II
Calendar No. 632
117th CONGRESS
2d Session
S. 2540
[Report No. 117–248]
IN THE SENATE OF THE UNITED STATES
July 29, 2021
Mr. Portman (for himself, Mr. Peters, and Ms. Hassan) introduced the following bill; which was read twice and referred to the Committee on Homeland Security and Governmental Affairs
December 13, 2022
Reported by Mr. Peters, with an amendment
Strike out all after the enacting clause and insert the part printed in italic
A BILL
To make technical corrections to title XXII of the Homeland Security Act of 2002, and for other purposes.
Short title
This Act may be cited as the CISA Technical Corrections and Improvements Act of 2021
.
Redesignations
In general
Subtitle A of title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651 et seq.) is amended—
by striking section 2201 (6 U.S.C. 651);
by redesignating sections 2202 through 2214 as sections 2201 through 2213, respectively;
by redesignating section 2217 (6 U.S.C. 665f) as section 2219;
by redesignating section 2216 (6 U.S.C. 665e) as section 2218;
by redesignating the fourth section 2215 (relating to Sector Risk Management Agencies) (6 U.S.C. 665d) as section 2217;
by redesignating the third section 2215 (relating to the Cybersecurity State Coordinator) (6 U.S.C. 665c) as section 2216; and
by redesignating the first section 2215 (relating to Duties and Authorities Relating to .GOV Internet Domain) (6 U.S.C. 665) as section 2214.
Technical and conforming amendments
The Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—
in section 320(d)(3)(C) (6 U.S.C. 195f(d)(3)(C)) by striking section 2201
and inserting section 2200
;
in section 846(1) (6 U.S.C. 417(1)), by striking section 2209
and inserting section 2208
;
in section 1801(c)(16) (6 U.S.C. 571(c)(16)) by striking section 2202(c)(7)
and inserting section 2201(c)(7)
;
in section 2001(4)(A)(iii)(II) (6 U.S.C. 601(4)(A)(iii)(II)), by striking section 2214(a)(2)
and inserting section 2213(a)(2)
;
in section 2008(a)(3) (6 U.S.C. 609(a)(3)), by striking section 2214(a)(2)
and inserting section 2213(a)(2);
in section 2201, as so redesignated—
in subsection (c)—
in the first paragraph (12), by striking section 2215
and inserting section 2216
;
by redesignating the second and third paragraphs (12) as paragraphs (13) and (14), respectively; and
in paragraph (13), as so redesignated, by striking section 2215
and inserting section 2214
; and
in subsection (e)(2), by striking sections 2203(b) and 2204(b)
and inserting sections 2202(b) and 2203(b)
;
in section 2202(b)(3), as so redesignated, by striking section 2202(c)(7)
and inserting section 2201(c)(7)
;
in section 2203(b)(3), as so redesignated, by striking section 2202(c)(7)
and inserting section 2201(c)(7)
;
in section 2204, as so redesignated, in the matter preceding paragraph (1), by striking section 2202
and inserting section 2201
;
in section 2210(b)(2)(A), as so redesignated, by striking section 2209
and inserting section 2208
; and
in section 2217(c)(4)(A), by striking section 2209
and inserting section 2208
.
Table of contents
The table of contents in section 1(b) of the Homeland Security Act of 2002 (Public Law 107–296; 116 Stat. 2135) is amended—
by striking inserting before the item relating to subtitle A of title XXII the following:
;
by striking the items relating to sections 2201 through 2217 and inserting the following:
Sec. 2201. Cybersecurity and Infrastructure Security Agency.
Sec. 2202. Cybersecurity Division.
Sec. 2203. Infrastructure Security Division.
Sec. 2204. Enhancement of Federal and non-Federal cybersecurity.
Sec. 2205. Net guard.
Sec. 2206. Cyber Security Enhancement Act of 2002.
Sec. 2207. Cybersecurity recruitment and retention.
Sec. 2208. National cybersecurity and communications integration center.
Sec. 2209. Cybersecurity plans.
Sec. 2210. Cybersecurity strategy.
Sec. 2211. Clearances.
Sec. 2212. Federal intrusion detection and prevention system.
Sec. 2213. National Asset Database.
Sec. 2214. Duties and authorities relating to .gov internet domain.
Sec. 2215. Joint Cyber Planning Office.
Sec. 2216. Cybersecurity State Coordinator.
Sec. 2217. Sector Risk Management Agencies.
Sec. 2218. Cybersecurity Advisory Committee.
