There is established in the Agency a program, to be known as "CyberSentry", to provide continuous monitoring and detection of cybersecurity risks to critical infrastructure entities that own or operate industrial control systems that support national critical functions, upon request and subject to the consent of such owner or operator.
The Director, through CyberSentry, shall-
Not later than 180 days after December 27, 2021, the Privacy Officer of the Agency under section 652(h) of this title shall-
Not later than one year after December 27, 2021, the Director shall provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a briefing and written report on implementation of this section.
Nothing in this section may be construed to permit the Federal Government to gain access to information of a remote computing service provider to the public or an electronic service provider to the public, the disclosure of which is not permitted under section 2702 of title 18.
In this section, the term "industrial control system" means an information system used to monitor and/or control industrial processes such as manufacturing, product handling, production, and distribution, including supervisory control and data acquisition (SCADA) systems used to monitor and/or control geographically dispersed assets, distributed control systems (DCSs), Human-Machine Interfaces (HMIs), and programmable logic controllers that control localized processes.
The authority to carry out a program under this section shall terminate on the date that is seven years after December 27, 2021.
6 U.S.C. § 665i
EDITORIAL NOTES
REFERENCES IN TEXTSection 1501 of the National Defense Authorization Act for Fiscal Year 2022, referred to in subsec. (b)(5), is section 1501, Dec. 27, 2021 of Pub. L. 117-81, 135 Stat. 2020, related to development of taxonomy of cyber capabilities, which is not classified to the Code.
CODIFICATION Section 1548(a) of Pub. L. 117-81 which directed that this section be added at the end of title XXII of the Homeland Security Act of 2002, was executed by adding this section at the end of this part as if the directory language had added the section at the end of subtitle A of title XXII of the Act, to reflect the probable intent of Congress.
AMENDMENTS2022-Subsec. (f). Pub. L. 117-263 added subsec. (f) and struck out former subsec. (f) which defined cybersecurity risk, industrial control system, and information system.
- assets
- The term "assets" includes contracts, facilities, property, records, unobligated or unexpended balances of appropriations, and other funds or resources (other than personnel).
- functions
- The term "functions" includes authorities, powers, rights, privileges, immunities, programs, projects, activities, duties, and responsibilities.
- Agency
- the term "Agency" means the Federal Emergency Management Agency;