128 STAT. 2972
PUBLIC LAW 113–274—DEC. 18, 2014
and activities, including computer network operations, information assurance, law enforcement, diplomacy, military, and intelligence missions as such activities relate to the security and
stability of cyberspace.
(2) INFORMATION SYSTEM.—The term ‘‘information system’’
has the meaning given that term in section 3502 of title 44,
United States Code.
15 USC 7422.
SEC. 3. NO REGULATORY AUTHORITY.
Nothing in this Act shall be construed to confer any regulatory
authority on any Federal, State, tribal, or local department or
agency.
15 USC 7423.
SEC. 4. NO ADDITIONAL FUNDS AUTHORIZED.
No additional funds are authorized to carry out this Act, and
the amendments made by this Act. This Act, and the amendments
made by this Act, shall be carried out using amounts otherwise
authorized or appropriated.
TITLE I—PUBLIC-PRIVATE
COLLABORATION ON CYBERSECURITY
SEC. 101. PUBLIC-PRIVATE COLLABORATION ON CYBERSECURITY.
Coordination.
dkrause on DSKHT7XVN1PROD with PUBLAWS
Consultation.
VerDate Mar 15 2010
07:01 Mar 03, 2015
(a) CYBERSECURITY.—Section 2(c) of the National Institute of
Standards and Technology Act (15 U.S.C. 272(c)) is amended—
(1) by redesignating paragraphs (15) through (22) as paragraphs (16) through (23), respectively; and
(2) by inserting after paragraph (14) the following:
‘‘(15) on an ongoing basis, facilitate and support the
development of a voluntary, consensus-based, industry-led set
of standards, guidelines, best practices, methodologies, procedures, and processes to cost-effectively reduce cyber risks to
critical infrastructure (as defined under subsection (e));’’.
(b) SCOPE AND LIMITATIONS.—Section 2 of the National Institute
of Standards and Technology Act (15 U.S.C. 272) is amended by
adding at the end the following:
‘‘(e) CYBER RISKS.—
‘‘(1) IN GENERAL.—In carrying out the activities under subsection (c)(15), the Director—
‘‘(A) shall—
‘‘(i) coordinate closely and regularly with relevant
private sector personnel and entities, critical infrastructure owners and operators, and other relevant
industry organizations, including Sector Coordinating
Councils and Information Sharing and Analysis Centers, and incorporate industry expertise;
‘‘(ii) consult with the heads of agencies with
national security responsibilities, sector-specific agencies and other appropriate agencies, State and local
governments, the governments of other nations, and
international organizations;
‘‘(iii) identify a prioritized, flexible, repeatable,
performance-based, and cost-effective approach,
including information security measures and controls,
Jkt 049139
PO 00274
Frm 00002
Fmt 6580
Sfmt 6581
E:\PUBLAW\PUBL274.113
PUBL274