H. R. 2029—720 ‘‘(j) REPORTS ON INTERNATIONAL COOPERATION.—Not later than 180 days after the date of enactment of this subsection, and periodically thereafter, the Secretary of Homeland Security shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the range of efforts underway to bolster cybersecurity collaboration with relevant international partners in accordance with subsection (c)(8). ‘‘(k) OUTREACH.—Not later than 60 days after the date of enactment of this subsection, the Secretary, acting through the Under Secretary appointed under section 103(a)(1)(H), shall— ‘‘(1) disseminate to the public information about how to voluntarily share cyber threat indicators and defensive measures with the Center; and ‘‘(2) enhance outreach to critical infrastructure owners and operators for purposes of such sharing. ‘‘(l) COORDINATED VULNERABILITY DISCLOSURE.—The Secretary, in coordination with industry and other stakeholders, may develop and adhere to Department policies and procedures for coordinating vulnerability disclosures.’’. SEC. 204. INFORMATION SHARING AND ANALYSIS ORGANIZATIONS. Section 212 of the Homeland Security Act of 2002 (6 U.S.C. 131) is amended— (1) in paragraph (5)— (A) in subparagraph (A)— (i) by inserting ‘‘, including information related to cybersecurity risks and incidents,’’ after ‘‘critical infrastructure information’’; and (ii) by inserting ‘‘, including cybersecurity risks and incidents,’’ after ‘‘related to critical infrastructure’’; (B) in subparagraph (B)— (i) by inserting ‘‘, including cybersecurity risks and incidents,’’ after ‘‘critical infrastructure information’’; and (ii) by inserting ‘‘, including cybersecurity risks and incidents,’’ after ‘‘related to critical infrastructure’’; and (C) in subparagraph (C), by inserting ‘‘, including cybersecurity risks and incidents,’’ after ‘‘critical infrastructure information’’; and (2) by adding at the end the following: ‘‘(8) CYBERSECURITY RISK; INCIDENT.—The terms ‘cybersecurity risk’ and ‘incident’ have the meanings given those terms in section 227.’’. SEC. 205. NATIONAL RESPONSE FRAMEWORK. Section 228 of the Homeland Security Act of 2002, as added by section 223(a)(4) of this division, is amended by adding at the end the following: ‘‘(d) NATIONAL RESPONSE FRAMEWORK.—The Secretary, in coordination with the heads of other appropriate Federal departments and agencies, and in accordance with the National Cybersecurity Incident Response Plan required under subsection (c), shall regularly update, maintain, and exercise the Cyber Incident Annex to the National Response Framework of the Department.’’.

Select target paragraph3