Sec. 10. CISA agency liaisons
317 words·~1 min read·
/bill/118/s/2251/is/section-10A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than 120 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall assign not less than 1 cybersecurity professional employed by the Cybersecurity and Infrastructure Security Agency to be the Cybersecurity and Infrastructure Security Agency liaison to the Chief Information Security Officer of each agency. Each liaison assigned under subsection
(a)shall have knowledge of— cybersecurity threats facing agencies, including any specific threats to the assigned agency; risk assessments of agency systems; and other Federal cybersecurity initiatives. The duties of each liaison assigned under subsection
(a)shall include— providing, as requested, assistance and advice to the agency Chief Information Security Officer; supporting, as requested, incident response coordination between the assigned agency and the Cybersecurity and Infrastructure Security Agency; becoming familiar with assigned agency systems, processes, and procedures to better facilitate support to the agency; and other liaison duties to the assigned agency solely in furtherance of Federal cybersecurity or support to the assigned agency as a Sector Risk Management Agency, as assigned by the Director of the Cybersecurity and Infrastructure Security Agency in consultation with the head of the assigned agency. A liaison assigned under subsection
(a)shall not be a contractor. One individual liaison may be assigned to multiple agency Chief Information Security Officers under subsection (a). The Director of the Cybersecurity and Infrastructure Security Agency shall consult with the Director on the execution of the duties of the Cybersecurity and Infrastructure Security Agency liaisons to ensure that there is no inappropriate duplication of activities among— Federal cybersecurity support to agencies of the Office of Management and Budget; and the Cybersecurity and Infrastructure Security Agency liaison. Nothing in this section shall be construed impact the ability of the Director to support agency implementation of Federal cybersecurity requirements pursuant to subchapter II of chapter 35 of title 44, United States Code, as amended by this Act.