</enum><header>In
				general</header><text>In accordance</text>
							</subparagraph><after-quoted-block>;
				and</after-quoted-block></quoted-block>
					</paragraph><paragraph id="ID4e71118384d141a59ad3813c0899ae69"><enum>(2)</enum><text>by adding at the
			 end the following:</text>
						<quoted-block display-inline="no-display-inline" id="id43AE7727B93D48D38AB64D4026BA820D" style="OLC">
							<subparagraph id="IDd905266de7574265841d4b699c4dc50d"><enum>(B)</enum><header>Considerations</header><text>In
				establishing and maintaining a list under subparagraph (A), the Secretary, in
				coordination with the Director of the National Center for Cybersecurity and
				Communications, shall consider cyber risks and consequences by sector,
				including—</text>
								<clause id="ID73b190164b114820b7084c5e0cdb147e"><enum>(i)</enum><text>the factors
				listed in section 248(a)(2);</text>
								</clause><clause id="ID6db6512de8fb4b1b849693e2904c3a1f"><enum>(ii)</enum><text>interdependencies
				between components of covered critical infrastructure (as defined under section
				241); and</text>
								</clause><clause id="ID05d300e5259b4708895019eed3cc270b"><enum>(iii)</enum><text>the potential
				for the destruction or disruption of the system or asset to cause—</text>
									<subclause id="IDd42e87bd76424cdba073104a1c980836"><enum>(I)</enum><text>a mass casualty
				event which includes an extraordinary number of fatalities;</text>
									</subclause><subclause id="IDc3863b9c57ed4877adbad2a69444f9f0"><enum>(II)</enum><text>severe economic
				consequences;</text>
									</subclause><subclause id="ID014b71c06ba2404888a769d3c2cd743e"><enum>(III)</enum><text>mass
				evacuations with a prolonged absence; or</text>
									</subclause><subclause id="ID68760a23b67c48488cb9107f1ff47efb"><enum>(IV)</enum><text>severe
				degradation of national security capabilities, including intelligence and
				defense
				functions.</text>
									</subclause></clause></subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection commented="no" id="ID9fc36cf6771c4a83bce20014fe92d0a8"><enum>(b)</enum><header>Covered
			 critical infrastructure</header><text>Title II of the Homeland Security Act of
			 2002 (6 U.S.C. 121 et seq.) (as amended by section 201 of this Act) is further
			 amended by adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="idC2CC650FB7C840B0812830593E6AFF40" style="OLC">
						<section commented="no" id="ID5971a9e03fa146caa35fb5f74675d56a"><enum>254.</enum><header>Covered
				critical infrastructure</header>
							<subsection commented="no" id="ID95c8c31645944afda761598d4cf8e81d"><enum>(a)</enum><header>Identification
				of covered critical infrastructure</header>
								<paragraph commented="no" id="IDb0f887b063aa4c5b85165913becb29e6"><enum>(1)</enum><header>In
				general</header><text>Subject to paragraphs (2) and (3), the Secretary, in
				coordination with sector-specific agencies and in consultation with the
				National Cybersecurity Advisory Council and other appropriate representatives
				of State and local governments and the private sector, shall establish and
				maintain a list of systems or assets that constitute covered critical
				infrastructure for purposes of this subtitle.</text>
								</paragraph><paragraph commented="no" id="ID7ac179597c6340b6a97ca4a82544e6c9"><enum>(2)</enum><header>Requirements</header>
									<subparagraph commented="no" id="idAEA1788ED00540C4B4B6B171DE82035F"><enum>(A)</enum><header>In
				general</header><text>A system or asset may not be identified as covered
				critical infrastructure under this section unless such system or asset meets
				each of the requirements under subparagraph (B) (i), (ii), and (iii).</text>
									</subparagraph><subparagraph commented="no" id="idE590996C419A4DA4A07A90BBB12410CB"><enum>(B)</enum><header>Requirements</header><text>The
				requirements referred to under subparagraph (A) are that—</text>
										<clause commented="no" id="ID87849b8a381a4288859389fa933cb700"><enum>(i)</enum><text>the destruction
				or the disruption of the reliable operation of the system or asset would cause
				national or regional catastrophic effects identified under section
