<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H2F523D288D694820AAC3249CF18BFD4A" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 HR 5491 IH: Securing Systemically Important Critical Infrastructure Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2021-10-05</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 5491</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20211005">October 5, 2021</action-date><action-desc><sponsor name-id="K000386">Mr. Katko</sponsor> (for himself, <cosponsor name-id="S001209">Ms. Spanberger</cosponsor>, and <cosponsor name-id="G000597">Mr. Garbarino</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HHM00">Committee on Homeland Security</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To authorize the Director of the Cybersecurity and Infrastructure Security Agency to designate certain elements of critical infrastructure as systemically important, and for other purposes.</official-title></form><legis-body id="HDD33A1B30E144433803B631AC44074AC" style="OLC"><section id="H7335384B4D3A4D4C8D0FE639EA6D8675" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Securing Systemically Important Critical Infrastructure Act</short-title></quote>.</text></section><section id="HFFDE0B4D66C849BAB8A358CDCC85520B"><enum>2.</enum><header>Designation of systemically important critical infrastructure</header><subsection id="HD887EBA8D066494F8299B5183DF1062F"><enum>(a)</enum><header>Title XXII technical and clerical amendments</header><paragraph id="H6C2430DB2F9A438D8B94A1BB0E4C4D14"><enum>(1)</enum><header>Technical amendments</header><subparagraph id="H2C05E6DFF6B94025A14BC1D61FCC1EBF"><enum>(A)</enum><header>Homeland Security Act of 2002</header><text display-inline="yes-display-inline">Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended—</text><clause id="H1512D51445994C4C928029F008066C22"><enum>(i)</enum><text>in section 2202 (<external-xref legal-doc="usc" parsable-cite="usc/6/652">6 U.S.C. 652</external-xref>)—</text><subclause id="HF6C0F3036B22439AAD2B45BDCC2401E4"><enum>(I)</enum><text>in paragraph (11), by striking <quote>and</quote> after the semicolon;</text></subclause><subclause id="H9F3E62C61BFD4FA2BD95B0A2FD3CE950"><enum>(II)</enum><text>in the first paragraph (12) (relating to appointment of a Cybersecurity State Coordinator) by striking <quote>as described in section 2215; and</quote> and inserting <quote>as described in section 2217;</quote>;</text></subclause><subclause id="HA57A1721D39C47F1A2E757306BFDF730"><enum>(III)</enum><text>by redesignating the second paragraph (12) (relating to the .gov internet domain) as paragraph (13); and</text></subclause><subclause id="H1B7442164EE547CEA697F3C2A0F530C7"><enum>(IV)</enum><text>by redesignating the third paragraph (12) (relating to carrying out such other duties and responsibilities) as paragraph (14);</text></subclause></clause><clause id="H9925CDCB82294FC08D70C8B7B6B88A2C"><enum>(ii)</enum><text display-inline="yes-display-inline">in the first section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665">6 U.S.C. 665</external-xref>; relating to the duties and authorities relating to .gov internet domain), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" id="H041935396ACA4B6BAA48468B8EC06A98" display-inline="no-display-inline"><section id="H4DF99850BA9D4496A358D10B9DE5435A"><enum>2215.</enum><header>Duties and authorities relating to .gov internet domain</header></section><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="H702703C474DD4A3BA01E5E86A0A75E76"><enum>(iii)</enum><text display-inline="yes-display-inline">in the second section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665b">6 U.S.C. 665b</external-xref>; relating to the joint cyber planning office), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" id="HBBD31BBB3ECF4CD39359563B86F70C5D" display-inline="no-display-inline"><section id="H1770DEFA1B2D4AAEB1ED693011B40991"><enum>2216.</enum><header>Joint cyber planning office</header></section><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="H48EFCE50325747C7A2500608A8AE07EB"><enum>(iv)</enum><text display-inline="yes-display-inline">in the third section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665c">6 U.S.C. 665c</external-xref>; relating to the Cybersecurity State Coordinator), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" id="HE8C9EE99E8D24A6CAB90DFA1EDDA7CFD" display-inline="no-display-inline"><section id="H2021E57A68204F39B542C9F45C1A4C42"><enum>2217.