Sec. 2219. Cybersecurity education and training programs.
.
Additional technical amendment
Amendment
Section 904(b)(1) of the DOTGOV Act of 2020 (title IX of division U of Public Law 116–260) is amended, in the matter preceding subparagraph (A), by striking Homeland Security Act
and inserting Homeland Security Act of 2002
.
Effective date
The amendment made by paragraph (1) shall take effect as if enacted as part of the DOTGOV Act of 2020 (title IX of division U of Public Law 116–260).
Consolidation of definitions
In general
Title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651) is amended—
by striking section 2201; and
by inserting before the subtitle A heading the following:
Definitions
Except as otherwise specifically provided, in this title:
Agency
The term Agency means the Cybersecurity and Infrastructure Security Agency.
Agency information
The term agency information means information collected or maintained by or on behalf of an agency.
Agency information system
The term agency information system means an information system used or operated by an agency or by another entity on behalf of an agency.
Appropriate congressional committees
The term appropriate congressional committees means—
the Committee on Homeland Security and Governmental Affairs of the Senate; and
the Committee on Homeland Security of the House of Representatives.
Critical infrastructure information
The term critical infrastructure information means information not customarily in the public domain and related to the security of critical infrastructure or protected systems—
actual, potential, or threatened interference with, attack on, compromise of, or incapacitation of critical infrastructure or protected systems by either physical or computer-based attack or other similar conduct (including the misuse of or unauthorized access to all types of communications and data transmission systems) that violates Federal, State, or local law, harms interstate commerce of the United States, or threatens public health or safety;
the ability of any critical infrastructure or protected system to resist such interference, compromise, or incapacitation, including any planned or past assessment, projection, or estimate of the vulnerability of critical infrastructure or a protected system, including security testing, risk evaluation thereto, risk management planning, or risk audit; or
any planned or past operational problem or solution regarding critical infrastructure or protected systems, including repair, recovery, reconstruction, insurance, or continuity, to the extent it is related to such interference, compromise, or incapacitation.
Cyber threat indicator
The term cyber threat indicator means information that is necessary to describe or identify—
malicious reconnaissance, including anomalous patterns of communications that appear to be transmitted for the purpose of gathering technical information related to a cybersecurity threat or security vulnerability;
a method of defeating a security control or exploitation of a security vulnerability;
a security vulnerability, including anomalous activity that appears to indicate the existence of a security vulnerability;
a method of causing a user with legitimate access to an information system or information that is stored on, processed by, or transiting an information system to unwittingly enable the defeat of a security control or exploitation of a security vulnerability;
malicious cyber command and control;
the actual or potential harm caused by an incident, including a description of the information exfiltrated as a result of a particular cybersecurity threat;
any other attribute of a cybersecurity threat, if disclosure of such attribute is not otherwise prohibited by law; or
any combination thereof.
Cybersecurity purpose
The term cybersecurity purpose means the purpose of protecting an information system or information that is stored on, processed by, or transiting an information system from a cybersecurity threat or security vulnerability.
Cybersecurity risk
The term cybersecurity risk—
means threats to and vulnerabilities of information or information systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information or information systems, including such related consequences caused by an act of terrorism; and
does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.
Cybersecurity threat
In general
Except as provided in subparagraph (B), the term cybersecurity threat means an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system.
Exclusion
The term cybersecurity threat does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.
Defensive measure
In general
Except as provided in subparagraph (B), the term defensive measure means an action, device, procedure, signature, technique, or other measure applied to an information system or information that is stored on, processed by, or transiting an information system that detects, prevents, or mitigates a known or suspected cybersecurity threat or security vulnerability.
Exclusion
The term defensive measure does not include a measure that destroys, renders unusable, provides unauthorized access to, or substantially harms an information system or information stored on, processed by, or transiting such information system not owned by—
the entity operating the measure; or
another entity or Federal entity that is authorized to provide consent and has provided consent to that private entity for operation of such measure.
Homeland Security Enterprise
The term Homeland Security Enterprise means relevant governmental and nongovernmental entities involved in homeland security, including Federal, State, local, and tribal government officials, private sector representatives, academics, and other policy experts.
Incident
The term incident means an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or actually or imminently jeopardizes, without lawful authority, an information system.
