Sec. 402. Systemically Important Critical Infrastructure
368 words·~2 min read·
/bill/117/s/2491/is/section-402A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
The Secretary may designate entities as Systemically Important Critical Infrastructure. Prior to designating any entities as Systemically Important Critical Infrastructure, the Secretary, in consultation with the National Cyber Director, Sector Risk Management Agencies, and appropriate stakeholders shall develop— a methodology for identifying Systemically Important Critical Infrastructure; and criteria for determining whether an entity qualifies as Systemically Important Critical Infrastructure.
In establishing criteria for determining whether an entity qualifies as Systemically Important Critical Infrastructure, the Secretary shall consider— the likelihood that disruption to or compromise of such an entity could cause a debilitating effect on national security, economic security, public health or safety, or any combination thereof; the extent to which damage, disruption, or unauthorized access to such an entity either separately or collectively, will disrupt the reliable operation of other critical infrastructure assets, or impede provisioning of one or more national critical functions; the extent to which national cybersecurity resilience would be enhanced by deeper risk management integration between Systemically Important Critical Infrastructure entities and the Federal Government; and the extent to which compromise or unauthorized access of such an entity could separately or collectively create widespread compromise of the cyber ecosystem, significant portions of critical infrastructure, or multiple critical infrastructure sectors.
Not later than 1 year after the date of enactment of this Act, the Secretary shall complete an initial list of entities designated as Systemically Important Critical Infrastructure. The Secretary shall maintain a comprehensive list of entities designated as Systemically Important Critical Infrastructure, which shall be updated within 7 days of a change in whether an entity qualifies as Systemically Important Critical Infrastructure. Not later than 90 days after designating an entity as Systemically Important Critical Infrastructure or removing the designation of an entity as Systemically Important Critical Infrastructure, the Secretary shall notify the entity.
The Secretary shall— not later than 30 days after the date of any addition, modification, or removal of an entity from the list of Significantly Important Critical Infrastructure maintained under subsection (d), notify the appropriate Congressional committees; and at least every 2 years, submit to the appropriate Congressional committees an updated comprehensive list of entities designated as Systemically Important Critical Infrastructure, in conjunction with each plan required pursuant to section 403.