Division L — Dhs Cyber Hunt and Incident Response Teams
DIVISION L Dhs Cyber Hunt and Incident Response Teams
SEC. 102. Department of Homeland Security Cyber Hunt and Incident Response Teams.
“(f) Cyber Hunt and Incident Response Teams.—
“(1) In general.—The Center shall maintain cyber hunt and incident response teams for the purpose of leading Federal asset response activities and providing timely technical assistance to Federal and non-Federal entities, including across all critical infrastructure sectors, regarding actual or potential security incidents, as appropriate and upon request, including—
“(A) assistance to asset owners and operators in restoring services following a cyber incident;
“(B) identification and analysis of cybersecurity risk and unauthorized cyber activity;
“(C) mitigation strategies to prevent, deter, and protect against cybersecurity risks;
“(D) recommendations to asset owners and operators for improving overall network and control systems security to lower cybersecurity risks, and other recommendations, as appropriate; and
“(E) such other capabilities as the Secretary determines appropriate.
“(2) Associated metrics.—The Center shall—
“(A) define the goals and desired outcomes for each cyber hunt and incident response team; and
“(B) develop metrics—
“(i) to measure the effectiveness and efficiency of each cyber hunt and incident response team in achieving the goals and desired outcomes defined under subparagraph (A); and
“(ii) that—
“(I) are quantifiable and actionable; and
“(II) the Center shall use to improve the effectiveness and accountability of, and service delivery by, cyber hunt and incident response teams.
“(3) Cybersecurity specialists.—After notice to, and with the approval of, the entity requesting action by or technical assistance from the Center, the Secretary may include cybersecurity specialists from the private sector on a cyber hunt and incident response team.”
; and