(2)
Appropriate congressional committees— The term appropriate congressional committees means—
(A)
the Committee on Homeland Security and Governmental Affairs of the Senate;
(B)
the Committee on Oversight and Government Reform of the House of Representatives;
(C)
each committee of Congress with jurisdiction over the activities of a regulatory agency; and
(D)
each committee of Congress with jurisdiction over the activities of a Sector Risk Management Agency with respect to a sector regulated by a regulatory agency.
(3)
Committee— The term Committee means the Harmonization Committee established under section 3(a).
(4)
Cybersecurity requirement— The term cybersecurity requirement means a regulation or supervisory activity, including an examination or binding guidance, that includes administrative, technical, or physical requirements relating to information security, security of information technology or operational technology, cybersecurity, or cyber risk or resilience.
(5)
Harmonization—
(A)
Definition— The term harmonization means the process of aligning cybersecurity requirements issued by regulatory agencies such that the requirements consist of—
(i)
a common set of minimum requirements that may apply across sectors and that can be updated periodically to address new or evolving risks relating to information security or cybersecurity; and
(ii)
sector-specific requirements, which may include performance-based requirements, that—
(I)
are necessary to address sector-specific risks that are not adequately addressed by the minimum requirements described in clause (i);
(II)
are substantially similar, where appropriate, to other requirements in that sector or a similar sector; and
(III)
align with international standards, where appropriate.
(B)
Rule of construction— Nothing in this definition shall be construed to exempt regulatory agencies from any otherwise applicable processes or laws relating to promulgating or amending regulations, including subchapter II of chapter 5, and chapter 7, of title 5, United States Code (commonly known as the “Administrative Procedure Act”).
(6)
Head— The term head includes, in the case of an agency directed by multiple individuals, such as a commission, a representative selected by such individuals from among such individuals.
(7)
Independent regulatory agency— The term independent regulatory agency has the meaning given that term in
section 3502 of title 44, United States Code.
(8)
Reciprocity— The term reciprocity means the recognition or acceptance by 1 regulatory agency of an assessment, determination, examination, finding, or conclusion of another regulatory agency for determining that a regulated entity has complied with a cybersecurity requirement.
(9)
Regulatory agency— The term regulatory agency means—
(A)
any independent regulatory agency that has the statutory authority to issue or enforce any mandatory cybersecurity requirement; or
(B)
any other agency that has the statutory authority to issue or enforce any cybersecurity requirement.
(10)
Regulatory framework— The term regulatory framework means the framework developed under section 3(e)(1).
(11)
Sector risk management agency— The term Sector Risk Management Agency has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (
6 U.S.C. 650).