Sec. 5. Privacy and Civil Liberties Protections. (a) Agencies shall coordinate their activities
under this order with their senior agency officials for privacy and civil liberties and ensure
that privacy and civil liberties protections are incorporated into such activities. Such
protections shall be based upon the Fair Information Practice Principles and other privacy
and civil liberties policies, principles, and frameworks as they apply to each agency's
activities.
(b) The Chief Privacy Officer and the Officer for Civil Rights and Civil Liberties of the
Department of Homeland Security (DHS) shall assess the privacy and civil liberties risks
of the functions and programs undertaken by DHS as called for in this order and shall
recommend to the Secretary ways to minimize or mitigate such risks, in a publicly
available report, to be released within 1 year of the date of this order. Senior agency
privacy and civil liberties officials for other agencies engaged in activities under this order
shall conduct assessments of their agency activities and provide those assessments to
DHS for consideration and inclusion in the report. The report shall be reviewed on an
annual basis and revised as necessary. The report may contain a classified annex if
necessary. Assessments shall include evaluation of activities against the Fair Information
Practice Principles and other applicable privacy and civil liberties policies, principles, and
frameworks. Agencies shall consider the assessments and recommendations of the report
in implementing privacy and civil liberties protections for agency activities.
(c) In producing the report required under subsection (b) of this section, the Chief Privacy
Officer and the Officer for Civil Rights and Civil Liberties of DHS shall consult with the
Privacy and Civil Liberties Oversight Board and coordinate with the Office of
Management and Budget (OMB).
(d) Information submitted voluntarily in accordance with 6 U.S.C. 133 by private entities
under this order shall be protected from disclosure to the fullest extent permitted by law.
Sec. 6. Consultative Process. The Secretary shall establish a consultative process to
coordinate improvements to the cybersecurity of critical infrastructure. As part of the
consultative process, the Secretary shall engage and consider the advice, on matters set
forth in this order, of the Critical Infrastructure Partnership Advisory Council; Sector
Coordinating Councils; critical infrastructure owners and operators; Sector-Specific
Agencies; other relevant agencies; independent regulatory agencies; State, local,
territorial, and tribal governments; universities; and outside experts.
Sec. 7. Baseline Framework to Reduce Cyber Risk to Critical Infrastructure. (a) The
Secretary of Commerce shall direct the Director of the National Institute of Standards and
Technology (the "Director") to lead the development of a framework to reduce cyber risks
to critical infrastructure (the "Cybersecurity Framework"). The Cybersecurity Framework
shall include a set of standards, methodologies, procedures, and processes that align
policy, business, and technological approaches to address cyber risks. The Cybersecurity
Framework shall incorporate voluntary consensus standards and industry best practices
to the fullest extent possible. The Cybersecurity Framework shall be consistent with
voluntary international standards when such international standards will advance the
3/8