CISA Technical Corrections and Improvements Act of 2021
A BILL
To make technical corrections to title XXII of the Homeland Security Act of 2002, and for other purposes.
Sec. 2 Redesignations
Sec. 3 Consolidation of definitions
“2200. Definitions
“Except as otherwise specifically provided, in this title:
“(1) Agency—The term Agency means the Cybersecurity and Infrastructure Security Agency.
“(2) Agency information—The term agency information means information collected or maintained by or on behalf of an agency.
“(3) Agency information system—The term agency information system means an information system used or operated by an agency or by another entity on behalf of an agency.
“(4) Appropriate congressional committees—The term appropriate congressional committees means—
“(A) the Committee on Homeland Security and Governmental Affairs of the Senate; and
“(B) the Committee on Homeland Security of the House of Representatives.
“(5) Critical infrastructure information—The term critical infrastructure information means information not customarily in the public domain and related to the security of critical infrastructure or protected systems—
“(A) actual, potential, or threatened interference with, attack on, compromise of, or incapacitation of critical infrastructure or protected systems by either physical or computer-based attack or other similar conduct (including the misuse of or unauthorized access to all types of communications and data transmission systems) that violates Federal, State, or local law, harms interstate commerce of the United States, or threatens public health or safety;
“(B) the ability of any critical infrastructure or protected system to resist such interference, compromise, or incapacitation, including any planned or past assessment, projection, or estimate of the vulnerability of critical infrastructure or a protected system, including security testing, risk evaluation thereto, risk management planning, or risk audit; or
“(C) any planned or past operational problem or solution regarding critical infrastructure or protected systems, including repair, recovery, reconstruction, insurance, or continuity, to the extent it is related to such interference, compromise, or incapacitation.
“(6) Cyber threat indicator—The term cyber threat indicator means information that is necessary to describe or identify—
“(A) malicious reconnaissance, including anomalous patterns of communications that appear to be transmitted for the purpose of gathering technical information related to a cybersecurity threat or security vulnerability;
“(B) a method of defeating a security control or exploitation of a security vulnerability;
“(C) a security vulnerability, including anomalous activity that appears to indicate the existence of a security vulnerability;
“(D) a method of causing a user with legitimate access to an information system or information that is stored on, processed by, or transiting an information system to unwittingly enable the defeat of a security control or exploitation of a security vulnerability;
“(E) malicious cyber command and control;
“(F) the actual or potential harm caused by an incident, including a description of the information exfiltrated as a result of a particular cybersecurity threat;
“(G) any other attribute of a cybersecurity threat, if disclosure of such attribute is not otherwise prohibited by law; or
“(H) any combination thereof.
“(7) Cybersecurity purpose—The term cybersecurity purpose means the purpose of protecting an information system or information that is stored on, processed by, or transiting an information system from a cybersecurity threat or security vulnerability.
“(8) Cybersecurity risk—The term cybersecurity risk—
“(A) means threats to and vulnerabilities of information or information systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information or information systems, including such related consequences caused by an act of terrorism; and
“(B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.
“(9) Cybersecurity threat
“(A) In general—Except as provided in subparagraph (B), the term cybersecurity threat means an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system.
“(B) Exclusion—The term cybersecurity threat does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.
“(10) Defensive measure
“(A) In general—Except as provided in subparagraph (B), the term defensive measure means an action, device, procedure, signature, technique, or other measure applied to an information system or information that is stored on, processed by, or transiting an information system that detects, prevents, or mitigates a known or suspected cybersecurity threat or security vulnerability.
“(B) Exclusion—The term defensive measure does not include a measure that destroys, renders unusable, provides unauthorized access to, or substantially harms an information system or information stored on, processed by, or transiting such information system not owned by—
“(i) the entity operating the measure; or
“(ii) another entity or Federal entity that is authorized to provide consent and has provided consent to that private entity for operation of such measure.
“(11) Homeland Security Enterprise—The term Homeland Security Enterprise means relevant governmental and nongovernmental entities involved in homeland security, including Federal, State, local, and tribal government officials, private sector representatives, academics, and other policy experts.