Information sharing and analysis organization
The term Information Sharing and Analysis Organization means any formal or informal entity or collaboration created or employed by public or private sector organizations, for purposes of—
gathering and analyzing critical infrastructure information, including information related to cybersecurity risks and incidents, in order to better understand security problems and interdependencies related to critical infrastructure, including cybersecurity risks and incidents, and protected systems, so as to ensure the availability, integrity, and reliability thereof;
communicating or disclosing critical infrastructure information, including cybersecurity risks and incidents, to help prevent, detect, mitigate, or recover from the effects of a interference, compromise, or a incapacitation problem related to critical infrastructure, including cybersecurity risks and incidents, or protected systems; and
voluntarily disseminating critical infrastructure information, including cybersecurity risks and incidents, to its members, State, local, and Federal Governments, or any other entities that may be of assistance in carrying out the purposes specified in subparagraphs (A) and (B).
Information system
The term information system has the meaning given the term in section 3502 of title 44, United States Code.
Intelligence community
The term intelligence community has the meaning given the term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)).
Monitor
The term monitor means to acquire, identify, or scan, or to possess, information that is stored on, processed by, or transiting an information system.
National cybersecurity asset response activities
The term national cybersecurity asset response activities means—
furnishing cybersecurity technical assistance to entities affected by cybersecurity risks to protect assets, mitigate vulnerabilities, and reduce impacts of cyber incidents;
identifying other entities that may be at risk of an incident and assessing risk to the same or similar vulnerabilities;
assessing potential cybersecurity risks to a sector or region, including potential cascading effects, and developing courses of action to mitigate such risks;
facilitating information sharing and operational coordination with threat response; and
providing guidance on how best to utilize Federal resources and capabilities in a timely, effective manner to speed recovery from cybersecurity risks.
National security system
The term national security system has the meaning given the term in section 11103 of title 40, United States Code.
Sector risk management agency
The term Sector Risk Management Agency means a Federal department or agency, designated by law or Presidential directive, with responsibility for providing institutional knowledge and specialized expertise of a sector, as well as leading, facilitating, or supporting programs and associated activities of its designated critical infrastructure sector in the all hazards environment in coordination with the Department.
Security vulnerability
The term security vulnerability means any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control.
Sharing
The term sharing (including all conjugations thereof) means providing, recieving, and disseminating (including all conjugations of each such terms).
.
Technical and conforming amendments
The Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—
in section 2201, as so redesignated—
in subsection (a)(1), by striking (in this subtitle referred to as the Agency)
;
in subsection (f)—
in paragraph (1), by inserting Executive
before Assistant Director
; and
in paragraph (2), by inserting Executive
before Assistant Director
;
in section 2202(a)(2), as so redesignated, by striking as the
and inserting Assistant Director
as the
; Executive Assistant Director
in section 2203(a)(2), as so redesignated, by striking as the
and inserting Assistant Director
as the
; Executive Assistant Director
in section 2208, as so redesignated—
by striking subsection (a);
by redesignating subsections (b) through subsection (o) as subsections (a) through (n), respectively;
in subsection (c)(1)(A)(iii), as so redesignated, by striking , as that term is defined under section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4))
;
in subsection (d), as so redesignated, in the matter preceding paragraph (1), by striking subsection (c)
and inserting subsection (b)
;
in subsection (j), as so redesignated, by striking subsection (c)(8)
and inserting subsection (b)(8)
; and
in subsection (n), as so redesignated—
in paragraph (2)(A), by striking subsection (c)(12)
and inserting subsection (b)(12)
; and
in paragraph (3)(B)(i), by striking subsection (c)(12)
and inserting subsection (b)(12)
;
in section 2209, as so redesignated—
by striking subsection (a);
by redesignating subsections (b) through (d) as subsections (a) through (c), respectively;
in subsection (b), as so redesignated—
by striking information sharing and analysis organizations (as defined in section 2222(5))
