(2)
Appropriate congressional committees— The term appropriate congressional committees means—
(A)
the Committee on Homeland Security and Governmental Affairs of the Senate;
(B)
the Committee on Oversight and Accountability of the House of Representatives;
(C)
each committee of Congress with jurisdiction over the activities of a regulatory agency; and
(D)
each committee of Congress with jurisdiction over the activities of a Sector Risk Management Agency with respect to a sector regulated by a regulatory agency.
(3)
Committee— The term Committee means the Harmonization Committee established under section 3(a).
(4)
Cybersecurity requirement— The term cybersecurity requirement means an administrative, technical, or physical safeguard, requirement, or supervisory activity, including regulations, guidance, bulletins or examinations, relating to information security, information technology, cybersecurity, or cyber risk or resilience.
(5)
Harmonization—
(A)
Definition— The term harmonization means the process of aligning cybersecurity requirements issued by regulatory agencies such that the requirements consist of—
(i)
a common set of minimum requirements that apply across sectors and that can be updated periodically to address new or evolving risks relating to information security or cybersecurity; and
(ii)
sector-specific requirements that—
(I)
are necessary to address sector-specific risks that are not adequately addressed by the minimum requirements in clause (i); and
(II)
are substantially similar, where appropriate, to other requirements in that sector or a similar sector.
(B)
Rule of construction— Nothing in this definition shall be construed to exempt regulatory agencies from any otherwise applicable processes or laws relating to updating regulations, including subchapter II of chapter 5, and chapter 7, of title 5, United States Code (commonly known as the “Administrative Procedure Act”).
(6)
Independent regulatory agency— The term independent regulatory agency has the meaning given that term in
section 3502 of title 44, United States Code.
(7)
Reciprocity— The term reciprocity means the recognition or acceptance by 1 regulatory agency of an assessment, determination, examination, finding, or conclusion of another regulatory agency for determining that a regulated entity has complied with a cybersecurity requirement.
(8)
Regulatory agency— The term regulatory agency means—
(A)
any independent regulatory agency that has the statutory authority to issue or enforce any mandatory cybersecurity requirement; or
(B)
any other agency that has the statutory authority to issue or enforce any cybersecurity requirement.
(9)
Regulatory Framework— The term regulatory framework means the framework developed under section 3(e)(1).
(10)
Sector risk management agency— The term Sector Risk Management Agency has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (
6 U.S.C. 650).