central to ensuring the safe operations of these critical systems. The Federal Government
will work with industry to share threat information for priority control system critical
infrastructure throughout the country.
(a) The Initiative began with a pilot effort with the Electricity Subsector, and is now
followed by a similar effort for natural gas pipelines. Efforts for the Water and
Wastewater Sector Systems and Chemical Sector will follow later this year.
(b) Sector Risk Management Agencies, as defined in section 9002(a)(7) of Public Law
116-283, and other executive departments and agencies (agencies), as appropriate and
consistent with applicable law, shall work with critical infrastructure stakeholders and
owners and operators to implement the principles and policy outlined in this
memorandum.
Sec. 4.Critical Infrastructure Cybersecurity Performance Goals. Cybersecurity needs vary
among critical infrastructure sectors, as do cybersecurity practices. However, there is a
need for baseline cybersecurity goals that are consistent across all critical infrastructure
sectors, as well as a need for security controls for select critical infrastructure that is
dependent on control systems.
(a) Pursuant to section 7(d) of Executive Order 13636 of February 12, 2013 (Improving
Critical Infrastructure Cybersecurity), the Secretary of Homeland Security, in
coordination with the Secretary of Commerce (through the Director of the National
Institute of Standards and Technology) and other agencies, as appropriate, shall develop
and issue cybersecurity performance goals for critical infrastructure to further a common
understanding of the baseline security practices that critical infrastructure owners and
operators should follow to protect national and economic security, as well as public health
and safety.
(b) This effort shall begin with the Secretary of Homeland Security issuing preliminary
goals for control systems across critical infrastructure sectors no later than
September 22, 2021, followed by the issuance of final cross-sector control system goals
within 1 year of the date of this memorandum. Additionally, following consultations with
relevant agencies, the Secretary of Homeland Security shall issue sector-specific critical
infrastructure cybersecurity performance goals within 1 year of the date of this
memorandum. These performance goals should serve as clear guidance to owners and
operators about cybersecurity practices and postures that the American people can trust
and should expect for such essential services. That effort may also include an
examination of whether additional legal authorities would be beneficial to enhancing the
cybersecurity of critical infrastructure, which is vital to the American people and the
security of our Nation.
2/3