dkrause on DSKHT7XVN1PROD with PUBLAWS
PUBLIC LAW 113–274—DEC. 18, 2014
128 STAT. 2973
that may be voluntarily adopted by owners and operators of critical infrastructure to help them identify,
assess, and manage cyber risks;
‘‘(iv) include methodologies—
‘‘(I) to identify and mitigate impacts of the
cybersecurity measures or controls on business
confidentiality; and
‘‘(II) to protect individual privacy and civil liberties;
‘‘(v) incorporate voluntary consensus standards and
industry best practices;
‘‘(vi) align with voluntary international standards
to the fullest extent possible;
‘‘(vii) prevent duplication of regulatory processes
and prevent conflict with or superseding of regulatory
requirements, mandatory standards, and related processes; and
‘‘(viii) include such other similar and consistent
elements as the Director considers necessary; and
‘‘(B) shall not prescribe or otherwise require—
‘‘(i) the use of specific solutions;
‘‘(ii) the use of specific information or communications technology products or services; or
‘‘(iii) that information or communications technology products or services be designed, developed,
or manufactured in a particular manner.
‘‘(2) LIMITATION.—Information shared with or provided to
the Institute for the purpose of the activities described under
subsection (c)(15) shall not be used by any Federal, State,
tribal, or local department or agency to regulate the activity
of any entity. Nothing in this paragraph shall be construed
to modify any regulatory requirement to report or submit
information to a Federal, State, tribal, or local department
or agency.
‘‘(3) DEFINITIONS.—In this subsection:
‘‘(A) CRITICAL INFRASTRUCTURE.—The term ‘critical
infrastructure’ has the meaning given the term in section
1016(e) of the USA PATRIOT Act of 2001 (42 U.S.C.
5195c(e)).
‘‘(B) SECTOR-SPECIFIC AGENCY.—The term ‘sector-specific agency’ means the Federal department or agency
responsible for providing institutional knowledge and
specialized expertise as well as leading, facilitating, or
supporting the security and resilience programs and associated activities of its designated critical infrastructure sector
in the all-hazards environment.’’.
(c) STUDY AND REPORTS.—
(1) STUDY.—The Comptroller General of the United States
shall conduct a study that assesses—
(A) the progress made by the Director of the National
Institute of Standards and Technology in facilitating the
development of standards and procedures to reduce cyber
risks to critical infrastructure in accordance with section
2(c)(15) of the National Institute of Standards and Technology Act, as added by this section;
(B) the extent to which the Director’s facilitation efforts
are consistent with the directive in such section that the
VerDate Mar 15 2010
07:01 Mar 03, 2015
Jkt 049139
PO 00274
Frm 00003
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL274.113
PUBL274