dkrause on DSKHT7XVN1PROD with PUBLAWS PUBLIC LAW 113–274—DEC. 18, 2014 128 STAT. 2973 that may be voluntarily adopted by owners and operators of critical infrastructure to help them identify, assess, and manage cyber risks; ‘‘(iv) include methodologies— ‘‘(I) to identify and mitigate impacts of the cybersecurity measures or controls on business confidentiality; and ‘‘(II) to protect individual privacy and civil liberties; ‘‘(v) incorporate voluntary consensus standards and industry best practices; ‘‘(vi) align with voluntary international standards to the fullest extent possible; ‘‘(vii) prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes; and ‘‘(viii) include such other similar and consistent elements as the Director considers necessary; and ‘‘(B) shall not prescribe or otherwise require— ‘‘(i) the use of specific solutions; ‘‘(ii) the use of specific information or communications technology products or services; or ‘‘(iii) that information or communications technology products or services be designed, developed, or manufactured in a particular manner. ‘‘(2) LIMITATION.—Information shared with or provided to the Institute for the purpose of the activities described under subsection (c)(15) shall not be used by any Federal, State, tribal, or local department or agency to regulate the activity of any entity. Nothing in this paragraph shall be construed to modify any regulatory requirement to report or submit information to a Federal, State, tribal, or local department or agency. ‘‘(3) DEFINITIONS.—In this subsection: ‘‘(A) CRITICAL INFRASTRUCTURE.—The term ‘critical infrastructure’ has the meaning given the term in section 1016(e) of the USA PATRIOT Act of 2001 (42 U.S.C. 5195c(e)). ‘‘(B) SECTOR-SPECIFIC AGENCY.—The term ‘sector-specific agency’ means the Federal department or agency responsible for providing institutional knowledge and specialized expertise as well as leading, facilitating, or supporting the security and resilience programs and associated activities of its designated critical infrastructure sector in the all-hazards environment.’’. (c) STUDY AND REPORTS.— (1) STUDY.—The Comptroller General of the United States shall conduct a study that assesses— (A) the progress made by the Director of the National Institute of Standards and Technology in facilitating the development of standards and procedures to reduce cyber risks to critical infrastructure in accordance with section 2(c)(15) of the National Institute of Standards and Technology Act, as added by this section; (B) the extent to which the Director’s facilitation efforts are consistent with the directive in such section that the VerDate Mar 15 2010 07:01 Mar 03, 2015 Jkt 049139 PO 00274 Frm 00003 Fmt 6580 Sfmt 6581 E:\PUBLAW\PUBL274.113 PUBL274

Select target paragraph3