128 STAT. 2972 PUBLIC LAW 113–274—DEC. 18, 2014 and activities, including computer network operations, information assurance, law enforcement, diplomacy, military, and intelligence missions as such activities relate to the security and stability of cyberspace. (2) INFORMATION SYSTEM.—The term ‘‘information system’’ has the meaning given that term in section 3502 of title 44, United States Code. 15 USC 7422. SEC. 3. NO REGULATORY AUTHORITY. Nothing in this Act shall be construed to confer any regulatory authority on any Federal, State, tribal, or local department or agency. 15 USC 7423. SEC. 4. NO ADDITIONAL FUNDS AUTHORIZED. No additional funds are authorized to carry out this Act, and the amendments made by this Act. This Act, and the amendments made by this Act, shall be carried out using amounts otherwise authorized or appropriated. TITLE I—PUBLIC-PRIVATE COLLABORATION ON CYBERSECURITY SEC. 101. PUBLIC-PRIVATE COLLABORATION ON CYBERSECURITY. Coordination. dkrause on DSKHT7XVN1PROD with PUBLAWS Consultation. VerDate Mar 15 2010 07:01 Mar 03, 2015 (a) CYBERSECURITY.—Section 2(c) of the National Institute of Standards and Technology Act (15 U.S.C. 272(c)) is amended— (1) by redesignating paragraphs (15) through (22) as paragraphs (16) through (23), respectively; and (2) by inserting after paragraph (14) the following: ‘‘(15) on an ongoing basis, facilitate and support the development of a voluntary, consensus-based, industry-led set of standards, guidelines, best practices, methodologies, procedures, and processes to cost-effectively reduce cyber risks to critical infrastructure (as defined under subsection (e));’’. (b) SCOPE AND LIMITATIONS.—Section 2 of the National Institute of Standards and Technology Act (15 U.S.C. 272) is amended by adding at the end the following: ‘‘(e) CYBER RISKS.— ‘‘(1) IN GENERAL.—In carrying out the activities under subsection (c)(15), the Director— ‘‘(A) shall— ‘‘(i) coordinate closely and regularly with relevant private sector personnel and entities, critical infrastructure owners and operators, and other relevant industry organizations, including Sector Coordinating Councils and Information Sharing and Analysis Centers, and incorporate industry expertise; ‘‘(ii) consult with the heads of agencies with national security responsibilities, sector-specific agencies and other appropriate agencies, State and local governments, the governments of other nations, and international organizations; ‘‘(iii) identify a prioritized, flexible, repeatable, performance-based, and cost-effective approach, including information security measures and controls, Jkt 049139 PO 00274 Frm 00002 Fmt 6580 Sfmt 6581 E:\PUBLAW\PUBL274.113 PUBL274

Select target paragraph3