and inserting Information Sharing and Analysis Organizations
; and
by striking (as defined in section 2209)
; and
in subsection (c), as so redesignated, by striking subsection (c)
and inserting subsection (b)
;
in section 2210, as so redesignated, by striking subsection (h);
in section 2211, as so redesignated, by striking information sharing and analysis organizations (as defined in section 2222(5))
and inserting Information Sharing and Analysis Organizations
;
in section 2212, as so redesignated—
by striking subsection (a);
by redesignating subsections (b) through (f) as subsections (a) through (e); respectively;
in subsection (b), as so redesignated, by striking subsection (b)
each place it appears and inserting subsection (a)
;
in subsection (c), as so redesignated, in the matter preceding paragraph (1), by striking subsection (b)
and inserting subsection (a)
; and
in subsection (d), as so redesignated—
in paragraph (1)—
in the matter preceding subparagraph (A), by striking subsection (c)(2)
and inserting subsection (b)(2)
;
in subparagraph (A), by striking subsection (c)(1)
and inserting subsection (b)(1)
; and
in subparagraph (B), by striking subsection (c)(2)
and inserting subsection (b)(2)
; and
in paragraph (2), by striking subsection (c)(2)
and inserting subsection (b)(2)
;
in section 2215 (6 U.S.C. 665b)—
by striking subsection (a);
by redesignating subsections (b) through (h) as subsections (a) through (g), respectively;
in subsection (a), as so redesignated—
in the matter preceding paragraph (1), by striking subsection (e)
and inserting subsection (d)
;
in paragraph (1), by striking subsection (c)
and inserting subsection (b)
; and
in paragraph (2), by striking subsection (c)
and inserting subsection (b)
;
in subsection (b)(4), as so redesignated—
by striking subsection (e)
and inserting subsection (d)
; and
by striking subsection (h)
and inserting subsection (g)
;
in subsection (d), as so redesignated, by striking subsection (b)(1)
each place it appears and inserting subsection (a)(1)
;
in subsection (e), as so redesignated—
by striking subsection (b)
and inserting subsection (a)
;
by striking subsection (e)
and inserting subsection (d)
; and
by striking subsection (b)(1)
and inserting subsection (a)(1)
; and
in subsection (f), as so redesignated, by striking subsection (c)
and inserting subsection (b)
;
in section 2216, as so redesignated, by striking subsection (f) and inserting the following:
Cyber defense operation defined
In this section, the term cyber defense operation means the use of a defensive measure.
; and
in section 2222—
by striking paragraphs (3), (5), and (8);
by redesignating paragraph (4) as paragraph (3); and
by redesignating paragraphs (6) and (7) as paragraphs (4) and (5), respectively.
Cybersecurity Act of 2015 definitions
Section 102 of the Cybersecurity Act of 2015 (6 U.S.C. 1501) is amended—
by striking paragraphs (4) through (7) and inserting the following:
Cybersecurity purpose
The term cybersecurity purpose has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
Cybersecurity threat
The term cybersecurity threat has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
Cyber theat indicator
The term cyber threat indicator has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
Defensive measure
The term defensive measure has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
;
by striking paragraph (13) and inserting the following:
Monitor
The term monitor has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
; and
by striking paragraph (17) and inserting the following:
Security vulnerability
The term security vulnerability has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
.
Additional technical and conforming amendments
Federal Cybersecurity Enhancement Act of 2015
The Federal Cybersecurity Enhancement Act of 2015 (6 U.S.C. 1521 et seq.) is amended—
in section 222 (6 U.S.C. 1521)—
in paragraph (2), by striking section 2210
and inserting section 2200
; and
in paragraph (4), by striking section 2209
and inserting section 2200
;
in section 223 (6 U.S.C. 151 note) is amended by striking section 2213(b)(1)
each place it appears and inserting section 2212(a)(1)
; and
in section 226—
in subsection (a)—
in paragraph (1), by striking section 2213
and inserting section 2200
;
in paragraph (4), by striking section 2210(b)(1)
and inserting section 2209(a)(1)
; and
in paragraph (5), by striking section 2213(b)
and inserting section 2212(a)
; and
in subsection (c)(1)(A)(vi), by striking section 2213(c)(5)
and inserting section 2212(b)(5)
; and
in section 227 (6 U.S.C. 1525)—
in subsection (a), by striking section 2213
and inserting section 2212
; and
in subsection (b), by striking section 2213(d)(2)
and inserting section 2212(c)(2)
.
Public Health Service Act
Section 2811(b)(4)(D) of the Public Health Service Act (42 U.S.C. 300hh–10(b)(4)(D)) is amended by striking section 228(c) of the Homeland Security Act of 2002 (6 U.S.C. 149(c))
and inserting section 2209(c) of the Homeland Security Act of 2002
.
