Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 117th Congress · S. 2377 (Reported in Senate) — To invest in the energy and outdoor infrastructure of the United States to deploy new and innovative technologies, up... · Sec. 1106

Sec. 1106. Cybersecurity plan

372 words·~2 min read·/bill/117/s/2377/rs/section-1106·

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

The Secretary may require, as the Secretary determines appropriate, a recipient of any award or other funding under this Act— to submit to the Secretary, prior to the issuance of the award or other funding, a cybersecurity plan that demonstrates the cybersecurity maturity of the recipient in the context of the project for which that award or other funding was provided; and establish a plan for maintaining and improving cybersecurity throughout the life of the proposed solution of the project. A cybersecurity plan described in subsection
(a)shall, at a minimum, describe how the recipient described in that subsection— plans to maintain cybersecurity between networks, systems, devices, applications, or components— within the proposed solution of the project; and at the necessary external interfaces at the proposed solution boundaries; will perform ongoing evaluation of cybersecurity risks to address issues as the issues arise throughout the life of the proposed solution; will report known or suspected network or system compromises of the project to the Secretary; and will leverage applicable cybersecurity programs of the Department, including cyber vulnerability testing and security engineering evaluations. Each recipient described in subsection
(a)should— maximize the use of open guidance and standards, including, wherever possible— the Cybersecurity Capability Maturity Model of the Department (or a successor model); and the Framework for Improving Critical Infrastructure Cybersecurity of the National Institute of Standards and Technology; and document — any deviation from open standards; and the utilization of proprietary standards where the recipient determines that such deviation necessary. The Office of Cybersecurity, Energy Security, and Emergency Response of the Department shall review each cybersecurity plan submitted under subsection
(a)to ensure integration with Department research, development, and demonstration programs. Information provided to, or collected by, the Federal Government pursuant to this section the disclosure of which the Secretary reasonably foresees could be detrimental to the physical security or cybersecurity of any electric utility or the bulk-power system— shall be exempt from disclosure under section 552(b)(3) of title 5, United States Code; and shall not be made available by any Federal agency, State, political subdivision of a State, or Tribal authority pursuant to any Federal, State, political subdivision of a State, or Tribal law, respectively, requiring public disclosure of information or records.
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.