§651. Definition
In this part, the term "Cybersecurity Advisory Committee" means the advisory committee established under section 665e(a) of this title.
(
Editorial Notes
Amendments
2022-
Par. (7).
2021-Par. (5).
Statutory Notes and Related Subsidiaries
Rule of Construction
Nothing in amendment made by
Construction of Pub. L. 115–278
"(1) conferring new authorities to the Secretary of Homeland Security, including programmatic, regulatory, or enforcement authorities, outside of the authorities in existence on the day before the date of enactment of this Act [Nov. 16, 2018];
"(2) reducing or limiting the programmatic, regulatory, or enforcement authority vested in any other Federal agency by statute; or
"(3) affecting in any manner the authority, existing on the day before the date of enactment of this Act, of any other Federal agency or component of the Department of Homeland Security."
National Cyber Exercises
"(a)
"(b)
"(1) appropriate personnel from-
"(A) the Department of Homeland Security;
"(B) the Department of Defense; and
"(C) the Department of Justice; and
"(2) appropriate elements of the intelligence community, identified by the Director of National Intelligence.
"(c)
"(d)
"(1)
"(A) The Department of Homeland Security.
"(B) The Department of Defense, as identified by the Secretary of Defense.
"(C) Elements of the intelligence community, as identified by the Director of National Intelligence.
"(D) The Department of Justice, as identified by the Attorney General.
"(E) Sector-specific agencies, as determined by the Secretary of Homeland Security.
"(2)
"(3)
"(A) Representatives from appropriate private entities.
"(B) Other individuals whom the Secretary determines will best assist the United States in preparing for, and defending against, a significant cyber incident impacting critical infrastructure.
"(4)
"(e)
"(f)
"(1) Exercising the orchestration of cybersecurity response and the provision of cyber support to Federal, State, local, and Tribal governments and private entities, including the exercise of the command, control, and deconfliction of-
"(A) operational responses through interagency coordination processes and response groups; and
"(B) each Federal agency participating in such exercise in accordance with subsection (d)(1).
"(2) Testing of the information sharing needs and capabilities of exercise participants.
"(3) Testing of the relevant policy, guidance, and doctrine, including the National Cyber Incident Response Plan of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security.
"(4) Testing of the integration and interoperability between the entities participating in the exercise in accordance with subsection (d).
"(5) Exercising the integration and interoperability of the cybersecurity operation centers of the Federal Government, as appropriate, in coordination with appropriate cabinet level officials.
"(g)
"(1)
"(2)
"(A) an assessment of the decision and response gaps observed in the exercise at issue;
"(B) proposed recommendations to improve the resilience, response, and recovery of the United States to a significant cyber attack against critical infrastructure; and
"(C) appropriate plans to address the recommendations proposed under subparagraph (B).
"(h)
"(i)
"(1)
"(A) the Committee on Armed Services of the Senate;
"(B) the Committee on Armed Services of the House of Representatives;
"(C) the Committee on Homeland Security and Governmental Affairs of the Senate;
"(D) the Committee on Homeland Security of the House of Representatives;
"(E) the Select Committee on Intelligence of the Senate;
"(F) the Permanent Select Committee on Intelligence of the House of Representatives;
"(G) the Committee on the Judiciary of the Senate;
"(H) the Committee on the Judiciary of the House of Representatives;
"(I) the Committee on Commerce, Science, and Transportation of the Senate;
"(J) the Committee on Science, Space, and Technology of the House of Representatives;
"(K) the Committee on Foreign Relations of the Senate; and
"(L) the Committee on Foreign Affairs of the House of Representatives.
"(2)
"(3)
"(4)
"(5)
"(6)
Executive Documents
Ex. Ord. No. 13905. Strengthening National Resilience Through Responsible Use of Positioning, Navigation, and Timing Services
Ex. Ord. No. 13905, Feb. 12, 2020, 85 F.R. 9359, provided:
By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered as follows:
(a) "PNT services" means any system, network, or capability that provides a reference to calculate or augment the calculation of longitude, latitude, altitude, or transmission of time or frequency data, or any combination thereof.
(b) "Responsible use of PNT services" means the deliberate, risk-informed use of PNT services, including their acquisition, integration, and deployment, such that disruption or manipulation of PNT services minimally affects national security, the economy, public health, and the critical functions of the Federal Government.