</enum><header>Cybersecurity State Coordinator</header></section><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="H12EB87B2618B44FA98B52BF04B2B51D2"><enum>(v)</enum><text display-inline="yes-display-inline">in the fourth section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665d">6 U.S.C. 665d</external-xref>; relating to Sector Risk Management Agencies), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" id="H830A6F53CEAA446C9D086520E3A9DDEC" display-inline="no-display-inline"><section id="H17ADA206767648FEBAF1BADFA0DD2627"><enum>2218.</enum><header>Sector Risk Management Agencies</header></section><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="H181DAAF436A741E4B6152318360EEFCA"><enum>(vi)</enum><text display-inline="yes-display-inline">in section 2216 (<external-xref legal-doc="usc" parsable-cite="usc/6/665e">6 U.S.C. 665e</external-xref>; relating to the Cybersecurity Advisory Committee), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" id="HA63D718D979B483C904E8F56D5CA6EDB" display-inline="no-display-inline"><section id="HF37A5F67C3234E3F82CC12220BC2E476"><enum>2219.</enum><header>Cybersecurity Advisory Committee</header></section><after-quoted-block>;</after-quoted-block></quoted-block><continuation-text continuation-text-level="clause"> and</continuation-text></clause><clause id="H07C3AA9FF4D345688D539CDA20EFE9FA"><enum>(vii)</enum><text display-inline="yes-display-inline">in section 2217 (<external-xref legal-doc="usc" parsable-cite="usc/6/665f">6 U.S.C. 665f</external-xref>; relating to Cybersecurity Education and Training Programs), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" id="H0FC419584F5E49D38EBED9CA743C985A" display-inline="no-display-inline"><section id="HB28B947363474CBFA96A75ECBC33680E"><enum>2220.</enum><header>Cybersecurity Education and Training Programs</header></section><after-quoted-block>.</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="H6FB6889439234D0D8F514FAB02877A50"><enum>(B)</enum><header>Consolidated Appropriations Act, 2021</header><text display-inline="yes-display-inline">Paragraph (1) of section 904(b) of division U of the Consolidated Appropriations Act, 2021 (<external-xref legal-doc="public-law" parsable-cite="pl/116/260">Public Law 116–260</external-xref>) is amended, in the matter preceding subparagraph (A), by inserting <quote>of 2002</quote> after <quote>Homeland Security Act</quote>.</text></subparagraph></paragraph><paragraph id="H068D470CC88C4110B1D7BD36D4F6D567"><enum>(2)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by striking the items relating to sections 2214 through 2217 and inserting the following new items:</text><quoted-block style="OLC" id="H06697CB6FC56440A8459F973F13A564C" display-inline="no-display-inline"><toc regeneration="no-regeneration"><toc-entry level="section">Sec. 2214. National Asset Database. </toc-entry><toc-entry level="section">Sec. 2215. Duties and authorities relating to .gov internet domain. </toc-entry><toc-entry level="section">Sec. 2216. Joint cyber planning office. </toc-entry><toc-entry level="section">Sec. 2217. Cybersecurity State Coordinator. </toc-entry><toc-entry level="section">Sec. 2218. Sector Risk Management Agencies. </toc-entry><toc-entry level="section">Sec. 2219. Cybersecurity Advisory Committee. </toc-entry><toc-entry level="section">Sec. 2220. Cybersecurity Education and Training Programs. </toc-entry><toc-entry level="section">Sec. 2220A. Designation of systemically important critical infrastructure.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection id="HD344E6FFBDC444B29F2095505F1E06E9"><enum>(b)</enum><header>Designation of systemically important critical infrastructure</header><text>Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended by adding at the end the following new section:</text><quoted-block style="OLC" id="H2BDE10726BD7468F89F484B192B11FB1" display-inline="no-display-inline"><section id="H1944D63D9050414786BC536EB4B4FED7" commented="no"><enum>2220A.