Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · STATUTE-COMPILATIONS · National Defense Authorization Act for Fiscal Year 2022 · Sec. 1548

Sec. 1548. CYBERSENTRY PROGRAM OF THE CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY

896 words·~4 min read·/statute-compilations/comps-16861/sec-1548

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

## SEC. 1548 CYBERSENTRY PROGRAM OF THE CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY ###
(a)In General Title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651 et seq.) is further amended by adding at the end the following new section: > > ## “SEC. 2220C CYBERSENTRY PROGRAM > > **[**[6 U.S.C. 665i](/us/usc/t6/s665i)**]** > > > ### “(a) Establishment > > There is established in the Agency a program, to be known as ‘CyberSentry’, to provide continuous monitoring and detection of cybersecurity risks to critical infrastructure entities that own or operate industrial control systems that support national critical functions, upon request and subject to the consent of such owner or operator. > > > ### “(b) Activities > > The Director, through CyberSentry, shall— > > > #### “(1) > > enter into strategic partnerships with critical infrastructure owners and operators that, in the determination of the Director and subject to the availability of resources, own or operate regionally or nationally significant industrial control systems that support national critical functions, in order to provide technical assistance in the form of continuous monitoring of industrial control systems and the information systems that support such systems and detection of cybersecurity risks to such industrial control systems and other cybersecurity services, as appropriate, based on and subject to the agreement and consent of such owner or operator; > > > #### “(2) > > leverage sensitive or classified intelligence about cybersecurity risks regarding particular sectors, particular adversaries, and trends in tactics, techniques, and procedures to advise critical infrastructure owners and operators regarding mitigation measures and share information as appropriate; > > > #### “(3) > > identify cybersecurity risks in the information technology and information systems that support industrial control systems which could be exploited by adversaries attempting to gain access to such industrial control systems, and work with owners and operators to remediate such vulnerabilities; > > > #### “(4) > > produce aggregated, anonymized analytic products, based on threat hunting and continuous monitoring and detection activities and partnerships, with findings and recommendations that can be disseminated to critical infrastructure owners and operators; and > > > #### “(5) > > support activities authorized in accordance with section 1501 of the National Defense Authorization Act for Fiscal Year 2022. > > > ### “(c) Privacy Review > > Not later than 180 days after the date of enactment of this section, the Privacy Officer of the Agency under section 2202(h) shall— > > > #### “(1) > > review the policies, guidelines, and activities of CyberSentry for compliance with all applicable privacy laws, including such laws governing the acquisition, interception, retention, use, and disclosure of communities; and > > > #### “(2) > > submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report certifying compliance with all applicable privacy laws as referred to in paragraph (1), or identifying any instances of noncompliance with such privacy laws. > > > ### “(d) Report to Congress > > Not later than one year after the date of the enactment of this section, the Director shall provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a briefing and written report on implementation of this section. > > > ### “(e) Savings > > Nothing in this section may be construed to permit the Federal Government to gain access to information of a remote computing service provider to the public or an electronic service provider to the public, the disclosure of which is not permitted under section 2702 of title 18, United States Code. > > > ### “(f) Definitions > > In this section: > > > #### “(1) Cybersecurity risk > > The term ‘cybersecurity risk’ has the meaning given such term in section 2209(a). > > > #### “(2) Industrial control system > > The term ‘industrial control system’ means an information system used to monitor and/or control industrial processes such as manufacturing, product handling, production, and distribution, including supervisory control and data acquisition (SCADA) systems used to monitor and/or control geographically dispersed assets, distributed control systems (DCSs), Human-Machine Interfaces (HMIs), and programmable logic controllers that control localized processes. > > > #### “(3) Information system > > The term ‘information system’ has the meaning given such term in section 102 of the Cybersecurity Act of 2015 (enacted as division N of the Consolidated Appropriations Act, 2016 (Public Law 114-113; 6 U.S.C. 1501(9)). > > > ### “(g) Termination > > The authority to carry out a program under this section shall terminate on the date that is seven years after the date of the enactment of this section.” > . ###
(b)Clerical Amendment The table of contents in section 1(b) of the Homeland Security Act of 2002 is further amended by adding after the item relating to section 2220B the following new item:" “Sec. 2220C. CyberSentry program.” ". ###
(c)Continuous Monitoring and Detection Section 2209(c)(6) of the Homeland Security Act of 2002 (6 U.S.C. 659) is amended by inserting “, which may take the form of continuous monitoring and detection of cybersecurity risks to critical infrastructure entities that own or operate industrial control systems that support national critical functions” after “mitigation, and remediation”.
Connectionstraces to 5
Citation graph
cites case law
Sec. 1548
CYBERSENTRY PROGRAM OF THE CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY
Cites 5Cited by 0 across 0 sources
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.