				210E(a)(2)(B)(iii);</text>
										</clause><clause commented="no" id="IDe308c469fc16433eaf397859d6dab01d"><enum>(ii)</enum><text>the system or
				asset is on the prioritized critical infrastructure list established by the
				Secretary under section 210E(a)(2); and</text>
										</clause><clause commented="no" id="ID26e4cad62a584e54a70f7ece40ce7372"><enum>(iii)</enum><subclause commented="no" display-inline="yes-display-inline" id="id7CDAC4BC73034AEEAC5C8757DCDE9FFC"><enum>(I)</enum><text>the system or asset is
				a component of the national information infrastructure; or</text>
											</subclause><subclause commented="no" id="IDfa207c6b8c9a46b89a373f96918855cd" indent="up1"><enum>(II)</enum><text>the national information infrastructure
				is essential to the reliable operation of the system or asset.</text>
											</subclause></clause></subparagraph></paragraph><paragraph commented="no" id="ID8e1f893e0bf141aabbc7c304f7084f70"><enum>(3)</enum><header>Limitation</header><text>A
				system or asset may not be identified as covered critical infrastructure under
				this section based solely on activities protected by the first amendment to the
				United States Constitution.</text>
								</paragraph></subsection><subsection commented="no" id="id47DDD864241845039FAD98563FA03702"><enum>(b)</enum><header>Notification</header>
								<paragraph commented="no" id="idE394179187CA4B0DB985807A2766F956"><enum>(1)</enum><header>Identification
				of system or asset</header><text>If the Secretary identifies any system or
				asset as covered critical infrastructure under subsection (a), the Secretary
				shall promptly notify the owner or operator of that system or asset of that
				identification.</text>
								</paragraph><paragraph commented="no" id="id2FADA6AC2B25484297EAB41A32BD603F"><enum>(2)</enum><header>System or asset
				no longer covered critical infrastructure</header><text>If the Secretary
				determines that any system or asset that was identified as covered critical
				infrastructure under subsection (a) no longer constitutes covered critical
				infrastructure, the Secretary shall promptly notify the owner or operator of
				that system or asset of that determination.</text>
								</paragraph></subsection><subsection commented="no" id="ID88ef3c15cfb441898690ebbe4ff0fd8e"><enum>(c)</enum><header>Redress</header>
								<paragraph commented="no" id="ID8254e88f53ee479a824a8cf898415e2a"><enum>(1)</enum><header>In
				general</header><text>Subject to paragraphs (2) and (3), the Secretary shall
				develop a mechanism, consistent with subchapter II of chapter 5 of title 5,
				United States Code, for an owner or operator notified under subsection (b)(1)
				to appeal the identification of a system or asset as covered critical
				infrastructure under this section.</text>
								</paragraph><paragraph id="ID4a118cf6e8c9494bb16ea162df659c14"><enum>(2)</enum><header>Appeal to
				Federal court</header><text>A civil action seeking judicial review of a final
				agency action taken under the mechanism developed under paragraph (1) shall be
				filed in the United States District Court for the District of Columbia.</text>
								</paragraph><paragraph commented="no" id="ID8410a0e58de54aa7b923c59d4dd2e0bb"><enum>(3)</enum><header>Compliance</header><text>The
				owner or operator of a system or asset identified as covered critical
				infrastructure shall comply with any requirement of this subtitle relating to
				covered critical infrastructure until such time as the system or asset is no
				longer identified as covered critical infrastructure, based on—</text>
									<subparagraph commented="no" id="id028BEC38979640C184F812C832748791"><enum>(A)</enum><text>an appeal under
				paragraph (1);</text>
									</subparagraph><subparagraph commented="no" id="id9ADA6E1FD602429193FAE3EE021334FF"><enum>(B)</enum><text>a determination
				of the Secretary unrelated to an appeal; or</text>
									</subparagraph><subparagraph commented="no" id="idEE4F42CD721C408481D2CA0908D70F81"><enum>(C)</enum><text>a final judgment
				entered in a civil action seeking judicial review brought in accordance with
				paragraph (2).</text>