</enum><header>Designation of systemically important critical infrastructure</header><subsection id="H62122FF009F74B788B8476F480F3790A"><enum>(a)</enum><header>In general</header><text>The Director of the Cybersecurity and Infrastructure Security Agency shall designate an element of critical infrastructure as systemically important critical infrastructure if—</text><paragraph id="H76F571DCA8B548F39406B8B8B99CC16A"><enum>(1)</enum><text>the Director makes a preliminary determination pursuant to subsection (d)(1), using the methodology established pursuant to subsection (b), that such element satisfies the criteria established pursuant to subsection (c); and</text></paragraph><paragraph id="H2ED90181DEDA47878DA47D683A454448"><enum>(2)</enum><text>such preliminary determination becomes a final determination pursuant to subsection (d)(2).</text></paragraph></subsection><subsection id="HE4292742993748B78147AE5E517D5FB8" commented="no"><enum>(b)</enum><header>Methodology</header><text display-inline="yes-display-inline">The Director, in consultation with the heads of Sector Risk Management Agencies and covered stakeholders, shall—</text><paragraph id="H1D69AE460F3840B2BA5D426A7BA7CE2C" commented="no"><enum>(1)</enum><text display-inline="yes-display-inline">establish a methodology for determining whether an element of critical infrastructure satisfies the criteria established for systemically important critical infrastructure pursuant to subsection (c); and</text></paragraph><paragraph id="HE3C5B3793DFF46E9994702DE6CFAF7A9" commented="no"><enum>(2)</enum><text>update such methodology, as necessary.</text></paragraph></subsection><subsection id="H1AECE23267CD409C83E6714B68E7B404" commented="no"><enum>(c)</enum><header>Criteria</header><paragraph id="H4ADD794E8EDE4814BE40095CF945525A" commented="no"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Director, in consultation with the heads of Sector Risk Management Agencies and covered stakeholders, shall develop objective criteria to determine whether an element of critical infrastructure should be designated as systemically important.</text></paragraph><paragraph id="HCC80E622B68A41AA97A1066368368A1C"><enum>(2)</enum><header>Considerations</header><text display-inline="yes-display-inline">In developing the criteria required under paragraph (1), the Director shall consider the following:</text><subparagraph id="H0CDBCD4E8D0E488DA738290C65F959F6" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">The likelihood that a disruption to, or compromise of, such element of critical infrastructure would result in a debilitating effect on national security, economic security, public health or safety, or any combination thereof.</text></subparagraph><subparagraph id="HA70919C42E2F47AFB3ECB10A64209E6A"><enum>(B)</enum><text display-inline="yes-display-inline">The extent to which damage, disruption, or unauthorized access to such element or collectively to the category of critical infrastructure to which such element belongs—</text><clause id="H7E61678B324A4EAB871D3F1F2EA0E580"><enum>(i)</enum><text>would disrupt the reliable operation of a category of critical infrastructure; and</text></clause><clause id="H291387DEF2444F08AABA497571A8A6FC"><enum>(ii)</enum><text>would impede provisioning of a national critical function.</text></clause></subparagraph><subparagraph id="HD45545005CE64132B2FEF3890615481D"><enum>(C)</enum><text display-inline="yes-display-inline">The extent to which increasing the risk management coordination between the Federal Government and the owner or operator of the element would enhance the cybersecurity resilience of the United States.</text></subparagraph></paragraph><paragraph id="H9AF74617C64E43109585CAED9E66B742" commented="no"><enum>(3)</enum><header>Updates</header><text display-inline="yes-display-inline">The Director, in consultation with the heads of Sector Risk Management Agencies and covered stakeholders, shall update the criteria established pursuant to paragraph (1), as necessary.