kgrant on DSKB33CYQ1 with PUBLAW
128 STAT. 3068
PUBLIC LAW 113–282—DEC. 18, 2014
‘‘(B) appropriate representatives of non-Federal entities, such as—
‘‘(i) State and local governments;
‘‘(ii) information sharing and analysis organizations; and
‘‘(iii) owners and operators of critical information
systems;
‘‘(C) components within the Center that carry out
cybersecurity and communications activities;
‘‘(D) a designated Federal official for operational
coordination with and across each sector; and
‘‘(E) other appropriate representatives or entities, as
determined by the Secretary.
‘‘(2) INCIDENTS.—In the event of an incident, during exigent
circumstances the Secretary may grant a Federal or non-Federal entity immediate temporary access to the Center.
‘‘(e) PRINCIPLES.—In carrying out the functions under subsection (c), the Center shall ensure—
‘‘(1) to the extent practicable, that—
‘‘(A) timely, actionable, and relevant information
related to cybersecurity risks, incidents, and analysis is
shared;
‘‘(B) when appropriate, information related to cybersecurity risks, incidents, and analysis is integrated with other
relevant information and tailored to the specific characteristics of a sector;
‘‘(C) activities are prioritized and conducted based on
the level of risk;
‘‘(D) industry sector-specific, academic, and national
laboratory expertise is sought and receives appropriate
consideration;
‘‘(E) continuous, collaborative, and inclusive coordination occurs—
‘‘(i) across sectors; and
‘‘(ii) with—
‘‘(I) sector coordinating councils;
‘‘(II) information sharing and analysis
organizations; and
‘‘(III) other appropriate non-Federal partners;
‘‘(F) as appropriate, the Center works to develop and
use mechanisms for sharing information related to cybersecurity risks and incidents that are technology-neutral,
interoperable, real-time, cost-effective, and resilient; and
‘‘(G) the Center works with other agencies to reduce
unnecessarily duplicative sharing of information related
to cybersecurity risks and incidents;
‘‘(2) that information related to cybersecurity risks and
incidents is appropriately safeguarded against unauthorized
access; and
‘‘(3) that activities conducted by the Center comply with
all policies, regulations, and laws that protect the privacy and
civil liberties of United States persons.
‘‘(f) NO RIGHT OR BENEFIT.—
‘‘(1) IN GENERAL.—The provision of assistance or information to, and inclusion in the Center of, governmental or private
entities under this section shall be at the sole and unreviewable
VerDate Mar 15 2010
21:01 Feb 12, 2015
Jkt 049139
PO 00282
Frm 00004
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL282.113
PUBL282