									</subparagraph></paragraph></subsection><subsection commented="no" id="ID6cba5ecbba054c43b38a1df240f4648b"><enum>(d)</enum><header>Addition of
				systems or assets</header>
								<paragraph commented="no" id="id78F232A39A694992BEFA123CBEAB1D82"><enum>(1)</enum><header>In
				general</header><text>The Secretary shall develop a process under which any
				owner or operator of a system or asset that may constitute covered critical
				infrastructure may—</text>
									<subparagraph commented="no" id="idA655267833A4433798AC0BDB58C21EC6"><enum>(A)</enum><text>request that such
				system or asset be identified by the Secretary as covered critical
				infrastructure under this section; and</text>
									</subparagraph><subparagraph commented="no" id="id96637C4281CD45BAA8835B51CE289257"><enum>(B)</enum><text>submit material
				supporting such a request to the Director of the Center for consideration by
				the Secretary in carrying out this section.</text>
									</subparagraph></paragraph><paragraph commented="no" id="idD4F43F65C3A84F979BB2A14B9851B908"><enum>(2)</enum><header>Final
				decision</header><text>A decision to identify any system or asset as covered
				critical infrastructure based on a request submitted under this
				subsection—</text>
									<subparagraph commented="no" id="idC05F4FA0BE34427398CD9145E6D35E96"><enum>(A)</enum><text>is committed to
				the sole, unreviewable discretion of the Secretary; and</text>
									</subparagraph><subparagraph commented="no" id="id9167EB2840364302934BFD171E9FB42A"><enum>(B)</enum><text>shall not be
				subject to—</text>
										<clause commented="no" id="idE778157EA07C4C50BC3B3E4EBD00A008"><enum>(i)</enum><text>an appeal under
				subsection (c); or</text>
										</clause><clause commented="no" id="id13652EE3328B4858AC1066BEA21D88F5"><enum>(ii)</enum><text>judicial
				review.</text>
										</clause></subparagraph></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection></section><section id="ID8dee57d503054ddcad53cf59054e804c"><enum>503.</enum><header>National
			 Center for Cybersecurity and Communications acquisition authorities</header>
				<subsection id="ID8d28a8d3b3bd49bca9714d0310104ba5"><enum>(a)</enum><header>In
			 general</header><text>The National Center for Cybersecurity and Communications
			 is authorized to use the authorities under subsections (c)(1) and (d)(1)(B) of
			 section 2304 of title 10, United States Code, instead of the authorities under
			 subsections (a)(1) and (b)(2) of section 3304 of title 41, United States Code,
			 subject to all other requirements of sections 3301 and 3304 of title 41, United
			 States Code.</text>
				</subsection><subsection id="IDb36031683c794e1fa4f7db7893808a9d"><enum>(b)</enum><header>Guidelines</header><text>Not
			 later than 90 days after the date of enactment of this Act, the chief
			 procurement officer of the Department of Homeland Security shall issue
			 guidelines for use of the authority under subsection (a).</text>
				</subsection><subsection id="ID18fe32fec4e9456cb72869c42f26eb39"><enum>(c)</enum><header>Termination</header><text>The
			 National Center for Cybersecurity and Communications may not use the authority
			 under subsection (a) on and after the date that is 3 years after the date of
			 enactment of this Act.</text>
				</subsection><subsection id="IDf58eb36c684c47d580b7444ac6e27d6b"><enum>(d)</enum><header>Reporting</header>
					<paragraph id="id7A68E2F7A5894CC6B1543A226CFF11E8"><enum>(1)</enum><header>In
			 general</header><text>On a semiannual basis, the Director of the National
			 Center for Cybersecurity and Communications shall submit a report on use of the
			 authority granted by subsection (a) to—</text>
						<subparagraph id="id228104CC1C254261B25D877EC45FAC76"><enum>(A)</enum><text>the Committee on
			 Homeland Security and Governmental Affairs of the Senate; and</text>
						</subparagraph><subparagraph id="id6BF6F047D324411AA639E35C8E395407"><enum>(B)</enum><text>the Committee on
			 Homeland Security of the House of Representatives.</text>
						</subparagraph></paragraph><paragraph id="idEADF5E92148841FA89420F2D83E2221F"><enum>(2)</enum><header>Contents</header><text>Each
