PUBLIC LAW 115–278—NOV. 16, 2018
132 STAT. 4169
‘‘(C) assessing potential cybersecurity risks to a sector
or region, including potential cascading effects, and developing courses of action to mitigate such risks;
‘‘(D) facilitating information sharing and operational
coordination with threat response; and
‘‘(E) providing guidance on how best to utilize Federal
resources and capabilities in a timely, effective manner
to speed recovery from cybersecurity risks.
‘‘(5) SECTOR-SPECIFIC AGENCY.—The term ‘Sector-Specific
Agency’ means a Federal department or agency, designated
by law or presidential directive, with responsibility for providing
institutional knowledge and specialized expertise of a sector,
as well as leading, facilitating, or supporting programs and
associated activities of its designated critical infrastructure
sector in the all hazards environment in coordination with
the Department.
‘‘(6) SHARING.—The term ‘sharing’ has the meaning given
the term in section 2209.
ralbany on LAP520R082 with PUB LAWS PDF
‘‘SEC.
2202.
CYBERSECURITY
AGENCY.
AND
INFRASTRUCTURE
SECURITY
‘‘(a) REDESIGNATION.—
‘‘(1) IN GENERAL.—The National Protection and Programs
Directorate of the Department shall, on and after the date
of the enactment of this subtitle, be known as the ‘Cybersecurity
and Infrastructure Security Agency’ (in this subtitle referred
to as the ‘Agency’).
‘‘(2) REFERENCES.—Any reference to the National Protection
and Programs Directorate of the Department in any law, regulation, map, document, record, or other paper of the United
States shall be deemed to be a reference to the Cybersecurity
and Infrastructure Security Agency of the Department.
‘‘(b) DIRECTOR.—
‘‘(1) IN GENERAL.—The Agency shall be headed by a Director
of Cybersecurity and Infrastructure Security (in this subtitle
referred to as the ‘Director’), who shall report to the Secretary.
‘‘(2) REFERENCE.—Any reference to an Under Secretary
responsible for overseeing critical infrastructure protection,
cybersecurity, and any other related program of the Department
as described in section 103(a)(1)(H) as in effect on the day
before the date of enactment of this subtitle in any law, regulation, map, document, record, or other paper of the United
States shall be deemed to be a reference to the Director of
Cybersecurity and Infrastructure Security of the Department.
‘‘(c) RESPONSIBILITIES.—The Director shall—
‘‘(1) lead cybersecurity and critical infrastructure security
programs, operations, and associated policy for the Agency,
including national cybersecurity asset response activities;
‘‘(2) coordinate with Federal entities, including Sector-Specific Agencies, and non-Federal entities, including international
entities, to carry out the cybersecurity and critical infrastructure activities of the Agency, as appropriate;
‘‘(3) carry out the responsibilities of the Secretary to secure
Federal information and information systems consistent with
law, including subchapter II of chapter 35 of title 44, United
States Code, and the Cybersecurity Act of 2015 (contained
VerDate Sep 11 2014
03:28 Aug 28, 2019
Jkt 089139
PO 00278
Frm 00003
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL278.115
6 USC 652.
Coordination.
PUBL278