William M. (Mac) Thornberry National Defense Authorization Act of Fiscal Year 2021
Section 9002 of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (6 U.S.C. 652a) is amended—
in subsection (a)—
in paragraph (5), by striking section 2222(5) of the Homeland Security Act of 2002 (6 U.S.C. 671(5))
and inserting section 2200 of the Homeland Security Act of 2002
; and
in paragraph (7), by striking given the term
and all that follows and inserting given the term in section 2200 of the Homeland Security Act of 2002
;
in subsection (b)(1)(A), by striking section 2202(c)(4) of the Homeland Security Act (6 U.S.C. 652(c)(4))
and inserting section 2201(c)(4)
;
in subsection (c)(3)(B), by striking section 2201(5) of the Homeland Security Act of 2002 (6 U.S.C. 651(5))
and inserting section 2200 of the Homeland Security Act of 2002
; and
in subsection (d)—
by striking section 2215
and inserting 2217
; and
by striking , as added by this section
.
National Security Act of 1947
Section 113B of the National Security Act of 1947 (50 U.S.C. 3049a(b)(4)) is amended by striking section 226 of the Homeland Security Act of 2002 (6 U.S.C. 147)
and inserting section 2207 of the Homeland Security Act of 2002
.
Cybersecurity Act of 2015
Section 404(a) of the Cybersecurity Act of 2015 (6 U.S.C. 1532(a)) is amended by striking section 2209
and inserting section 2208
.
IoT Cybersecurity Improvement Act of 2020
Section 5(b)(3) of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c) is amended by striking section 2209(m)
and inserting section 2208(l)
.
Small Business Act
Section 21(a)(8)(B) of the Small Business Act (15 U.S.C. 648(a)(8)(B)) is amended by striking section 2209(a)
and inserting section 2200
.
Title 46
Section 70101(2) of title 46, United States Code, is amended by striking section 227 of the Homeland Security Act of 2002 (6 U.S.C. 148)
and inserting section 2200 of the Homeland Security Act of 2002
.
Short title
This Act may be cited as the CISA Technical Corrections and Improvements Act of 2021
.
Redesignations
In general
Subtitle A of title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651 et seq.) is amended—
by redesignating section 2217 (6 U.S.C. 665f) as section 2220;
by redesignating section 2216 (6 U.S.C. 665e) as section 2219;
by redesignating the fourth section 2215 (relating to Sector Risk Management Agencies) (6 U.S.C. 665d) as section 2218;
by redesignating the third section 2215 (relating to the Cybersecurity State Coordinator) (6 U.S.C. 665c) as section 2217; and
by redesignating the second section 2215 (relating to the Joint Cyber Planning Office) (6 U.S.C. 665b) as section 2216.
Technical and conforming amendments
Section 2202(c) of the Homeland Security Act of 2002 (6 U.S.C. 652(c)) is amended—
in paragraph (11), by striking and
at the end;
in the first paragraph (12)—
by striking section 2215
and inserting section 2217
; and
by striking and
at the end; and
by redesignating the second and third paragraphs (12) as paragraphs (13) and (14), respectively.
Additional technical amendment
Amendment
Section 904(b)(1) of the DOTGOV Act of 2020 (title IX of division U of Public Law 116–260) is amended, in the matter preceding subparagraph (A), by striking Homeland Security Act
and inserting Homeland Security Act of 2002
.
Effective date
The amendment made by paragraph (1) shall take effect as if enacted as part of the DOTGOV Act of 2020 (title IX of division U of Public Law 116–260).
Consolidation of definitions
In general
Title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651) is amended by inserting before the subtitle A heading the following:
Definitions
Except as otherwise specifically provided, in this title:
Agency
The term Agency means the Cybersecurity and Infrastructure Security Agency.
Agency information
The term agency information means information collected or maintained by or on behalf of an agency.
Agency information system
The term agency information system means an information system used or operated by an agency or by another entity on behalf of an agency.
Appropriate congressional committees
The term appropriate congressional committees means—
the Committee on Homeland Security and Governmental Affairs of the Senate; and
the Committee on Homeland Security of the House of Representatives.
Critical infrastructure information
The term critical infrastructure information means information not customarily in the public domain and related to the security of critical infrastructure or protected systems—
actual, potential, or threatened interference with, attack on, compromise of, or incapacitation of critical infrastructure or protected systems by either physical or computer-based attack or other similar conduct (including the misuse of or unauthorized access to all types of communications and data transmission systems) that violates Federal, State, or local law, harms interstate commerce of the United States, or threatens public health or safety;
the ability of any critical infrastructure or protected system to resist such interference, compromise, or incapacitation, including any planned or past assessment, projection, or estimate of the vulnerability of critical infrastructure or a protected system, including security testing, risk evaluation thereto, risk management planning, or risk audit; or
any planned or past operational problem or solution regarding critical infrastructure or protected systems, including repair, recovery, reconstruction, insurance, or continuity, to the extent it is related to such interference, compromise, or incapacitation.