</text></paragraph></subsection><subsection id="HCD9275F8C5A444DAAF7D917956207B59"><enum>(d)</enum><header>Determinations</header><paragraph id="HE19EC22ACB1A4CB5A635A62CB6280477"><enum>(1)</enum><header>Preliminary determination</header><text display-inline="yes-display-inline">In the case of an element of critical infrastructure that the Director determines satisfies the criteria established under subsection (c), the Director shall—</text><subparagraph id="H40903E141C7946DD895B131E92A7CA45"><enum>(A)</enum><text>use the methodology under subsection (b) to make a preliminary determination with respect to whether such element is systemically important;</text></subparagraph><subparagraph id="H09045ABE37F8425F8D29C0BD9C85ED05"><enum>(B)</enum><text>notify the owner or operator of the element of such determination; and</text></subparagraph><subparagraph id="H52486B8E69C04035BFC06E015A6AD9FC"><enum>(C)</enum><text>provide such owner or operator with an opportunity to provide additional information for consideration in the final determination under paragraph (2).</text></subparagraph></paragraph><paragraph id="H84E6333A1968468F877D2BDB0B0202A3"><enum>(2)</enum><header>Final determination</header><text display-inline="yes-display-inline">On the date that is 30 days after the date on which the Director provides notice under paragraph (1)(B) with respect to a preliminary determination, such preliminary determination shall become final unless the Director determines, on the basis of additional information, that the element subject to the preliminary determination does not satisfy the criteria under subsection (c).</text></paragraph><paragraph id="H74AAEA78C09948E7BE58EC0F2213288E" commented="no"><enum>(3)</enum><header>Periodic review</header><text display-inline="yes-display-inline">Periodically, the Director shall review a final designation made pursuant to paragraph (2) with respect to an element using the same procedures outlined under such paragraph.</text></paragraph><paragraph id="H5D2464A30D05489AB8C106100D01C4A6"><enum>(4)</enum><header>Protection of information</header><text>Information obtained by the Director pursuant to paragraph (1)(C) shall be protected under section 2224 or classified, as determined appropriate by the Director.</text></paragraph></subsection><subsection id="HEAC4D2FF2B3A444B9610F50CA3F68982" commented="no"><enum>(e)</enum><header>List of systemically important critical infrastructure</header><paragraph id="HC0BB3D47875C4608A16B599B15D8A10D" commented="no"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the enactment of this section, the Director, in coordination with the heads of Sector Risk Management Agencies, shall develop a comprehensive list that includes any element of critical infrastructure designated as systemically important under this section.</text></paragraph><paragraph id="HEFE1F7E41D4740889CE2E5C86636F793" commented="no"><enum>(2)</enum><header>Update of list and notification to owners and operators</header><text display-inline="yes-display-inline">Not later than 7 days after the date on which the Director makes a final determination pursuant to paragraph (2) or (3) of subsection (d), the Director shall—</text><subparagraph id="H4830E393CB3645BCA10399B67AACC7D7" commented="no"><enum>(A)</enum><text>update the list required under paragraph (1); and</text></subparagraph><subparagraph id="HC6C9F7F74D3B4CB1AF1EFC61B2AC74BD" commented="no"><enum>(B)</enum><text>notify the appropriate owner or operator of the element of critical infrastructure of the addition, modification, or removal of such element from such list.</text></subparagraph></paragraph><paragraph id="HD793EEC20DDF4ECAAE76E7BBED7953C4" commented="no"><enum>(3)</enum><header>Congressional notification</header><text display-inline="yes-display-inline">Not later than 30 days after the list is updated pursuant to paragraph (2), the Director shall submit to the appropriate congressional committees such updated list.</text></paragraph><paragraph id="H052A89D0059940C495FEF079846F565B" commented="no"><enum>(4)</enum><header>Limitation on dissemination of list</header><text display-inline="yes-display-inline">The Director shall limit the dissemination of the list required under paragraph (1) to individuals who need access to such list to carry out official duties or responsibilities.