“(12) Incident—The term incident means an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or actually or imminently jeopardizes, without lawful authority, an information system.
“(13) Information sharing and analysis organization—The term Information Sharing and Analysis Organization means any formal or informal entity or collaboration created or employed by public or private sector organizations, for purposes of—
“(A) gathering and analyzing critical infrastructure information, including information related to cybersecurity risks and incidents, in order to better understand security problems and interdependencies related to critical infrastructure, including cybersecurity risks and incidents, and protected systems, so as to ensure the availability, integrity, and reliability thereof;
“(B) communicating or disclosing critical infrastructure information, including cybersecurity risks and incidents, to help prevent, detect, mitigate, or recover from the effects of a interference, compromise, or a incapacitation problem related to critical infrastructure, including cybersecurity risks and incidents, or protected systems; and
“(C) voluntarily disseminating critical infrastructure information, including cybersecurity risks and incidents, to its members, State, local, and Federal Governments, or any other entities that may be of assistance in carrying out the purposes specified in subparagraphs (A) and (B).
“(14) Information system—The term information system has the meaning given the term in section 3502 of title 44, United States Code.
“(15) Intelligence community—The term intelligence community has the meaning given the term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)).
“(16) Monitor—The term monitor means to acquire, identify, or scan, or to possess, information that is stored on, processed by, or transiting an information system.
“(17) National cybersecurity asset response activities—The term national cybersecurity asset response activities means—
“(A) furnishing cybersecurity technical assistance to entities affected by cybersecurity risks to protect assets, mitigate vulnerabilities, and reduce impacts of cyber incidents;
“(B) identifying other entities that may be at risk of an incident and assessing risk to the same or similar vulnerabilities;
“(C) assessing potential cybersecurity risks to a sector or region, including potential cascading effects, and developing courses of action to mitigate such risks;
“(D) facilitating information sharing and operational coordination with threat response; and
“(E) providing guidance on how best to utilize Federal resources and capabilities in a timely, effective manner to speed recovery from cybersecurity risks.
“(18) National security system—The term national security system has the meaning given the term in section 11103 of title 40, United States Code.
“(19) Sector risk management agency—The term Sector Risk Management Agency means a Federal department or agency, designated by law or Presidential directive, with responsibility for providing institutional knowledge and specialized expertise of a sector, as well as leading, facilitating, or supporting programs and associated activities of its designated critical infrastructure sector in the all hazards environment in coordination with the Department.
“(20) Security control—The term security control means the management, operational, and technical controls used to protect against an unauthorized effort to adversely affect the confidentiality, integrity, and availability of an information system or its information.
“(21) Security vulnerability—The term security vulnerability means any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control.
“(22) Sharing—The term sharing (including all conjugations thereof) means providing, receiving, and disseminating (including all conjugations of each such terms).”
“2201. Definition
“In this subtitle, the term Cybersecurity Advisory Committee means the advisory committee established under section 2219(a).”
“(f) Cyber defense operation defined—In this section, the term cyber defense operation means the use of a defensive measure.”
“(4) Cybersecurity purpose—The term cybersecurity purpose has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
“(5) Cybersecurity threat—The term cybersecurity threat has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
“(6) Cyber threat indicator—The term cyber threat indicator has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
“(7) Defensive measure—The term defensive measure has the meaning given the term in section 2200 of the Homeland Security Act of 2002.”
“(13) Monitor—The term monitor has the meaning given the term in section 2200 of the Homeland Security Act of 2002.”
“(16) Security control—The term security control has the meaning given the term in section 2200 of the Homeland Security Act of 2002.
“(17) Security vulnerability—The term security vulnerability has the meaning given the term in section 2200 of the Homeland Security Act of 2002.”
Sec. 4 Additional technical and conforming amendments
“(7) Sector Risk Management Agency—The term Sector Risk Management Agency has the meaning given the term in section 2200 of the Homeland Security Act of 2002.”