Cyber threat indicator
The term cyber threat indicator means information that is necessary to describe or identify—
malicious reconnaissance, including anomalous patterns of communications that appear to be transmitted for the purpose of gathering technical information related to a cybersecurity threat or security vulnerability;
a method of defeating a security control or exploitation of a security vulnerability;
a security vulnerability, including anomalous activity that appears to indicate the existence of a security vulnerability;
a method of causing a user with legitimate access to an information system or information that is stored on, processed by, or transiting an information system to unwittingly enable the defeat of a security control or exploitation of a security vulnerability;
malicious cyber command and control;
the actual or potential harm caused by an incident, including a description of the information exfiltrated as a result of a particular cybersecurity threat;
any other attribute of a cybersecurity threat, if disclosure of such attribute is not otherwise prohibited by law; or
any combination thereof.
Cybersecurity purpose
The term cybersecurity purpose means the purpose of protecting an information system or information that is stored on, processed by, or transiting an information system from a cybersecurity threat or security vulnerability.
Cybersecurity risk
The term cybersecurity risk—
means threats to and vulnerabilities of information or information systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information or information systems, including such related consequences caused by an act of terrorism; and
does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.
Cybersecurity threat
In general
Except as provided in subparagraph (B), the term cybersecurity threat means an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system.
Exclusion
The term cybersecurity threat does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.
Defensive measure
In general
Except as provided in subparagraph (B), the term defensive measure means an action, device, procedure, signature, technique, or other measure applied to an information system or information that is stored on, processed by, or transiting an information system that detects, prevents, or mitigates a known or suspected cybersecurity threat or security vulnerability.
Exclusion
The term defensive measure does not include a measure that destroys, renders unusable, provides unauthorized access to, or substantially harms an information system or information stored on, processed by, or transiting such information system not owned by—
the entity operating the measure; or
another entity or Federal entity that is authorized to provide consent and has provided consent to that private entity for operation of such measure.
Homeland Security Enterprise
The term Homeland Security Enterprise means relevant governmental and nongovernmental entities involved in homeland security, including Federal, State, local, and tribal government officials, private sector representatives, academics, and other policy experts.
Incident
The term incident means an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or actually or imminently jeopardizes, without lawful authority, an information system.
Information sharing and analysis organization
The term Information Sharing and Analysis Organization means any formal or informal entity or collaboration created or employed by public or private sector organizations, for purposes of—
gathering and analyzing critical infrastructure information, including information related to cybersecurity risks and incidents, in order to better understand security problems and interdependencies related to critical infrastructure, including cybersecurity risks and incidents, and protected systems, so as to ensure the availability, integrity, and reliability thereof;
communicating or disclosing critical infrastructure information, including cybersecurity risks and incidents, to help prevent, detect, mitigate, or recover from the effects of a interference, compromise, or a incapacitation problem related to critical infrastructure, including cybersecurity risks and incidents, or protected systems; and
voluntarily disseminating critical infrastructure information, including cybersecurity risks and incidents, to its members, State, local, and Federal Governments, or any other entities that may be of assistance in carrying out the purposes specified in subparagraphs (A) and (B).
Information system
The term information system has the meaning given the term in section 3502 of title 44, United States Code.
Intelligence community
The term intelligence community has the meaning given the term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)).
Monitor
The term monitor means to acquire, identify, or scan, or to possess, information that is stored on, processed by, or transiting an information system.
National cybersecurity asset response activities
The term national cybersecurity asset response activities means—
furnishing cybersecurity technical assistance to entities affected by cybersecurity risks to protect assets, mitigate vulnerabilities, and reduce impacts of cyber incidents;
identifying other entities that may be at risk of an incident and assessing risk to the same or similar vulnerabilities;
assessing potential cybersecurity risks to a sector or region, including potential cascading effects, and developing courses of action to mitigate such risks;
facilitating information sharing and operational coordination with threat response; and
providing guidance on how best to utilize Federal resources and capabilities in a timely, effective manner to speed recovery from cybersecurity risks.
National security system
The term national security system has the meaning given the term in section 11103 of title 40, United States Code.
Sector risk management agency
The term Sector Risk Management Agency means a Federal department or agency, designated by law or Presidential directive, with responsibility for providing institutional knowledge and specialized expertise of a sector, as well as leading, facilitating, or supporting programs and associated activities of its designated critical infrastructure sector in the all hazards environment in coordination with the Department.
