Sec. 8. Voluntary Critical Infrastructure Cybersecurity Program. (a) The Secretary, in
coordination with Sector-Specific Agencies, shall establish a voluntary program to
support the adoption of the Cybersecurity Framework by owners and operators of critical
infrastructure and any other interested entities (the "Program").
(b) Sector-Specific Agencies, in consultation with the Secretary and other interested
agencies, shall coordinate with the Sector Coordinating Councils to review the
Cybersecurity Framework and, if necessary, develop implementation guidance or
supplemental materials to address sector-specific risks and operating environments.
(c) Sector-Specific Agencies shall report annually to the President, through the Secretary,
on the extent to which owners and operators notified under section 9 of this order are
participating in the Program.
(d) The Secretary shall coordinate establishment of a set of incentives designed to
promote participation in the Program. Within 120 days of the date of this order, the
Secretary and the Secretaries of the Treasury and Commerce each shall make
recommendations separately to the President, through the Assistant to the President for
Homeland Security and Counterterrorism and the Assistant to the President for Economic
Affairs, that shall include analysis of the benefits and relative effectiveness of such
incentives, and whether the incentives would require legislation or can be provided under
existing law and authorities to participants in the Program.
(e) Within 120 days of the date of this order, the Secretary of Defense and the
Administrator of General Services, in consultation with the Secretary and the Federal
Acquisition Regulatory Council, shall make recommendations to the President, through
the Assistant to the President for Homeland Security and Counterterrorism and the
Assistant to the President for Economic Affairs, on the feasibility, security benefits, and
relative merits of incorporating security standards into acquisition planning and contract
administration. The report shall address what steps can be taken to harmonize and make
consistent existing procurement requirements related to cybersecurity.
Sec. 9. Identification of Critical Infrastructure at Greatest Risk. (a) Within 150 days of the
date of this order, the Secretary shall use a risk-based approach to identify critical
infrastructure where a cybersecurity incident could reasonably result in catastrophic
regional or national effects on public health or safety, economic security, or national
security. In identifying critical infrastructure for this purpose, the Secretary shall use the
consultative process established in section 6 of this order and draw upon the expertise of
Sector-Specific Agencies. The Secretary shall apply consistent, objective criteria in
identifying such critical infrastructure. The Secretary shall not identify any commercial
information technology products or consumer information technology services under this
section. The Secretary shall review and update the list of identified critical infrastructure
under this section on an annual basis, and provide such list to the President, through the
Assistant to the President for Homeland Security and Counterterrorism and the Assistant
to the President for Economic Affairs.
5/8