ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

6 U.S.C. § 681aCyber incident review

submitted 4 years ago by Pub. L. 107-296 to r/title-6-DOMESTIC-SECURITY · 924 words · no verdicts yet

in plain englishAI-generated · not legal advice

The Center must collect, secure, analyze, share, and use cyber-incident information to improve cybersecurity and awareness. The Director must also provide Congress monthly briefings about the national cyber threat landscape and reporting trends.

(a) Activities. The Center must: (1) receive, combine, analyze, and secure covered-entity reports about covered cyber incidents, using processes consistent with the Cybersecurity Information Sharing Act of 2015, to assess security controls, identify attackers’ methods for overcoming them, assess possible public-health and safety effects, and improve awareness across critical-infrastructure sectors; (2) coordinate and share information with appropriate Federal agencies to identify and track ransom payments, including virtual-currency payments; (3) use incident information to (A) improve information sharing and coordination with agencies, sector councils, sharing organizations, governments, technology providers, critical-infrastructure owners and operators, response firms, and security researchers, and (B) give appropriate entities timely, useful, anonymized reports about incident campaigns and trends, including available context, threat indicators, and defensive measures under section 681e; (4) create ways for stakeholders to give feedback about receiving required reports, ransom reports, and voluntary information and about supporting private-sector cybersecurity; (5) voluntarily help relevant critical-infrastructure owners and operators promptly share information about covered incidents and ransom payments, especially ongoing threats or vulnerabilities, and identify and distribute ways to prevent or reduce similar incidents; (6) review a covered incident, including ransomware, that is also a significant cyber incident, or a related group that together is significant, and identify and distribute ways to prevent or reduce similar incidents; (7) immediately review reports under sections 681b(a) and 681c involving an ongoing threat or vulnerability for anonymizable indicators and distribute them with defensive measures, coordinating with other Agency divisions as suitable; (8) publish quarterly unclassified public reports describing combined, anonymized observations, findings, and recommendations from covered-incident reports; (9) consistently with section 681e, find ways to use incident data to support cybersecurity research by academic and private organizations; and (10) under section 681e and subsection (b), make a covered-incident report, ransom report, voluntary information under section 681c, or information from a request or subpoena under section 681d available to appropriate Sector Risk Management Agencies and other appropriate Federal agencies as soon as possible and no later than 24 hours after receipt. (b) Interagency sharing. The President or a designee may set a specific sharing deadline and must identify the appropriate Federal agencies for subsection (a)(10). (c) Periodic briefing. Within 60 days after the section 681b(b) final rule takes effect and on the first day of every month after that, the Director, consulting the National Cyber Director, Attorney General, and Director of National Intelligence, must brief Senate and House leaders and the specified homeland-security committees. The briefing must describe the national cyber-threat landscape, threats to Federal agencies and covered entities, applicable intelligence and law-enforcement information, covered incidents, and ransomware attacks as of the briefing date. It must: (1) give the prior month’s total reports under sections 681b and 681c, separating required and voluntary reports; (2) describe trends in incidents and ransomware compared with earlier reports, including common infrastructure, tactics, and techniques and intelligence gaps hindering responses; (3) summarize known uses of information in those reports; and (4) include an unclassified part, while allowing a classified part.
the actual law source: uscode.house.gov ↗public domain
(a) Activities

The Center shall—

(1)

receive, aggregate, analyze, and secure, using processes consistent with the processes developed pursuant to the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501 et seq.) reports from covered entities related to a covered cyber incident to assess the effectiveness of security controls, identify tactics, techniques, and procedures adversaries use to overcome those controls and other cybersecurity purposes, including to assess potential impact of cyber incidents on public health and safety and to enhance situational awareness of cyber threats across critical infrastructure sectors;

(2)

coordinate and share information with appropriate Federal departments and agencies to identify and track ransom payments, including those utilizing virtual currencies;

(3)

leverage information gathered about cyber incidents to—

(A)

enhance the quality and effectiveness of information sharing and coordination efforts with appropriate entities, including agencies, sector coordinating councils, Information Sharing and Analysis Organizations, State, local, Tribal, and territorial governments, technology providers, critical infrastructure owners and operators, cybersecurity and cyber incident response firms, and security researchers; and