(c) "Critical infrastructure" means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on national security, national economic security, national public health or safety, or on any combination of those matters.
(d) "PNT profile" means a description of the responsible use of PNT services-aligned to standards, guidelines, and sector-specific requirements-selected for a particular system to address the potential disruption or manipulation of PNT services.
(e) "Sector-Specific Agency" (SSA) is the executive department or agency that is responsible for providing institutional knowledge and specialized expertise as well as leading, facilitating, or supporting the security and resilience programs and associated activities of its designated critical infrastructure sector in the all-hazards environment. The SSAs are those identified in Presidential Policy Directive 21 of February 12, 2013 (Critical Infrastructure Security and Resilience).
To this end, the Federal Government shall engage the public and private sectors to identify and promote the responsible use of PNT services.
(b) The Secretary of Defense, Secretary of Transportation, and Secretary of Homeland Security shall refer to the PNT profiles created pursuant to subsection (a) of this section in updates to the Federal Radionavigation Plan.
(c) Within 1 year of the date of this order, the Secretary of Homeland Security, in coordination with the heads of SSAs, shall develop a plan to test the vulnerabilities of critical infrastructure systems, networks, and assets in the event of disruption and manipulation of PNT services. The results of the tests carried out under that plan shall be used to inform updates to the PNT profiles identified in subsection (a) of this section.
(d) Within 90 days of the PNT profiles being made available, the heads of SSAs and the heads of other executive departments and agencies (agencies), as appropriate, through the Secretary of Homeland Security, shall develop contractual language for inclusion of the relevant information from the PNT profiles in the requirements for Federal contracts for products, systems, and services that integrate or utilize PNT services, with the goal of encouraging the private sector to use additional PNT services and develop new robust and secure PNT services. The heads of SSAs and the heads of other agencies, as appropriate, shall update the requirements as necessary.
(e) Within 180 days of the completion of any of the duties described in subsection (d) of this section, and consistent with applicable law and to the maximum extent practicable, the Federal Acquisition Regulatory Council, in consultation with the heads of SSAs and the heads of other agencies, as appropriate, shall incorporate the requirements developed under subsection (d) of this section into Federal contracts for products, systems, and services that integrate or use PNT services.
(f) Within 1 year of the PNT profiles being made available, and biennially thereafter, the heads of SSAs and the heads of other agencies, as appropriate, through the Secretary of Homeland Security, shall submit a report to the Assistant to the President for National Security Affairs and the Director of the Office of Science and Technology Policy (OSTP) on the extent to which the PNT profiles have been adopted in their respective agencies' acquisitions and, to the extent possible, the extent to which PNT profiles have been adopted by owners and operators of critical infrastructure.
(g) Within 180 days of the date of this order, the Secretary of Transportation, Secretary of Energy, and Secretary of Homeland Security shall each develop plans to engage with critical infrastructure owners or operators to evaluate the responsible use of PNT services. Each pilot program shall be completed within 1 year of developing the plan, and the results shall be used to inform the development of the relevant PNT profile and research and development (R&D) opportunities.
(h) Within 1 year of the date of this order, the Director of OSTP shall coordinate the development of a national plan, which shall be informed by existing initiatives, for the R&D and pilot testing of additional, robust, and secure PNT services that are not dependent on global navigation satellite systems (GNSS). The plan shall also include approaches to integrate and use multiple PNT services to enhance the resilience of critical infrastructure.
Once the plan is published, the Director of OSTP shall coordinate updates to the plan every 4 years, or as appropriate.
(i) Within 180 days of the date of this order, the Secretary of Commerce shall make available a GNSS-independent source of Coordinated Universal Time, to support the needs of critical infrastructure owners and operators, for the public and private sectors to access.
(i) the authority granted by law to an executive department or agency, or the head thereof; or
(ii) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals.
(b) This order shall be implemented consistent with applicable law and subject to the availability of appropriations.
(c) This order is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.
Donald J. Trump.
[Reference to a Sector Specific Agency (including any permutations or conjugations thereof) deemed to be a reference to the Sector Risk Management Agency of the relevant critical infrastructure sector and have the meaning given such term in section 650 of this title, see section 652a(c)(3) of this title, enacted Jan. 1, 2021.]