SEC. 101. Public-Private Collaboration on Cybersecurity.
“(15) on an ongoing basis, facilitate and support the development of a voluntary, consensus-based, industry-led set of standards, guidelines, best practices, methodologies, procedures, and processes to cost-effectively reduce cyber risks to critical infrastructure (as defined under subsection (e));”
“(e) Cyber Risks.—
“(1) In general.—In carrying out the activities under subsection (c)(15), the Director—
“(A) shall—
“(i) coordinate closely and regularly with relevant private sector personnel and entities, critical infrastructure owners and operators, and other relevant industry organizations, including Sector Coordinating Councils and Information Sharing and Analysis Centers, and incorporate industry expertise;
“(ii) consult with the heads of agencies with national security responsibilities, sector-specific agencies and other appropriate agencies, State and local governments, the governments of other nations, and international organizations;
“(iii) identify a prioritized, flexible, repeatable, performance-based, and cost-effective approach, including information security measures and controls, that may be voluntarily adopted by owners and operators of critical infrastructure to help them identify, assess, and manage cyber risks;
“(iv) include methodologies—
“(I) to identify and mitigate impacts of the cybersecurity measures or controls on business confidentiality; and
“(II) to protect individual privacy and civil liberties;
“(v) incorporate voluntary consensus standards and industry best practices;
“(vi) align with voluntary international standards to the fullest extent possible;
“(vii) prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes; and
“(viii) include such other similar and consistent elements as the Director considers necessary; and
“(B) shall not prescribe or otherwise require—
“(i) the use of specific solutions;
“(ii) the use of specific information or communications technology products or services; or
“(iii) that information or communications technology products or services be designed, developed, or manufactured in a particular manner.
“(2) Limitation.—Information shared with or provided to the Institute for the purpose of the activities described under subsection (c)(15) shall not be used by any Federal, State, tribal, or local department or agency to regulate the activity of any entity. Nothing in this paragraph shall be construed to modify any regulatory requirement to report or submit information to a Federal, State, tribal, or local department or agency.
“(3) Definitions.—In this subsection:
“(A) Critical infrastructure.—The term ‘critical infrastructure’ has the meaning given the term in section 1016(e) of the USA PATRIOT Act of 2001 (42 U.S.C. 5195c(e)).
“(B) Sector-specific agency.—The term ‘sector-specific agency’ means the Federal department or agency responsible for providing institutional knowledge and specialized expertise as well as leading, facilitating, or supporting the security and resilience programs and associated activities of its designated critical infrastructure sector in the all-hazards environment.”