11742
Federal Register / Vol. 78, No. 33 / Tuesday, February 19, 2013 / Presidential Documents
(b) Sector-Specific Agencies, in consultation with the Secretary and other
interested agencies, shall coordinate with the Sector Coordinating Councils
to review the Cybersecurity Framework and, if necessary, develop implementation guidance or supplemental materials to address sector-specific risks
and operating environments.
(c) Sector-Specific Agencies shall report annually to the President, through
the Secretary, on the extent to which owners and operators notified under
section 9 of this order are participating in the Program.
(d) The Secretary shall coordinate establishment of a set of incentives
designed to promote participation in the Program. Within 120 days of the
date of this order, the Secretary and the Secretaries of the Treasury and
Commerce each shall make recommendations separately to the President,
through the Assistant to the President for Homeland Security and Counterterrorism and the Assistant to the President for Economic Affairs, that shall
include analysis of the benefits and relative effectiveness of such incentives,
and whether the incentives would require legislation or can be provided
under existing law and authorities to participants in the Program.
srobinson on DSK4SPTVN1PROD with MISCELLANEOUS
(e) Within 120 days of the date of this order, the Secretary of Defense
and the Administrator of General Services, in consultation with the Secretary
and the Federal Acquisition Regulatory Council, shall make recommendations
to the President, through the Assistant to the President for Homeland Security
and Counterterrorism and the Assistant to the President for Economic Affairs,
on the feasibility, security benefits, and relative merits of incorporating
security standards into acquisition planning and contract administration.
The report shall address what steps can be taken to harmonize and make
consistent existing procurement requirements related to cybersecurity.
Sec. 9. Identification of Critical Infrastructure at Greatest Risk. (a) Within
150 days of the date of this order, the Secretary shall use a risk-based
approach to identify critical infrastructure where a cybersecurity incident
could reasonably result in catastrophic regional or national effects on public
health or safety, economic security, or national security. In identifying critical
infrastructure for this purpose, the Secretary shall use the consultative process established in section 6 of this order and draw upon the expertise
of Sector-Specific Agencies. The Secretary shall apply consistent, objective
criteria in identifying such critical infrastructure. The Secretary shall not
identify any commercial information technology products or consumer information technology services under this section. The Secretary shall review
and update the list of identified critical infrastructure under this section
on an annual basis, and provide such list to the President, through the
Assistant to the President for Homeland Security and Counterterrorism and
the Assistant to the President for Economic Affairs.
(b) Heads of Sector-Specific Agencies and other relevant agencies shall
provide the Secretary with information necessary to carry out the responsibilities under this section. The Secretary shall develop a process for other
relevant stakeholders to submit information to assist in making the identifications required in subsection (a) of this section.
(c) The Secretary, in coordination with Sector-Specific Agencies, shall
confidentially notify owners and operators of critical infrastructure identified
under subsection (a) of this section that they have been so identified, and
ensure identified owners and operators are provided the basis for the determination. The Secretary shall establish a process through which owners
and operators of critical infrastructure may submit relevant information and
request reconsideration of identifications under subsection (a) of this section.
Sec. 10. Adoption of Framework. (a) Agencies with responsibility for regulating the security of critical infrastructure shall engage in a consultative
process with DHS, OMB, and the National Security Staff to review the
preliminary Cybersecurity Framework and determine if current cybersecurity
regulatory requirements are sufficient given current and projected risks. In
making such determination, these agencies shall consider the identification
VerDate Mar<15>2010
18:55 Feb 15, 2013
Jkt 229001
PO 00000
Frm 00006
Fmt 4705
Sfmt 4790
E:\FR\FM\19FEE0.SGM
19FEE0