Security control
The term security control means the management, operational, and technical controls used to protect against an unauthorized effort to adversely affect the confidentiality, integrity, and availability of an information system or its information.
Security vulnerability
The term security vulnerability means any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control.
Sharing
The term sharing (including all conjugations thereof) means providing, receiving, and disseminating (including all conjugations of each such terms).
.
Technical and conforming amendments
The Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—
by amending section 2201 to read as follows:
Definition
In this subtitle, the term Cybersecurity Advisory Committee means the advisory committee established under section 2219(a).
;
in section 2202—
in subsection (a)(1), by striking (in this subtitle referred to as the Agency)
;
in subsection (f)—
in paragraph (1), by inserting Executive
before Assistant Director
; and
in paragraph (2), by inserting Executive
before Assistant Director
;
in section 2203(a)(2), by striking as the
and inserting Assistant Director
as the
; Executive Assistant Director
in section 2204(a)(2), by striking as the
and inserting Assistant Director
as the
; Executive Assistant Director
in section 2209—
by striking subsection (a);
by redesignating subsections (b) through subsection (o) as subsections (a) through (n), respectively;
in subsection (c)(1)—
in subparagraph (A)(iii), as so redesignated, by striking , as that term is defined under section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4))
; and
in subparagraph (B)(ii), by striking information sharing and analysis organizations
and inserting Information Sharing and Analysis Organizations
;
in subsection (d), as so redesignated—
in the matter preceding paragraph (1), by striking subsection (c)
and inserting subsection (b)
; and
in paragraph (1)(E)(ii)(II), by striking information sharing and analysis organizations
and inserting Information Sharing and Analysis Organizations
;
in subsection (j), as so redesignated, by striking subsection (c)(8)
and inserting subsection (b)(8)
; and
in subsection (n), as so redesignated—
in paragraph (2)(A), by striking subsection (c)(12)
and inserting subsection (b)(12)
; and
in paragraph (3)(B)(i), by striking subsection (c)(12)
and inserting subsection (b)(12)
;
in section 2210—
by striking subsection (a);
by redesignating subsections (b) through (d) as subsections (a) through (c), respectively;
in subsection (b), as so redesignated—
by striking information sharing and analysis organizations (as defined in section 2222(5))
and inserting Information Sharing and Analysis Organizations
; and
by striking (as defined in section 2209)
; and
in subsection (c), as so redesignated, by striking subsection (c)
and inserting subsection (b)
;
in section 2211, by striking subsection (h);
in section 2212, by striking information sharing and analysis organizations (as defined in section 2222(5))
and inserting Information Sharing and Analysis Organizations
;
in section 2213—
by striking subsection (a);
by redesignating subsections (b) through (f) as subsections (a) through (e); respectively;
in subsection (b), as so redesignated, by striking subsection (b)
each place it appears and inserting subsection (a)
;
in subsection (c), as so redesignated, in the matter preceding paragraph (1), by striking subsection (b)
and inserting subsection (a)
; and
in subsection (d), as so redesignated—
in paragraph (1)—
in the matter preceding subparagraph (A), by striking subsection (c)(2)
and inserting subsection (b)(2)
;
in subparagraph (A), by striking subsection (c)(1)
and inserting subsection (b)(1)
; and
in subparagraph (B), by striking subsection (c)(2)
and inserting subsection (b)(2)
; and
in paragraph (2), by striking subsection (c)(2)
and inserting subsection (b)(2)
;
in section 2216, as so redesignated—
in subsection (d)(2), by striking information sharing and analysis organizations
and inserting Information Sharing and Analysis Organizations
; and
by striking subsection (f) and inserting the following:
Cyber defense operation defined
In this section, the term cyber defense operation means the use of a defensive measure.
;
in section 2218(c)(4)(A), as so redesignated, by striking information sharing and analysis organizations
and inserting Information Sharing and Analysis Organizations
; and
in section 2222—
by striking paragraphs (3), (5), and (8);
by redesignating paragraph (4) as paragraph (3); and
by redesignating paragraphs (6) and (7) as paragraphs (4) and (5), respectively.
Table of contents amendments
The table of contents in section 1(b) of the Homeland Security Act of 2002 (Public Law 107–296; 116 Stat. 2135) is amended—
by inserting before the item relating to subtitle A of title XXII the following:
Sec. 2200. Definitions.
