objectives of this order, and shall meet the requirements of the National Institute of
Standards and Technology Act, as amended (15 U.S.C. 271 et seq.), the National
Technology Transfer and Advancement Act of 1995 (Public Law 104-113), and OMB
Circular A-119, as revised.
(b) The Cybersecurity Framework shall provide a prioritized, flexible, repeatable,
performance-based, and cost-effective approach, including information security measures
and controls, to help owners and operators of critical infrastructure identify, assess, and
manage cyber risk. The Cybersecurity Framework shall focus on identifying cross-sector
security standards and guidelines applicable to critical infrastructure. The Cybersecurity
Framework will also identify areas for improvement that should be addressed through
future collaboration with particular sectors and standards-developing organizations. To
enable technical innovation and account for organizational differences, the Cybersecurity
Framework will provide guidance that is technology neutral and that enables critical
infrastructure sectors to benefit from a competitive market for products and services that
meet the standards, methodologies, procedures, and processes developed to address cyber
risks. The Cybersecurity Framework shall include guidance for measuring the
performance of an entity in implementing the Cybersecurity Framework.
(c) The Cybersecurity Framework shall include methodologies to identify and mitigate
impacts of the Cybersecurity Framework and associated information security measures or
controls on business confidentiality, and to protect individual privacy and civil liberties.
(d) In developing the Cybersecurity Framework, the Director shall engage in an open
public review and comment process. The Director shall also consult with the Secretary,
the National Security Agency, Sector-Specific Agencies and other interested agencies
including OMB, owners and operators of critical infrastructure, and other stakeholders
through the consultative process established in section 6 of this order. The Secretary, the
Director of National Intelligence, and the heads of other relevant agencies shall provide
threat and vulnerability information and technical expertise to inform the development of
the Cybersecurity Framework. The Secretary shall provide performance goals for the
Cybersecurity Framework informed by work under section 9 of this order.
(e) Within 240 days of the date of this order, the Director shall publish a preliminary
version of the Cybersecurity Framework (the "preliminary Framework"). Within 1 year of
the date of this order, and after coordination with the Secretary to ensure suitability under
section 8 of this order, the Director shall publish a final version of the Cybersecurity
Framework (the "final Framework").
(f) Consistent with statutory responsibilities, the Director will ensure the Cybersecurity
Framework and related guidance is reviewed and updated as necessary, taking into
consideration technological changes, changes in cyber risks, operational feedback from
owners and operators of critical infrastructure, experience from the implementation of
section 8 of this order, and any other relevant factors.
4/8