Cyber incident reporting sharing
In general
section 104 of title 5section 681a(b) of this titleNotwithstanding any other provision of law or regulation, any Federal agency, including any independent establishment (as defined in ), that receives a report from an entity of a cyber incident, including a ransomware attack, shall provide the report to the Agency as soon as possible, but not later than 24 hours after receiving the report, unless a shorter period is required by an agreement made between the Department of Homeland Security (including the Cybersecurity and Infrastructure Security Agency) and the recipient Federal agency. The Director shall share and coordinate each report pursuant to , as added by section 103 of this division.
Rule of construction
section 681e(d) of this titleThe requirements described in paragraph (1) and , as added by section 103 of this division, may not be construed to be a violation of any provision of law or policy that would otherwise prohibit disclosure or provision of information within the executive branch.
Protection of information
The Director shall comply with any obligations of the recipient Federal agency described in paragraph (1) to protect information, including with respect to privacy, confidentiality, or information security, if those obligations would impose greater protection requirements than this division or the amendments made by this division.
Effective date
section 681b(b) of this titleThis subsection shall take effect on the effective date of the final rule issued pursuant to , as added by section 103 of this division.
Agency agreements
In general
section 104 of title 5The Agency and any Federal agency, including any independent establishment (as defined in ), that receives incident reports from entities, including due to ransomware attacks, shall, as appropriate, enter into a documented agreement to establish policies, processes, procedures, and mechanisms to ensure reports are shared with the Agency pursuant to paragraph (1).
Availability
To the maximum extent practicable, each documented agreement required under subparagraph (A) shall be made publicly available.
Requirement
section 681b of this titleThe documented agreements required by subparagraph (A) shall require reports be shared from Federal agencies with the Agency in such time as to meet the overall timeline for covered entity reporting of covered cyber incidents and ransom payments established in , as added by section 103 of this division.
Harmonizing reporting requirements
Pub. L. 117–103, div. Y, § 104136 Stat. 1054(, , .)
Editorial Notes
References in Text
section 103 of div. Y of Pub. L. 117–103section 659 of this titleSection 103 of this division, referred to in text, is , which enacted this part and amended .
Codification
Section was enacted as part of the Cyber Incident Reporting for Critical Infrastructure Act of 2022, and also as part of the Consolidated Appropriations Act, 2022, and not as part of the Homeland Security Act of 2002 which comprises this chapter.
Statutory Notes and Related Subsidiaries
Definitions
section 102 of div. Y of Pub. L. 117–103section 665j of this titleFor definitions of terms used in this section, see , which is set out as a note under .