6 U.S.C. § 652
Cybersecurity and Infrastructure Security Agency
United States · Title 6 — DOMESTIC SECURITY · Status: effective
Cite this
- Citation
- 6 U.S.C. § 652, Cybersecurity and Infrastructure Security Agency, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/428143
- Permanent ID
ys:prov:428143@1- SHA-256
76ac211d31e188ee0847782c3ece240cc00d0226109c02f49796722057a932ff
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
The National Protection and Programs Directorate of the Department shall, on and after November 16, 2018, be known as the “Cybersecurity and Infrastructure Security Agency”.
Any reference to the National Protection and Programs Directorate of the Department in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Cybersecurity and Infrastructure Security Agency of the Department.
The Agency shall be headed by the Director, who shall report to the Secretary.
The Director shall be appointed from among individuals who have—
The areas specified in this subparagraph are the following:
Any reference to an Under Secretary responsible for overseeing critical infrastructure protection, cybersecurity, and any other related program of the Department as described in section 113(a)(1)(H) of this title as in effect on the day before November 16, 2018, in any law, regulation, map, document, record, or other paper of the United States shall be deemed to be a reference to the Director of the Cybersecurity and Infrastructure Security Agency.
The Director shall—
develop, coordinate, and implement—
There shall be in the Agency a Deputy Director of the Cybersecurity and Infrastructure Security Agency who shall—
The responsibilities of the Secretary relating to cybersecurity and infrastructure security shall include the following:
To access, receive, and analyze law enforcement information, intelligence information, and other information from Federal Government agencies, State, local, tribal, and territorial government agencies, including law enforcement agencies, and private sector entities, and to integrate that information, in support of the mission responsibilities of the Department, in order to—
To encourage and build cybersecurity awareness and competency across the United States and to develop, attract, and retain the cybersecurity workforce necessary for the cybersecurity related missions of the Department, including by—
carrying out cybersecurity related workforce development activities, including through—
The Secretary may reallocate within the Agency the functions specified in sections 653(b) and 654(b) of this title, consistent with the responsibilities provided in paragraph (1), upon certifying to and briefing the appropriate congressional committees, and making available to the public, at least 60 days prior to the reallocation that the reallocation is necessary for carrying out the activities of the Agency.
The Secretary shall provide the Agency with a staff of analysts having appropriate expertise and experience to assist the Agency in discharging the responsibilities of the Agency under this section.
Analysts under this subsection may include analysts from the private sector.
Analysts under this subsection shall possess security clearances appropriate for their work under this section.
In order to assist the Agency in discharging the responsibilities of the Agency under this section, personnel of the Federal agencies described in subparagraph (B) may be detailed to the Agency for the performance of analytic functions and related duties.
The Federal agencies described in this subparagraph are—
The Secretary and the head of a Federal agency described in subparagraph (B) may enter into agreements for the purpose of detailing personnel under this paragraph.
The detail of personnel under this paragraph may be on a reimbursable or non-reimbursable basis.
The Agency shall be composed of the following divisions:
To the maximum extent practicable, the Director shall examine the establishment of central locations in geographical regions with a significant Agency presence.
When establishing the central locations described in paragraph (1), the Director shall coordinate with component heads and the Under Secretary for Management to co-locate or partner on any new real property leases, renewing any occupancy agreements for existing leases, or agreeing to extend or newly occupy any Federal space or new construction.
There shall be a Privacy Officer of the Agency with primary responsibility for privacy policy and compliance for the Agency.
The responsibilities of the Privacy Officer of the Agency shall include—
Nothing in this subchapter may be construed as affecting in any manner the authority, existing on the day before November 16, 2018, of any other component of the Department or any other Federal department or agency, including the authority provided to the Sector Risk Management Agency specified in section 61003(c) of division F of the Fixing America’s Surface Transportation Act (6 U.S.C. 121 note; Public Law 114–94).
Legislative history
The public laws that enacted or amended this section. Tallies are for the whole bill as it passed each chamber — often an omnibus covering far more than this provision — not a vote on this section alone.
- Homeland Security Act of 2002
- Cybersecurity and Infrastructure Security Agency Act of 2018House: no recorded tallySenate: no recorded tally
- Consolidated Appropriations Act, 2021House: no recorded tallySenate: no recorded tally
- William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021
- National Defense Authorization Act for Fiscal Year 2022House: 363–70Senate: no recorded tally
- James M. Inhofe National Defense Authorization Act for Fiscal Year 2023