</text></paragraph></subsection><subsection id="HBAB987847AC34A7EA6A66DBAEE100B4C" commented="no"><enum>(f)</enum><header>Prioritization of Agency resources</header><paragraph id="H35783AC29EB34CDDAD854E3CF6128F70" commented="no"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Director shall—</text><subparagraph id="H616C8FAFF8DD4BF2AB9311AE468FF503" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">seek to enter into enhanced risk management coordination with the owners and operators of elements of critical infrastructure designated as systemically important under this section; and</text></subparagraph><subparagraph id="H67FD7F175FA849ACA591020FCE2B6319" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">in allocating Agency resources to such owners and operators, prioritize owners and operators who coordinate with the Director pursuant to subparagraph (A).</text></subparagraph></paragraph><paragraph id="HE0073493264D4CC9875CDCF2D5B6BA09" commented="no"><enum>(2)</enum><header>Prioritized representation in the office for joint cyber planning</header><text display-inline="yes-display-inline">The head of the office for joint cyber planning established pursuant to section 2216, in carrying out the responsibilities of such office with respect to relevant cyber defense planning, joint cyber operations, cybersecurity exercises, and information-sharing practices, shall, to the extent practicable, prioritize the involvement of owners and operators of elements of critical infrastructure designated as systemically important under this section. </text></paragraph><paragraph id="HDF3260D6214B4359AD2C4336348F5A83" commented="no"><enum>(3)</enum><header>Continuous monitoring services</header><text display-inline="yes-display-inline">The Director shall, to the extent practicable, encourage the participation of the owners and operators of elements of critical infrastructure designated as systemically important pursuant to this section in voluntary programs to provide technical assistance in the form of continuous monitoring and detection of cybersecurity risks.</text></paragraph></subsection><subsection id="H1D585EDD6D60416B804C0A6DF7499BE8" commented="no"><enum>(g)</enum><header>Reports</header><paragraph id="H5A40908076D7431F80C536E9560258B1" commented="no"><enum>(1)</enum><header>Initial report</header><text>Not later than 180 days after the date of the enactment of this section, the Director, in consultation with the heads of Sector Risk Management Agencies and covered stakeholders, shall submit to the appropriate congressional committees a report that includes the following:</text><subparagraph id="HDFC5628439214A8D997D285F98DC2B32" display-inline="no-display-inline" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">A description of the capabilities of the Agency that exist immediately before the date of the enactment of this section with respect to identifying critical infrastructure.</text></subparagraph><subparagraph id="HA484D2A8C18344EEA7F68BFD196D44F4" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">Information relating to the criteria and methodology established pursuant to subsections (b) and (c) to identify an element of critical infrastructure as systemically important pursuant to this section.</text></subparagraph><subparagraph id="H09CFC67CBDFF40A0BA6CCDA66A0FE279" commented="no"><enum>(C)</enum><text display-inline="yes-display-inline">Information relating to—</text><clause id="HABA47207A08D4178978CB7E2426339F6"><enum>(i)</enum><text>the capabilities of the Agency to identify systems, assets, and facilities as systemically important pursuant to this section; and</text></clause><clause id="H706C6F41D2514A08833E12A0B97A713A"><enum>(ii)</enum><text>any updates relating to the capabilities referred to in clause (i).</text></clause></subparagraph><subparagraph id="H148A973755BD47E48AAF609719CCAF9E" commented="no"><enum>(D)</enum><text>Information relating to—</text><clause id="H172DAA2A0B0B42FABF6EA2E3F11909CB"><enum>(i)</enum><text>the interactions between the Agency, the heads of Sector Risk Management Agencies, and covered stakeholders with respect to carrying out this section, including processes used for incorporation of industry feedback and any associated challenges;</text></clause><clause id="H6C766B1FC4EC437CAEE929CBD422AD3C" commented="no"><enum>(ii)</enum><text>critical infrastructure identification programs within the Department and how such programs are being incorporated into the process to identify such infrastructure, including—</text><subclause id="H6E310779FBC24E738F9A91B4A59DB46C" commented="no"><enum>(I)</enum><text>section 9 of Executive Order 13636;</text></subclause><subclause