;
by striking the item relating to section 2201 and insert the following:
; and
by striking the item relating to section 2214 and all that follows through the item relating to section 2217 and inserting the following:
Sec. 2214. National Asset Database.
Sec. 2215. Duties and authorities relating to .gov internet domain.
Sec. 2216. Joint Cyber Planning Office.
Sec. 2217. Cybersecurity State Coordinator.
Sec. 2218. Sector Risk Management Agencies.
Sec. 2219. Cybersecurity Advisory Committee.
Sec. 2220. Cybersecurity Education and Training Programs.
.
Cybersecurity Act of 2015 definitions
Section 102 of the Cybersecurity Act of 2015 (6 U.S.C. 1501) is amended—
by striking paragraphs (4) through (7) and inserting the following:
Cybersecurity purpose
The term cybersecurity purpose has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
Cybersecurity threat
The term cybersecurity threat has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
Cyber threat indicator
The term cyber threat indicator has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
Defensive measure
The term defensive measure has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
;
by striking paragraph (13) and inserting the following:
Monitor
The term monitor has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
; and
by striking paragraphs (16) and (17) and inserting the following:
Security control
The term security control has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
Security vulnerability
The term security vulnerability has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
.
Additional technical and conforming amendments
Federal Cybersecurity Enhancement Act of 2015
The Federal Cybersecurity Enhancement Act of 2015 (6 U.S.C. 1521 et seq.) is amended—
in section 222 (6 U.S.C. 1521)—
in paragraph (2), by striking section 2210
and inserting section 2200
; and
in paragraph (4), by striking section 2209
and inserting section 2200
;
in section 223(b) (6 U.S.C. 151 note), by striking section 2213(b)(1)
each place it appears and inserting section 2213(a)(1)
;
in section 226 (6 U.S.C. 1524)—
in subsection (a)—
in paragraph (1), by striking section 2213
and inserting section 2200
;
in paragraph (2), by striking section 102
and inserting section 2200 of the Homeland Security Act of 2002
;
in paragraph (4), by striking section 2210(b)(1)
and inserting section 2210(a)(1)
; and
in paragraph (5), by striking section 2213(b)
and inserting section 2213(a)
; and
in subsection (c)(1)(A)(vi), by striking section 2213(c)(5)
and inserting section 2213(b)(5)
; and
in section 227(b) (6 U.S.C. 1525(b)), by striking section 2213(d)(2)
and inserting section 2213(c)(2)
.
Public Health Service Act
Section 2811(b)(4)(D) of the Public Health Service Act (42 U.S.C. 300hh–10(b)(4)(D)) is amended by striking section 228(c) of the Homeland Security Act of 2002 (6 U.S.C. 149(c))
and inserting section 2210(b) of the Homeland Security Act of 2002 (6 U.S.C. 660(b))
.
William M. (Mac) Thornberry National Defense Authorization Act of Fiscal Year 2021
Section 9002 of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (6 U.S.C. 652a) is amended—
in subsection (a)—
in paragraph (5), by striking section 2222(5) of the Homeland Security Act of 2002 (6 U.S.C. 671(5))
and inserting section 2200 of the Homeland Security Act of 2002
; and
by amending paragraph (7) to read as follows:
Sector Risk Management Agency
The term Sector Risk Management Agency has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
;
in subsection (c)(3)(B), by striking section 2201(5)
and inserting section 2200
; and
in subsection (d)—
by striking section 2215
and inserting 2218
; and
by striking , as added by this section
.
National Security Act of 1947
Section 113B of the National Security Act of 1947 (50 U.S.C. 3049a(b)(4)) is amended by striking section 226 of the Homeland Security Act of 2002 (6 U.S.C. 147)
and inserting section 2208 of the Homeland Security Act of 2002 (6 U.S.C. 658)
.
IoT Cybersecurity Improvement Act of 2020
Section 5(b)(3) of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c) is amended by striking section 2209(m) of the Homeland Security Act of 2002 (6 U.S.C. 659(m))
and inserting section 2209(l) of the Homeland Security Act of 2002 (6 U.S.C. 659(l))
.
Small Business Act
Section 21(a)(8)(B) of the Small Business Act (15 U.S.C. 648(a)(8)(B)) is amended by striking section 2209(a)
and inserting section 2200
.
Title 46
Section 70101(2) of title 46, United States Code, is amended by striking section 227 of the Homeland Security Act of 2002 (6 U.S.C. 148)
and inserting section 2200 of the Homeland Security Act of 2002
.
December 13, 2022
Reported with an amendment