Sec. 2. National Cybersecurity and Communications Integration Center
696 words·~3 min read·
/bill/114/hr/1731/rh/section-2A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Subsection
(a)of the second section 226 of the Homeland Security Act of 2002 ( 6 U.S.C. 148 ; relating to the National Cybersecurity and Communications Integration Center) is amended— in paragraph (3), by striking and at the end; in paragraph (4), by striking the period at the end and inserting ; and ; and by adding at the end the following new paragraphs: the term cyber threat indicator means technical information that is necessary to describe or identify— a method for probing, monitoring, maintaining, or establishing network awareness of an information system for the purpose of discerning technical vulnerabilities of such information system, if such method is known or reasonably suspected of being associated with a known or suspected cybersecurity risk, including communications that reasonably appear to be transmitted for the purpose of gathering technical information related to a cybersecurity risk; a method for defeating a technical or security control of an information system; a technical vulnerability, including anomalous technical behavior that may become a vulnerability; a method of causing a user with legitimate access to an information system or information that is stored on, processed by, or transiting an information system to inadvertently enable the defeat of a technical or operational control; a method for unauthorized remote identification of, access to, or use of an information system or information that is stored on, processed by, or transiting an information system that is known or reasonably suspected of being associated with a known or suspected cybersecurity risk; the actual or potential harm caused by a cybersecurity risk, including a description of the information exfiltrated as a result of a particular cybersecurity risk; any other attribute of a cybersecurity risk that cannot be used to identify specific persons reasonably believed to be unrelated to such cybersecurity risk, if disclosure of such attribute is not otherwise prohibited by law; or any combination of subparagraphs
(A)through (G); the term cybersecurity purpose means the purpose of protecting an information system or information that is stored on, processed by, or transiting an information system from a cybersecurity risk or incident; except as provided in subparagraph (B), the term defensive measure means an action, device, procedure, signature, technique, or other measure applied to an information system or information that is stored on, processed by, or transiting an information system that detects, prevents, or mitigates a known or suspected cybersecurity risk or incident, or any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control; such term does not include a measure that destroys, renders unusable, or substantially harms an information system or data on an information system not belonging to— the non-Federal entity, not including a State, local, or tribal government, operating such measure; or another Federal entity or non-Federal entity that is authorized to provide consent and has provided such consent to the non-Federal entity referred to in clause (i); the term network awareness means to scan, identify, acquire, monitor, log, or analyze information that is stored on, processed by, or transiting an information system; the term private entity means a non-Federal entity that is an individual or private group, organization, proprietorship, partnership, trust, cooperative, corporation, or other commercial or non-profit entity, including an officer, employee, or agent thereof; such term includes a component of a State, local, or tribal government performing electric utility services; the term security control means the management, operational, and technical controls used to protect against an unauthorized effort to adversely affect the confidentially, integrity, or availability of an information system or information that is stored on, processed by, or transiting an information system; and the term sharing means providing, receiving, and disseminating. . Subparagraph
(B)of subsection (d)(1) of such second section 226 of the Homeland Security Act of 2002 is amended— in clause (i), by striking and local and inserting , local, and tribal ; in clause (ii)— by inserting , including information sharing and analysis centers before the semicolon; and by striking and at the end; in clause (iii), by striking the period at the end and inserting ; and ; and by adding at the end the following new clause: private entities. .
Connections1 off-index
1 reference not yet in our index
- 6 USC 148
Citation graph
cites case law
Sec. 2
National Cybersecurity and Communications Integration Center
Cite6 USC 148
Cites 1Cited by 0 across 0 sources