			 report submitted under paragraph (1) shall include, at a minimum—</text>
						<subparagraph id="ID526e53cd080c4e1ba39334d0383a4590"><enum>(A)</enum><text>the number of
			 contract actions taken under the authority under subsection (a) during the
			 period covered by the report; and</text>
						</subparagraph><subparagraph id="IDbd8afab4c01d4a52a876ecf20eb6e504"><enum>(B)</enum><text>for each contract
			 action described in subparagraph (A)—</text>
							<clause id="IDa972ec1f9c9b4d2b86ea0f88dafe6c7d"><enum>(i)</enum><text>the
			 total dollar value of the contract action;</text>
							</clause><clause id="IDef93ac7a44f94538aafeab1e8225783c"><enum>(ii)</enum><text>a
			 summary of the market research conducted by the National Center for
			 Cybersecurity and Communications, including a list of all offerors who were
			 considered and those who actually submitted bids, in order to determine that
			 use of the authority was appropriate; and</text>
							</clause><clause id="IDc5e937b2a96a4d2bb56b9e3a5a013256"><enum>(iii)</enum><text>a
			 copy of the justification and approval documents required by section 3304(e) of
			 title 41, United States Code.</text>
							</clause></subparagraph></paragraph><paragraph id="id7E55C0043F924AE98F099B776B752B62"><enum>(3)</enum><header>Classified
			 annex</header><text>A report submitted under this subsection shall be submitted
			 in an unclassified form, but may include a classified annex, if
			 necessary.</text>
					</paragraph></subsection></section><section id="IDf25ea60651464629aa89763d19916f46"><enum>504.</enum><header>Evaluation of
			 the effective implementation of Office of Management and Budget information
			 security related policies and directives</header>
				<subsection id="IDd3710d94740740968e2c66e67034b4f0"><enum>(a)</enum><header>In
			 general</header><text>The Administrator for Electronic Government and
			 Information Technology, in coordination with the Chief Information Officers
			 Council, the Federal Information Security Taskforce, and Council on Inspectors
			 General on Integrity and Efficiency, shall evaluate agency adoption and
			 effective implementation of appropriate information security related policies,
			 memoranda, and directives issued by the Office of Management and Budget
			 including—</text>
					<paragraph id="ID01edc5d1c4fb45dd90059e852cc719df"><enum>(1)</enum><text>OMB Memorandum
			 M–10–15, FY 2010 Reporting Instructions for the Federal Information Security
			 Management Act and Agency Privacy Management, issued April 21, 2010;</text>
					</paragraph><paragraph id="IDa675560662db4b34abe4b1c6fc184077"><enum>(2)</enum><text>OMB Memorandum
			 M–09–32, Update on the Trusted Internet Connections Initiative, issued
			 September 17, 2009;</text>
					</paragraph><paragraph id="ID7857852fb12b465990e0a43531cb4a21"><enum>(3)</enum><text>OMB Memorandum
			 M–09–02, Information Technology Management Structure and Governance Framework,
			 issued October 21, 2008;</text>
					</paragraph><paragraph id="IDad9c856eb9fd4f118701e4fd40b4d6bb"><enum>(4)</enum><text>OMB Memorandum
			 M–08–23, Securing the Federal Government’s Domain Name System Infrastructure,
			 issued April 22, 2008;</text>
					</paragraph><paragraph id="ID18e2bcfb9aac4550a9f4fb17a238af5e"><enum>(5)</enum><text>OMB Memorandum
			 M–08–22, Guidance on the Federal Desktop Core Configuration (FDCC), issued
			 August 11, 2008;</text>
					</paragraph><paragraph id="ID33eb3b3a44f04fbea2b3968d41ab516c"><enum>(6)</enum><text>OMB Memorandum
			 M–07–16, Safeguarding Against and Responding to the Breach of Personally
			 Identifiable Information, issued May 22, 2007;</text>
					</paragraph><paragraph id="ID56d3e2e551db4609832ec6589454aa0d"><enum>(7)</enum><text>OMB Memorandum
			 M–07–06, Validating and Monitoring Agency Issuance of Personal Identity
			 Verification Credentials, issued January 11, 2007;</text>
					</paragraph><paragraph id="IDa3d9f2bc45d447f888a8a91b3e5c5538"><enum>(8)</enum><text>OMB Memorandum
			 M–04–26, Personal Use Policies and <quote>File Sharing</quote> Technology,
			 issued September 8, 2004; and</text>
					</paragraph><paragraph id="ID46e6b7f5120f42ffb8487f3e69c76511"><enum>(9)</enum><text>OMB Memorandum
