128 STAT. 3070
PUBLIC LAW 113–282—DEC. 18, 2014
(4) the average length of time taken to resolve requests
described in paragraph (3);
(5) the identification of—
(A) any delay in resolving requests described in paragraph (3) involving security clearance processing; and
(B) the agency involved with a delay described in
subparagraph (A);
(6) a description of any other obstacles or challenges to
resolving requests described in paragraph (3) and a summary
of the reasons for denials of any such requests;
(7) the extent to which the Department is engaged in
information sharing with each critical infrastructure sector,
including—
(A) the extent to which each sector has representatives
at the Center;
(B) the extent to which owners and operators of critical
infrastructure in each critical infrastructure sector participate in information sharing at the Center; and
(C) the volume and range of activities with respect
to which the Secretary has collaborated with the sector
coordinating councils and the sector-specific agencies to
promote greater engagement with the Center; and
(8) the policies and procedures established by the Center
to safeguard privacy and civil liberties.
SEC. 6. GAO REPORT.
Not later than 2 years after the date of enactment of this
Act, the Comptroller General of the United States shall submit
to the Committee on Homeland Security and Governmental Affairs
of the Senate and the Committee on Homeland Security of the
House of Representatives a report on the effectiveness of the Center
in carrying out its cybersecurity mission.
SEC. 7. CYBER INCIDENT RESPONSE PLAN; CLEARANCES; BREACHES.
(a) CYBER INCIDENT RESPONSE PLAN; CLEARANCES.—Subtitle
C of title II of the Homeland Security Act of 2002 (6 U.S.C. 141
et seq.), as amended by section 3, is amended by adding at the
end the following:
6 USC 149.
‘‘SEC. 227. CYBER INCIDENT RESPONSE PLAN.
‘‘The Under Secretary appointed under section 103(a)(1)(H)
shall, in coordination with appropriate Federal departments and
agencies, State and local governments, sector coordinating councils,
information sharing and analysis organizations (as defined in section 212(5)), owners and operators of critical infrastructure, and
other appropriate entities and individuals, develop, regularly
update, maintain, and exercise adaptable cyber incident response
plans to address cybersecurity risks (as defined in section 226)
to critical infrastructure.
kgrant on DSKB33CYQ1 with PUBLAW
6 USC 150.
‘‘SEC. 228. CLEARANCES.
‘‘The Secretary shall make available the process of application
for security clearances under Executive Order 13549 (75 Fed. Reg.
162; relating to a classified national security information program)
or any successor Executive Order to appropriate representatives
VerDate Mar 15 2010
21:01 Feb 12, 2015
Jkt 049139
PO 00282
Frm 00006
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL282.113
PUBL282