(b) Heads of Sector-Specific Agencies and other relevant agencies shall provide the
Secretary with information necessary to carry out the responsibilities under this section.
The Secretary shall develop a process for other relevant stakeholders to submit
information to assist in making the identifications required in subsection (a) of this
section.
(c) The Secretary, in coordination with Sector-Specific Agencies, shall confidentially
notify owners and operators of critical infrastructure identified under subsection (a) of
this section that they have been so identified, and ensure identified owners and operators
are provided the basis for the determination. The Secretary shall establish a process
through which owners and operators of critical infrastructure may submit relevant
information and request reconsideration of identifications under subsection (a) of this
section.
Sec. 10. Adoption of Framework. (a) Agencies with responsibility for regulating the
security of critical infrastructure shall engage in a consultative process with DHS, OMB,
and the National Security Staff to review the preliminary Cybersecurity Framework and
determine if current cybersecurity regulatory requirements are sufficient given current
and projected risks. In making such determination, these agencies shall consider the
identification of critical infrastructure required under section 9 of this order. Within 90
days of the publication of the preliminary Framework, these agencies shall submit a
report to the President, through the Assistant to the President for Homeland Security and
Counterterrorism, the Director of OMB, and the Assistant to the President for Economic
Affairs, that states whether or not the agency has clear authority to establish requirements
based upon the Cybersecurity Framework to sufficiently address current and projected
cyber risks to critical infrastructure, the existing authorities identified, and any additional
authority required.
(b) If current regulatory requirements are deemed to be insufficient, within 90 days of
publication of the final Framework, agencies identified in subsection (a) of this section
shall propose prioritized, risk-based, efficient, and coordinated actions, consistent with
Executive Order 12866 of September 30, 1993 (Regulatory Planning and Review),
Executive Order 13563 of January 18, 2011 (Improving Regulation and Regulatory
Review), and Executive Order 13609 of May 1, 2012 (Promoting International Regulatory
Cooperation), to mitigate cyber risk.
(c) Within 2 years after publication of the final Framework, consistent with Executive
Order 13563 and Executive Order 13610 of May 10, 2012 (Identifying and Reducing
Regulatory Burdens), agencies identified in subsection (a) of this section shall, in
consultation with owners and operators of critical infrastructure, report to OMB on any
critical infrastructure subject to ineffective, conflicting, or excessively burdensome
cybersecurity requirements. This report shall describe efforts made by agencies, and make
recommendations for further actions, to minimize or eliminate such requirements.
6/8