			 M–03–22, OMB Guidance for Implementing the Privacy Provisions of the
			 E-Government Act of 2002, issued September 26, 2003.</text>
					</paragraph></subsection><subsection id="ID0d74015446a04ecc8c3f6f0ff9ed510b"><enum>(b)</enum><header>Report</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Office of
			 Management and Budget shall submit a report on the evaluation required under
			 subsection (a) to the appropriate congressional committees which shall
			 include—</text>
					<paragraph id="IDd28ccb84472847b6a8d0cd194aa11238"><enum>(1)</enum><text>an examination of
			 whether Federal agencies have effectively implemented information security
			 policies;</text>
					</paragraph><paragraph id="ID37644a13733d4e90b36deef6f345fa96"><enum>(2)</enum><text>identification of
			 and reasons why Federal agencies are not in compliance with information
			 security policies;</text>
					</paragraph><paragraph id="ID3a47956fd3e94f489d87288f3dfba00a"><enum>(3)</enum><text>the extent to
			 which contractors working on behalf of Federal agencies are in compliance and
			 effectively implementing information security policies; and</text>
					</paragraph><paragraph id="ID8d6453cf07304b58831374c15909e99e"><enum>(4)</enum><text>recommended
			 legislative and executive branch actions.</text>
					</paragraph></subsection></section><section id="IDa9d2582a915f438bb7c1b906f75c7f14"><enum>505.</enum><header>Technical and
			 conforming amendments</header>
				<subsection id="IDebb5b8c5f11b4b4b98b96f775c5825e1"><enum>(a)</enum><header>Elimination of
			 assistant Secretary for cybersecurity and communications</header><text>The
			 Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—</text>
					<paragraph id="IDb4012596895f4c6ebabda70595db9787"><enum>(1)</enum><text>in section
			 103(a)(8) (6 U.S.C. 113(a)(8)), by striking <quote>,
			 cybersecurity,</quote>;</text>
					</paragraph><paragraph commented="no" id="IDf6c80999b93b46c78ba6c5e54dcb2452"><enum>(2)</enum><text>in section 514 (6
			 U.S.C. 321c)—</text>
						<subparagraph commented="no" id="IDc526f7bb82b44e88bdc3fc7c288fed20"><enum>(A)</enum><text>by striking
			 subsection (b); and</text>
						</subparagraph><subparagraph commented="no" id="IDb2f07f2bbf524ee0ae00403c7f026553"><enum>(B)</enum><text>by redesignating
			 subsection (c) as subsection (b); and</text>
						</subparagraph></paragraph><paragraph commented="no" id="IDbd44498c567f4f0f8fa8c79194d60b75"><enum>(3)</enum><text>in section
			 1801(b) (6 U.S.C. 571(b)), by striking <quote>shall report to the Assistant
			 Secretary for Cybersecurity and Communications</quote> and inserting
			 <quote>shall report to the Director of the National Center for Cybersecurity
			 and Communications</quote>.</text>
					</paragraph></subsection><subsection id="IDeb3f67bfd68047d3bf7be05d258038f9"><enum>(b)</enum><header>CIO
			 council</header><text>Section 3603(b) of title 44, United States Code, is
			 amended—</text>
					<paragraph id="ID1e41d0f1105546f99a0fe3cd32138ac7"><enum>(1)</enum><text>by redesignating
			 paragraph (7) as paragraph (8); and</text>
					</paragraph><paragraph id="IDe149e934fba54bd687269772da3ee0c8"><enum>(2)</enum><text>by inserting
			 after paragraph (6) the following:</text>
						<quoted-block display-inline="no-display-inline" id="idD5819C86F704427DB7EF34F4ECC28650" style="OLC">
							<paragraph id="ID4088a4f377f84b31af170004c694ba8e"><enum>(7)</enum><text>The Director of
				the National Center for Cybersecurity and
				Communications.</text>
							</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection id="ID642ee8805aeb4dcca00f62d7e48bb8df"><enum>(c)</enum><header>Repeal</header><text>The
			 Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—</text>
					<paragraph id="IDd68a0734bbdf4fedbfbe3fe8bd23e3c1"><enum>(1)</enum><text>by striking
			 section 223 (6 U.S.C. 143); and</text>
					</paragraph><paragraph id="ID46563491e41b4ef9989b304c0cca9c3a"><enum>(2)</enum><text>by redesignating
			 sections 224 and 225 (6 U.S.C. 144 and 145) as sections 223 and 224,
			 respectively.</text>
					</paragraph></subsection><subsection id="ID4bf046b97b72401492a4b53b17377fd0"><enum>(d)</enum><header>Technical
