kgrant on DSKB33CYQ1 with PUBLAW
PUBLIC LAW 113–282—DEC. 18, 2014
128 STAT. 3067
‘‘(A) actually or imminently jeopardizes, without lawful
authority, the integrity, confidentiality, or availability of
information on an information system; or
‘‘(B) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies;
‘‘(3) the term ‘information sharing and analysis organization’ has the meaning given that term in section 212(5); and
‘‘(4) the term ‘information system’ has the meaning given
that term in section 3502(8) of title 44, United States Code.
‘‘(b) CENTER.—There is in the Department a national cybersecurity and communications integration center (referred to in this
section as the ‘Center’) to carry out certain responsibilities of the
Under Secretary appointed under section 103(a)(1)(H).
‘‘(c) FUNCTIONS.—The cybersecurity functions of the Center
shall include—
‘‘(1) being a Federal civilian interface for the multi-directional and cross-sector sharing of information related to cybersecurity risks, incidents, analysis, and warnings for Federal and
non-Federal entities;
‘‘(2) providing shared situational awareness to enable realtime, integrated, and operational actions across the Federal
Government and non-Federal entities to address cybersecurity
risks and incidents to Federal and non-Federal entities;
‘‘(3) coordinating the sharing of information related to
cybersecurity risks and incidents across the Federal Government;
‘‘(4) facilitating cross-sector coordination to address cybersecurity risks and incidents, including cybersecurity risks and
incidents that may be related or could have consequential
impacts across multiple sectors;
‘‘(5)(A) conducting integration and analysis, including crosssector integration and analysis, of cybersecurity risks and
incidents; and
‘‘(B) sharing the analysis conducted under subparagraph
(A) with Federal and non-Federal entities;
‘‘(6) upon request, providing timely technical assistance,
risk management support, and incident response capabilities
to Federal and non-Federal entities with respect to cybersecurity risks and incidents, which may include attribution, mitigation, and remediation; and
‘‘(7) providing information and recommendations on security and resilience measures to Federal and non-Federal entities, including information and recommendations to—
‘‘(A) facilitate information security; and
‘‘(B) strengthen information systems against cybersecurity risks and incidents.
‘‘(d) COMPOSITION.—
‘‘(1) IN GENERAL.—The Center shall be composed of—
‘‘(A) appropriate representatives of Federal entities,
such as—
‘‘(i) sector-specific agencies;
‘‘(ii) civilian and law enforcement agencies; and
‘‘(iii) elements of the intelligence community, as
that term is defined under section 3(4) of the National
Security Act of 1947 (50 U.S.C. 3003(4));
VerDate Mar 15 2010
21:01 Feb 12, 2015
Jkt 049139
PO 00282
Frm 00003
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL282.113
PUBL282