id="H6602726B7FB14D8389C771C6BF1957C2" commented="no"><enum>(II)</enum><text>the National Asset Database established under section 2214; and</text></subclause><subclause id="HD5EA2BFD687D4A0FAE7D394EEEF95E52" commented="no"><enum>(III)</enum><text>section 4 of Executive Order 14028;</text></subclause></clause><clause id="H7BCE060AF73A46DEA5195FDC33B859EF" commented="no"><enum>(iii)</enum><text display-inline="yes-display-inline">any identified gaps in authorities or any additional resources required to carry out this section, including necessary legislation;</text></clause><clause id="H058599D099E842F9BA453434CDFF5016" commented="no"><enum>(iv)</enum><text display-inline="yes-display-inline">any resources the Agency is authorized to provide to the owners and operators of an element of critical infrastructure designated as systemically important pursuant to this section; and</text></clause><clause id="HB3BEEF69C45C4AD7BDDC60793AFDCFC1" commented="no"><enum>(v)</enum><text display-inline="yes-display-inline">opportunities for enhanced risk management coordination between the Federal Government and the owners and operators of an element of critical infrastructure designated as systemically important pursuant to this section.</text></clause></subparagraph></paragraph><paragraph id="H3B70EC2C329446768B0A0D7B37B40CBC" commented="no"><enum>(2)</enum><header>Subsequent reports</header><text display-inline="yes-display-inline">Not later than 2 years after the date on which the initial report is submitted pursuant to paragraph (1), and once every 2 years thereafter for 10 years, the Director, in consultation with the heads of Sector Risk Management Agencies and covered stakeholders, shall submit to the appropriate congressional committees a report that includes the updated information required under subparagraphs (B) through (D) of paragraph (1).</text></paragraph><paragraph id="H8313A64D14DA4D6F85427CCF4F96177D" commented="no"><enum>(3)</enum><header>Form</header><text>Each of the reports required under paragraphs (1) and (2) shall be submitted in unclassified form, but may contain a classified annex.</text></paragraph></subsection><subsection id="HDB2962CC251A4CF7AF4115CF9D9A621A" commented="no"><enum>(h)</enum><header>Restriction</header><text display-inline="yes-display-inline">Subchapter I of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, shall not apply to any action by the Director to implement this section.</text></subsection><subsection id="HDB7BE44299024A4ABAA59D85C3E3E987"><enum>(i)</enum><header>Covered stakeholders described</header><text>In this section, the term <term>covered stakeholders</term> means individuals identified by the Director. Such individuals shall include—</text><paragraph id="H3573D342D3C543728F10F200FF648DC8" commented="no" display-inline="no-display-inline"><enum>(1)</enum><text display-inline="yes-display-inline">representatives from the Critical Infrastructure Partnership Advisory Council, established pursuant to section 871;</text></paragraph><paragraph id="HB71F901EE3E14534BF649338C6AA64FF" commented="no" display-inline="no-display-inline"><enum>(2)</enum><text display-inline="yes-display-inline">representatives from the Cybersecurity Advisory Committee established under section 2219;</text></paragraph><paragraph id="HAF493EDC25354956A6658BD977A6C065" commented="no" display-inline="no-display-inline"><enum>(3)</enum><text display-inline="yes-display-inline">individuals representing critical infrastructure industries, the elements of which are subject to, or likely to be subject to, a preliminary determination under subsection (d)(1); </text></paragraph><paragraph id="H4FDE0E750748474C8EEF98938D2EED6F" commented="no" display-inline="no-display-inline"><enum>(4)</enum><text display-inline="yes-display-inline">representatives from trade organizations whose memberships include a concentration of owners and operators of critical infrastructure industries, the elements of which are subject to, or likely to be subject to, a preliminary determination under subsection (d)(1); and</text></paragraph><paragraph id="H9179E8D079504167B77C07F2445D3FF1" commented="no" display-inline="no-display-inline"><enum>(5)</enum><text display-inline="yes-display-inline">any other individual determined appropriate by the Director.