§ 652a. Sector Risk Management Agencies
1,178 words·~5 min read·
/usc/title-6/section-652aA research copy — for the controlling text, always check the official state or federal source. Not legal advice.
(a)Definitions In this section:
(1)Appropriate congressional committees The term “appropriate congressional committees” means—
(A)the Committee on Homeland Security and the Committee on Armed Services in the House of Representatives; and
(B)the Committee on Homeland Security and Governmental Affairs and the Committee on Armed Services in the Senate.
(2)Critical infrastructure The term “critical infrastructure” has the meaning given that term in section 5195c(e) of title 42.
(3)Department The term “Department” means the Department of Homeland Security.
(4)Director The term “Director” means the Director of the Cybersecurity and Infrastructure Security Agency of the Department.
(5)Secretary The term “Secretary” means the Secretary of Homeland Security.
(7)11 So in original. Probably should be “(6)”. Sector Risk Management Agency The term “Sector Risk Management Agency” has the meaning given the term in section 650 of this title.
(b)Critical infrastructure sector designation
(1)Initial review Not later than 180 days after January 1, 2021, the Secretary, in consultation with the heads of Sector Risk Management Agencies, shall—
(A)review the current framework for securing critical infrastructure, as described in section 652(c)(4) of this title and Presidential Policy Directive 21; and
(B)submit to the President and appropriate congressional committees a report that includes—
(i)information relating to—
(I)the analysis framework or methodology used to—
(aa)evaluate the current framework for securing critical infrastructure referred to in subparagraph (A); and
(bb)develop recommendations to—
(AA)revise the current list of critical infrastructure sectors designated pursuant to Presidential Policy Directive 21, any successor or related document, or policy; or
(BB)identify and designate any subsectors of such sectors;
(II)the data, metrics, and other information used to develop the recommendations required under clause (ii); and
(ii)recommendations relating to—
(I)revising—
(aa)the current framework for securing critical infrastructure referred to in subparagraph (A);
(bb)the current list of critical infrastructure sectors designated pursuant to Presidential Policy Directive 21, any successor or related document, or policy; or
(cc)the identification and designation of any subsectors of such sectors; and
(II)any revisions to the list of designated Federal departments or agencies that serve as the Sector Risk Management Agency for a sector or subsector of such section, necessary to comply with paragraph (3)(B).
(2)Periodic evaluation by the Secretary At least once every five years, the Secretary, in consultation with the Director and the heads of Sector Risk Management Agencies, shall—
(A)evaluate the current list of designated critical infrastructure sectors and subsectors of such sectors and the appropriateness of Sector Risk Management Agency designations, as set forth in Presidential Policy Directive 21, any successor or related document, or policy; and
(B)recommend, as appropriate, to the President—
(i)revisions to the current list of designated critical infrastructure sectors or subsectors of such sectors; and
(ii)revisions to the designation of any Federal department or agency designated as the Sector Risk Management Agency for a sector or subsector of such sector.
(3)Review and revision by the President Not later than 180 days after the Secretary submits a recommendation pursuant to paragraph
(1)or (2), the President shall—
(A)review the recommendation and revise, as appropriate, the designation of a critical infrastructure sector or subsector or the designation of a Sector Risk Management Agency; and
(B)submit to the appropriate congressional committees, the Majority and Minority Leaders of the Senate, and the Speaker and Minority Leader of the House of Representatives, a report that includes—
(i)an explanation with respect to the basis for accepting or rejecting the recommendations of the Secretary; and
(ii)information relating to the analysis framework, methodology, metrics, and data used to—
(I)evaluate the current framework for securing critical infrastructure referred to in paragraph (1)(A); and
(II)develop—
(aa)recommendations to revise—
(AA)the list of critical infrastructure sectors designated pursuant to Presidential Policy Directive 21, any successor or related document, or policy; or
(BB)the designation of any subsectors of such sectors; and
(bb)the recommendations of the Secretary.
(4)Publication Any designation of critical infrastructure sectors shall be published in the Federal Register.
(c)Sector Risk Management Agencies
(1)Omitted
(2)Omitted
(3)References Any reference to a Sector Specific Agency (including any permutations or conjugations thereof) in any law, regulation, map, document, record, or other paper of the United States shall be deemed to—
(A)be a reference to the Sector Risk Management Agency of the relevant critical infrastructure sector; and
(B)have the meaning given such term in section 650 of this title.
(4)Omitted
(d)Report and auditing Not later than two years after January 1, 2021 and every four years thereafter for 12 years, the Comptroller General of the United States shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the effectiveness of Sector Risk Management Agencies in carrying out their responsibilities under section 665d of this title.
(Pub. L. 116–283, div. H, title XC, § 9002, Jan. 1, 2021, 134 Stat. 4768; Pub. L. 117–263, div. G, title LXXI, § 7143(d)(5), Dec. 23, 2022, 136 Stat. 3663.)
Connections36 cite this · traces to 8
Cited by 36 sections · top 34
U.S. Code
public-private-law
register
statute-compilations
- Sec. 1511RESPONSIBILITY FOR CYBERSECURITY AND CRITICAL INFRASTRUCTURE PROTECTION OF DEFENSE INDUSTRIAL BASE
- Sec. 1724RESPONSIBILITY FOR CYBERSECURITY AND CRITICAL INFRASTRUCTURE PROTECTION OF THE DEFENSE INDUSTRIAL BASE
- Sec. 9002SECTOR RISK MANAGEMENT AGENCIES
- Sec. 7143CISA TECHNICAL CORRECTIONS AND IMPROVEMENTS
statutes-at-large
- Public Law 117–263To authorize appropriations for fiscal year 2023 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes
- Public Law 118–31To authorize appropriations for fiscal year 2024 for military activities of the Department of Defense and for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes
- Public Law 116–283To authorize appropriations for fiscal year 2021 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes
bill
- Sec. 4Additional technical and conforming amendments
- Sec. 3Cyber incident reporting
- Sec. 2Rural manufacturing loans
- Sec. 7143CISA technical corrections and improvements
- Sec. 5208GAO review of Department of Homeland Security efforts related to establishing space as a critical infrastructure sector
- Sec. 5208GAO review of Department of Homeland Security efforts related to establishing space as a critical infrastructure sector
- Sec. 7143CISA technical corrections and improvements
- Sec. 4Additional technical and conforming amendments
- Sec. 3Cyber incident reporting
- Sec. 1524Responsibility for cybersecurity and critical infrastructure protection of the defense industrial base
- Sec. 1511Responsibility for cybersecurity and critical infrastructure protection of defense industrial base
- Sec. 1524Responsibility for cybersecurity and critical infrastructure protection of the defense industrial base
- Sec. 1524Responsibility for cybersecurity and critical infrastructure protection of the defense industrial base
- Sec. 2Rural manufacturing loans
- Sec. 2National risk management process
- Sec. 2National risk management cycle
- Sec. 2National risk management cycle
Traces to 8 documents
U.S. Code
2 references not yet in our index
- 134 Stat. 4768
- 136 Stat. 3663
Citation graph
cites case law
§ 652a
Sector Risk Management Agencies
Bills×17
U.S.C.×8
Stat. Comp.×4
Pub. L.×3
Stat.×3
Fed. Reg.×1
Stat.134 Stat. 4768
Stat.136 Stat. 3663
Cites 10Cited by 36 across 6 sources