Under subsection (o) of Section 2209 of the Homeland Security Act, as amended (6 U.S.C. § 659(o)), CISA has the authority to issue administrative subpoenas for the production of information necessary to identify and notify an entity at risk. This authority applies when CISA identifies a system connected to the internet with a specific security vulnerability and has reason to believe the security vulnerability relates to critical infrastructure and affects a covered device or system, but is unable to identify the entity at risk.
