PUBLIC LAW 115–278—NOV. 16, 2018 132 STAT. 4169 ‘‘(C) assessing potential cybersecurity risks to a sector or region, including potential cascading effects, and developing courses of action to mitigate such risks; ‘‘(D) facilitating information sharing and operational coordination with threat response; and ‘‘(E) providing guidance on how best to utilize Federal resources and capabilities in a timely, effective manner to speed recovery from cybersecurity risks. ‘‘(5) SECTOR-SPECIFIC AGENCY.—The term ‘Sector-Specific Agency’ means a Federal department or agency, designated by law or presidential directive, with responsibility for providing institutional knowledge and specialized expertise of a sector, as well as leading, facilitating, or supporting programs and associated activities of its designated critical infrastructure sector in the all hazards environment in coordination with the Department. ‘‘(6) SHARING.—The term ‘sharing’ has the meaning given the term in section 2209. ralbany on LAP520R082 with PUB LAWS PDF ‘‘SEC. 2202. CYBERSECURITY AGENCY. AND INFRASTRUCTURE SECURITY ‘‘(a) REDESIGNATION.— ‘‘(1) IN GENERAL.—The National Protection and Programs Directorate of the Department shall, on and after the date of the enactment of this subtitle, be known as the ‘Cybersecurity and Infrastructure Security Agency’ (in this subtitle referred to as the ‘Agency’). ‘‘(2) REFERENCES.—Any reference to the National Protection and Programs Directorate of the Department in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Cybersecurity and Infrastructure Security Agency of the Department. ‘‘(b) DIRECTOR.— ‘‘(1) IN GENERAL.—The Agency shall be headed by a Director of Cybersecurity and Infrastructure Security (in this subtitle referred to as the ‘Director’), who shall report to the Secretary. ‘‘(2) REFERENCE.—Any reference to an Under Secretary responsible for overseeing critical infrastructure protection, cybersecurity, and any other related program of the Department as described in section 103(a)(1)(H) as in effect on the day before the date of enactment of this subtitle in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Director of Cybersecurity and Infrastructure Security of the Department. ‘‘(c) RESPONSIBILITIES.—The Director shall— ‘‘(1) lead cybersecurity and critical infrastructure security programs, operations, and associated policy for the Agency, including national cybersecurity asset response activities; ‘‘(2) coordinate with Federal entities, including Sector-Specific Agencies, and non-Federal entities, including international entities, to carry out the cybersecurity and critical infrastructure activities of the Agency, as appropriate; ‘‘(3) carry out the responsibilities of the Secretary to secure Federal information and information systems consistent with law, including subchapter II of chapter 35 of title 44, United States Code, and the Cybersecurity Act of 2015 (contained VerDate Sep 11 2014 03:28 Aug 28, 2019 Jkt 089139 PO 00278 Frm 00003 Fmt 6580 Sfmt 6581 E:\PUBLAW\PUBL278.115 6 USC 652. Coordination. PUBL278

Select target paragraph3