yourstate.us
6 CFR 29.1

§ 29.1 Purpose and scope.

United States · 6 CFR — Domestic Security · Status: effective

Get this as JSONEmbed this
Cite this
Citation
6 CFR 29.1, § 29.1 Purpose and scope, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/12200
Permanent ID
ys:prov:12200@1
SHA-256
22a4e5ccfaf0dc1a1840ef95b9b1269527a49a16450cffee1d0b12d75946c840

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

(a) Purpose of this part. This part implements the Critical Infrastructure Information Act of 2002 (CII Act) by establishing uniform procedures for the receipt, care, and storage of Critical Infrastructure Information voluntarily submitted to the Department of Homeland Security through CISA. Consistent with the statutory mission of DHS to prevent terrorist attacks within the United States and reduce the vulnerability of the United States to terrorism, CISA will encourage the voluntary submission of CII by safeguarding and protecting that information from unauthorized disclosure and by ensuring that such information is, as necessary, securely shared with State and Local governments pursuant to the CII Act. As required by the CII Act, this part establishes procedures regarding: (1) The acknowledgment of receipt by CISA of voluntarily submitted CII; (2) The receipt, validation, handling, storage, proper marking, and use of information as PCII; (3) The safeguarding and maintenance of the confidentiality of such information and appropriate sharing of such information with State and Local governments or government agencies pursuant to 6 U.S.C. 673(a)(1)(E); and (4) The issuance of advisories, notices, and warnings related to the protection of critical infrastructure or protected systems in such a manner to protect, as appropriate, from unauthorized disclosure the source of critical infrastructure information that forms the basis of the warning, and any information that is proprietary or business sensitive, might be used to identify the submitting person or entity, or is otherwise not appropriately in the public domain. (b) Scope. This part applies to all persons and entities that are authorized to handle, use, store, or otherwise accept receipt of PCII.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.