128 STAT. 3070 PUBLIC LAW 113–282—DEC. 18, 2014 (4) the average length of time taken to resolve requests described in paragraph (3); (5) the identification of— (A) any delay in resolving requests described in paragraph (3) involving security clearance processing; and (B) the agency involved with a delay described in subparagraph (A); (6) a description of any other obstacles or challenges to resolving requests described in paragraph (3) and a summary of the reasons for denials of any such requests; (7) the extent to which the Department is engaged in information sharing with each critical infrastructure sector, including— (A) the extent to which each sector has representatives at the Center; (B) the extent to which owners and operators of critical infrastructure in each critical infrastructure sector participate in information sharing at the Center; and (C) the volume and range of activities with respect to which the Secretary has collaborated with the sector coordinating councils and the sector-specific agencies to promote greater engagement with the Center; and (8) the policies and procedures established by the Center to safeguard privacy and civil liberties. SEC. 6. GAO REPORT. Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the effectiveness of the Center in carrying out its cybersecurity mission. SEC. 7. CYBER INCIDENT RESPONSE PLAN; CLEARANCES; BREACHES. (a) CYBER INCIDENT RESPONSE PLAN; CLEARANCES.—Subtitle C of title II of the Homeland Security Act of 2002 (6 U.S.C. 141 et seq.), as amended by section 3, is amended by adding at the end the following: 6 USC 149. ‘‘SEC. 227. CYBER INCIDENT RESPONSE PLAN. ‘‘The Under Secretary appointed under section 103(a)(1)(H) shall, in coordination with appropriate Federal departments and agencies, State and local governments, sector coordinating councils, information sharing and analysis organizations (as defined in section 212(5)), owners and operators of critical infrastructure, and other appropriate entities and individuals, develop, regularly update, maintain, and exercise adaptable cyber incident response plans to address cybersecurity risks (as defined in section 226) to critical infrastructure. kgrant on DSKB33CYQ1 with PUBLAW 6 USC 150. ‘‘SEC. 228. CLEARANCES. ‘‘The Secretary shall make available the process of application for security clearances under Executive Order 13549 (75 Fed. Reg. 162; relating to a classified national security information program) or any successor Executive Order to appropriate representatives VerDate Mar 15 2010 21:01 Feb 12, 2015 Jkt 049139 PO 00282 Frm 00006 Fmt 6580 Sfmt 6581 E:\PUBLAW\PUBL282.113 PUBL282

Select target paragraph3