</text></paragraph></subsection><subsection id="HE1898686A5B94D4893CAEEF7DDBAFCF1" commented="no"><enum>(j)</enum><header>Definitions</header><text>In this section:</text><paragraph id="H384E5594C6234ACBBB4C9039A0255362" commented="no"><enum>(1)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means—</text><subparagraph id="H11DCCE6F07B443AFAF04AC4CB867ACE0" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">the Committee on Homeland Security of the House of Representatives; and</text></subparagraph><subparagraph id="H2415D2A6ECB54DA9A7CBB3C17E0983F1" commented="no"><enum>(B)</enum><text>the Committee on Homeland Security and Governmental Affairs of the Senate.</text></subparagraph></paragraph><paragraph id="HCCE4F9E84F7945F7A38FD4F6A4441B1F" commented="no"><enum>(2)</enum><header>National critical function</header><text display-inline="yes-display-inline">The term <term>national critical function</term> means a function of the Federal Government or a United States private sector entity, as determined by the Director, that the disruption, corruption, or dysfunction of such function would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof. </text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="HF578BC122B9442A8871790795E185CF8" commented="no"><enum>(c)</enum><header>Assessment of risk management coordination</header><paragraph id="HC7DF286A6C9A4F51A384FC53E4F9FE1E" commented="no"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 120 days after the date of the enactment of this Act, the Director, in consultation with the heads of Sector Risk Management Agencies and covered stakeholders, shall conduct an assessment of potential processes for, and benefits of, enhanced risk management coordination between the Federal Government and the owners and operators of elements of critical infrastructure designated as systemically important pursuant to section 2220A of the Homeland Security Act of 2002, as added by subsection (b) of this Act.</text></paragraph><paragraph id="H494A538D747343A2B0B88E3105FCFDFC" commented="no"><enum>(2)</enum><header>Consideration</header><text>The assessment required under paragraph (1) shall include a consideration of—</text><subparagraph id="H8B216917E8EE4FC982A308B0FB5D5B3F" commented="no"><enum>(A)</enum><text>opportunities for enhanced intelligence support and information-sharing;</text></subparagraph><subparagraph id="H77AFEE91DC634AECA771AC64002B5EB9" commented="no"><enum>(B)</enum><text>prioritized Federal technical assistance; </text></subparagraph><subparagraph id="HC6CE499C453F4353A98CEFEAB02A2E7B" commented="no"><enum>(C)</enum><text>any other process for, or benefit of, enhanced risk management coordination determined appropriate by the Director; and</text></subparagraph><subparagraph id="HDDAB188334074828890A198BB3FE3671"><enum>(D)</enum><text display-inline="yes-display-inline">any additional resources or authorization required to conduct enhanced risk management coordination between the Federal Government and owners and operators of elements of critical infrastructure designated as systemically important pursuant to section 2220A of the Homeland Security Act of 2002, as added by subsection (b) of this Act, including the prevention of duplicative requirements for regulated sectors and entities.</text></subparagraph></paragraph><paragraph id="H9BF50A20CF8F48019A973FBCF2580A5D"><enum>(3)</enum><header>Covered stakeholders described</header><text display-inline="yes-display-inline">The term <quote>covered stakeholders</quote> has the meaning given such term in section 2220A(i) of the Homeland Security Act of 2002, as added by subsection (b) of this Act.</text></paragraph></subsection></section><section id="HED0C8AE014B54598867FB1F28B369D24"><enum>3.</enum><header>Prioritization of clearances for systemically important critical infrastructure</header><text display-inline="no-display-inline">Section 2212 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/662">6 U.S.C. 662</external-xref>) is amended by adding at the end the following new sentence: <quote>In carrying out this section, the Secretary shall prioritize the applications of owners and operators of elements of critical infrastructure designated as systemically important pursuant to section 2220A.</quote>. </text></section></legis-body></bill> 

