Federal Register / Vol. 78, No. 33 / Tuesday, February 19, 2013 / Presidential Documents
11741
Institute of Standards and Technology (the ‘‘Director’’) to lead the development of a framework to reduce cyber risks to critical infrastructure (the
‘‘Cybersecurity Framework’’). The Cybersecurity Framework shall include
a set of standards, methodologies, procedures, and processes that align policy,
business, and technological approaches to address cyber risks. The Cybersecurity Framework shall incorporate voluntary consensus standards and industry
best practices to the fullest extent possible. The Cybersecurity Framework
shall be consistent with voluntary international standards when such international standards will advance the objectives of this order, and shall meet
the requirements of the National Institute of Standards and Technology
Act, as amended (15 U.S.C. 271 et seq.), the National Technology Transfer
and Advancement Act of 1995 (Public Law 104–113), and OMB Circular
A–119, as revised.
(b) The Cybersecurity Framework shall provide a prioritized, flexible,
repeatable, performance-based, and cost-effective approach, including information security measures and controls, to help owners and operators of
critical infrastructure identify, assess, and manage cyber risk. The Cybersecurity Framework shall focus on identifying cross-sector security standards
and guidelines applicable to critical infrastructure. The Cybersecurity Framework will also identify areas for improvement that should be addressed
through future collaboration with particular sectors and standards-developing
organizations. To enable technical innovation and account for organizational
differences, the Cybersecurity Framework will provide guidance that is technology neutral and that enables critical infrastructure sectors to benefit from
a competitive market for products and services that meet the standards,
methodologies, procedures, and processes developed to address cyber risks.
The Cybersecurity Framework shall include guidance for measuring the performance of an entity in implementing the Cybersecurity Framework.
(c) The Cybersecurity Framework shall include methodologies to identify
and mitigate impacts of the Cybersecurity Framework and associated information security measures or controls on business confidentiality, and to protect
individual privacy and civil liberties.
(d) In developing the Cybersecurity Framework, the Director shall engage
in an open public review and comment process. The Director shall also
consult with the Secretary, the National Security Agency, Sector-Specific
Agencies and other interested agencies including OMB, owners and operators
of critical infrastructure, and other stakeholders through the consultative
process established in section 6 of this order. The Secretary, the Director
of National Intelligence, and the heads of other relevant agencies shall
provide threat and vulnerability information and technical expertise to inform
the development of the Cybersecurity Framework. The Secretary shall provide
performance goals for the Cybersecurity Framework informed by work under
section 9 of this order.
srobinson on DSK4SPTVN1PROD with MISCELLANEOUS
(e) Within 240 days of the date of this order, the Director shall publish
a preliminary version of the Cybersecurity Framework (the ‘‘preliminary
Framework’’). Within 1 year of the date of this order, and after coordination
with the Secretary to ensure suitability under section 8 of this order, the
Director shall publish a final version of the Cybersecurity Framework (the
‘‘final Framework’’).
(f) Consistent with statutory responsibilities, the Director will ensure the
Cybersecurity Framework and related guidance is reviewed and updated
as necessary, taking into consideration technological changes, changes in
cyber risks, operational feedback from owners and operators of critical infrastructure, experience from the implementation of section 8 of this order,
and any other relevant factors.
Sec. 8. Voluntary Critical Infrastructure Cybersecurity Program. (a) The Secretary, in coordination with Sector-Specific Agencies, shall establish a voluntary program to support the adoption of the Cybersecurity Framework
by owners and operators of critical infrastructure and any other interested
entities (the ‘‘Program’’).
VerDate Mar<15>2010
18:55 Feb 15, 2013
Jkt 229001
PO 00000
Frm 00005
Fmt 4705
Sfmt 4790
E:\FR\FM\19FEE0.SGM
19FEE0