EO 13691Executive OrderObama · D Quiet signal

Executive Order 13691

Promoting Private Sector Cybersecurity Information Sharing

This executive order encourages voluntary formation of Information Sharing and Analysis Organizations (ISAOs) to enable private sector cybersecurity information sharing with the federal government. It establishes a standards-setting process for ISAOs, designates DHS's NCCIC as a critical infrastructure protection program, and amends the National Industrial Security Program to facilitate classified information sharing with private sector partners under voluntary agreements.

Impact dates

  1. Open competitive process to select ISAO Standards Organization

  2. Standards development with open public review and comment process

Key directives

  • DHS Secretary shall strongly encourage development and formation of ISAOs
  • DHS shall enter into agreement with nongovernmental ISAO Standards Organization through open and competitive process
  • ISAO Standards Organization shall identify common voluntary standards for ISAO creation and functioning
  • Standards must address contractual agreements, business processes, operating procedures, technical means, and privacy protections including minimization
  • NCCIC shall engage in continuous collaborative coordination with ISAOs
  • NCCIC delegated authority to enter into voluntary agreements with ISAOs
  • Secretary shall determine eligibility of ISAOs for security clearances
  • Agencies shall coordinate activities with senior privacy and civil liberties officials
  • Senior privacy officials shall conduct assessments and provide to DHS Chief Privacy Officer and Office for Civil Rights and Civil Liberties
  • EO 12829 amended to add Intelligence Reform and Terrorism Prevention Act of 2004 references
  • DHS Secretary given authority to prescribe National Industrial Security Program Manual portion for classified information shared under critical infrastructure protection program
  • DHS Secretary may determine eligibility for access to Classified National Security Information under designated critical infrastructure protection program

Who is ordered

Timeline

Immediate

  • DHS Secretary directed to strongly encourage ISAO formation
  • NCCIC designated as critical infrastructure protection program
  • EO 12829 amendments take effect

Near term (90d)

  • Open competitive process to select ISAO Standards Organization
  • Development of voluntary standards for ISAO creation and functioning

Long term

  • Implementation of ISAO standards across sectors
  • Establishment of deeper national information sharing networks
  • Potential expansion of automated information sharing mechanisms

Risks & tensions

  • No explicit calendar deadlines or day-counts in text; timeline for SO selection and standards development is vague
  • Voluntary nature of ISAO participation may limit adoption and effectiveness
  • Privacy protections described as 'based upon' Fair Information Practice Principles but not mandated as binding requirements
  • Multiple agency coordination required (DHS, DOD, DOJ, DNI, DOE, NRC) creates potential for jurisdictional friction
  • Classified information sharing with private sector raises security clearance backlogs and insider threat concerns
  • EO explicitly disclaims creating enforceable rights, limiting accountability mechanisms
Executive Order 13691: Promoting Private Sector Cybersecurity Information Sharing · Executive Orders