			 correction</header><text>Section 1802(a) of the Homeland Security Act of 2002
			 (6 U.S.C. 572(a)) is amended in the matter preceding paragraph (1) by striking
			 <quote>Department of</quote>.</text>
				</subsection><subsection id="ID2c3179bca1654d6ba39adf69e447c378"><enum>(e)</enum><header>Executive
			 schedule position</header><text>Section 5313 of title 5, United States Code, is
			 amended by adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="id71240877E71F464E91E5C8DCFDACD36E" style="OLC"><list level="subsection">
							<list-item>Director of the National Center for Cybersecurity
				  and
				  Communications.</list-item></list>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="ID831465e0f53349feb7320379fb3915f2"><enum>(f)</enum><header>Table of
			 contents</header><text>The table of contents in section 1(b) of the Homeland
			 Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—</text>
					<paragraph id="IDb01181e4bbcc468e9ddf9f3963f71318"><enum>(1)</enum><text>by striking the
			 items relating to sections 223, 224, and 225 and inserting the
			 following:</text>
						<quoted-block display-inline="no-display-inline" id="id4BED448555DB406097B5BEF6F8A10312" style="OLC">
							<toc>
								<toc-entry bold="off" level="section">Sec. 223. NET
				guard.</toc-entry>
								<toc-entry bold="off" level="section">Sec. 224. Cyber Security
				Enhancements Act of 2002.</toc-entry>
							</toc>
							<after-quoted-block>;
				  </after-quoted-block></quoted-block>
						<continuation-text continuation-text-level="paragraph">and</continuation-text></paragraph><paragraph id="ID9d8b6f58542e40679224348117cfa69f"><enum>(2)</enum><text>by inserting
			 after the item relating to section 237 the following:</text>
						<quoted-block display-inline="no-display-inline" id="id0AD3EF184E0C401988D5CB963A657555" style="OLC">
							<toc>
								<toc-entry level="section">Sec. 238. Cybersecurity research and
				development.</toc-entry>
								<toc-entry level="section">Sec. 239. National Cybersecurity Advisory
				Council.</toc-entry>
								<toc-entry idref="idB3D24B1FCBA246FDB68631AA0603CD9F" level="subtitle">Subtitle E—Cybersecurity</toc-entry>
								<toc-entry idref="id1E279600464842C9B55CADFF8FDCA5D0" level="section">Sec. 241. Definitions.</toc-entry>
								<toc-entry idref="IDf6b7d2881b9e4f02aa9f77f4ac2d4880" level="section">Sec. 242. National Center for Cybersecurity and
				Communications.</toc-entry>
								<toc-entry idref="id35D467794B804C8FBFF6A142C0B025DF" level="section">Sec. 243. Physical and cyber infrastructure
				collaboration.</toc-entry>
								<toc-entry idref="ID82845397830046c58a2ac43623da495b" level="section">Sec. 244. United States Computer Emergency Readiness
				Team.</toc-entry>
								<toc-entry idref="IDa4904f3a58824895a05620d3e9fe4a85" level="section">Sec. 245. Additional authorities of the Director of the
				National Center for Cybersecurity and Communications.</toc-entry>
								<toc-entry idref="IDca133ac3db80457ea0b070c2c58b80d5" level="section">Sec. 246. Information sharing.</toc-entry>
								<toc-entry idref="ID197d66a7fda64f58bb7cecdfb99d5a2d" level="section">Sec. 247. Private sector assistance.</toc-entry>
								<toc-entry idref="ID59a6ada748504ade8d72a3e673e78ebf" level="section">Sec. 248. Cyber risks to covered critical
				infrastructure.</toc-entry>
								<toc-entry idref="ID67ff41b5884a45da9cc1d5cf932541ca" level="section">Sec. 249. National cyber emergencies.</toc-entry>
								<toc-entry idref="IDe55bcbe958884fb4a262509e81f8f913" level="section">Sec. 250. Enforcement.</toc-entry>
								<toc-entry idref="IDd1766abbf9ec4ed8ad7d8fe630e5fb0b" level="section">Sec. 251. Protection of information.</toc-entry>
								<toc-entry idref="ID1777c88e155140fcbb5a6b412edcb19d" level="section">Sec. 252. Sector-specific agencies.</toc-entry>
								<toc-entry idref="IDc6bcff949e2148f3aee117b1b733317f" level="section">Sec. 253. Strategy for Federal cybersecurity supply chain
				management.</toc-entry>
								<toc-entry bold="off" level="section">Sec. 254. Covered critical
				infrastructure.</toc-entry>
							</toc>
							<after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection></section></title></legis-body>
</bill>