(B)

provide appropriate entities, including sector coordinating councils, Information Sharing and Analysis Organizations, State, local, Tribal, and territorial governments, technology providers, cybersecurity and cyber incident response firms, and security researchers, with timely, actionable, and anonymized reports of cyber incident campaigns and trends, including, to the maximum extent practicable, related contextual information, cyber threat indicators, and defensive measures, pursuant to section 681e of this title;

(4)

establish mechanisms to receive feedback from stakeholders on how the Agency can most effectively receive covered cyber incident reports, ransom payment reports, and other voluntarily provided information, and how the Agency can most effectively support private sector cybersecurity;

(5)

facilitate the timely sharing, on a voluntary basis, between relevant critical infrastructure owners and operators of information relating to covered cyber incidents and ransom payments, particularly with respect to ongoing cyber threats or security vulnerabilities and identify and disseminate ways to prevent or mitigate similar cyber incidents in the future;

(6)

for a covered cyber incident, including a ransomware attack, that also satisfies the definition of a significant cyber incident, or is part of a group of related cyber incidents that together satisfy such definition, conduct a review of the details surrounding the covered cyber incident or group of those incidents and identify and disseminate ways to prevent or mitigate similar incidents in the future;

(7)

with respect to covered cyber incident reports under section 1 681b(a) and 681c of this title involving an ongoing cyber threat or security vulnerability, immediately review those reports for cyber threat indicators that can be anonymized and disseminated, with defensive measures, to appropriate stakeholders, in coordination with other divisions within the Agency, as appropriate;

(8)

publish quarterly unclassified, public reports that describe aggregated, anonymized observations, findings, and recommendations based on covered cyber incident reports, which may be based on the unclassified information contained in the briefings required under subsection (c);

(9)

proactively identify opportunities, consistent with the protections in section 681e of this title, to leverage and utilize data on cyber incidents in a manner that enables and strengthens cybersecurity research carried out by academic institutions and other private sector organizations, to the greatest extent practicable; and

(10)

in accordance with section 681e of this title and subsection (b) of this section, as soon as possible but not later than 24 hours after receiving a covered cyber incident report, ransom payment report, voluntarily submitted information pursuant to section 681c of this title, or information received pursuant to a request for information or subpoena under section 681d of this title, make available the information to appropriate Sector Risk Management Agencies and other appropriate Federal agencies.

(b) Interagency sharing

The President or a designee of the President—

(1)

may establish a specific time requirement for sharing information under subsection (a)(10); and

(2)

shall determine the appropriate Federal agencies under subsection (a)(10).

(c) Periodic briefing

Not later than 60 days after the effective date of the final rule required under section 681b(b) of this title, and on the first day of each month thereafter, the Director, in consultation with the National Cyber Director, the Attorney General, and the Director of National Intelligence, shall provide to the majority leader of the Senate, the minority leader of the Senate, the Speaker of the House of Representatives, the minority leader of the House of Representatives, the Committee on Homeland Security and Governmental Affairs of the Senate, and the Committee on Homeland Security of the House of Representatives a briefing that characterizes the national cyber threat landscape, including the threat facing Federal agencies and covered entities, and applicable intelligence and law enforcement information, covered cyber incidents, and ransomware attacks, as of the date of the briefing, which shall—

(1)

include the total number of reports submitted under sections 681b and 681c of this title during the preceding month, including a breakdown of required and voluntary reports;

(2)

include any identified trends in covered cyber incidents and ransomware attacks over the course of the preceding month and as compared to previous reports, including any trends related to the information collected in the reports submitted under sections 681b and 681c of this title, including—

(A)

the infrastructure, tactics, and techniques malicious cyber actors commonly use; and

(B)

intelligence gaps that have impeded, or currently are impeding, the ability to counter covered cyber incidents and ransomware threats;

(3)

include a summary of the known uses of the information in reports submitted under sections 681b and 681c of this title; and

(4)

include an unclassified portion, but may include a classified component.

Source credit: (Pub. L. 107–296, title XXII, § 2241, as added Pub. L. 117–103, div. Y, § 103(a)(2), Mar. 15, 2022, 136 Stat. 1040.)

history & why it existsrecord from the source credit
  • 2022Enacted · Pub. L. 107-296 · 136 Stat. 1040

A history note hasn’t been published yet. The record shows enactment by Pub. L. 107-296 on 2022-03-15.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case