ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

10 U.S.C. § 393Reporting on penetrations of networks and information systems of certain contractors

submitted 11 years ago by Pub. L. 114-92 to r/title-10-ARMED-FORCES · 832 words · no verdicts yet

in plain englishAI-generated · not legal advice

This law requires cleared defense contractors to report when their networks are hacked. The Department of Defense sets criteria for which networks count and how reports must work. Contractors get legal protection for complying, unless they acted with willful misconduct.

(a) Procedures for Reporting Penetrations: The Secretary of Defense must create procedures requiring every "cleared defense contractor" to report to a Department of Defense component (chosen by the Secretary) whenever one of the contractor's networks or information systems — one that meets the criteria set under (b) — is successfully broken into ("penetrated"). (b) Networks and Information Systems Subject to Reporting: The Secretary must pick a senior official who, working with a listed group of officials — the Under Secretaries for Policy, for Acquisition and Sustainment, for Research and Engineering, and for Intelligence and Security, the Department's Chief Information Officer, and the Commander of U.S. Cyber Command — sets the criteria for which "covered networks" must follow the reporting procedures in (a). (c) Procedure Requirements: The procedures must require contractors to quickly report each successful penetration of a covered network to the designated Department component. Each report must include a description of the technique or method used; a sample of any malicious software the contractor found and isolated; and a summary of any Department-related information that may have been compromised. The procedures must also let Department personnel, on request, get access to a contractor's equipment or information to do their own forensic analysis, in addition to whatever the contractor does — but that access is limited to figuring out whether Department information was stolen ("exfiltrated") and what was taken, and must reasonably protect trade secrets, financial or commercial information, and information that could identify a specific person. Finally, the procedures must limit who can receive the gathered information to entities whose mission it may affect, entities that might help diagnose or fix cyber incidents, entities doing counterintelligence or law enforcement investigations, or entities working on national security, including cyber situational awareness and defense. (d) Protection From Liability of Cleared Defense Contractors: No lawsuit can be brought or continued against a cleared defense contractor for complying with this section the way the procedures require — any such case must be dismissed right away. But this protection does not apply if the contractor engaged in "willful misconduct" while complying, and it does not limit any other legal defenses that might normally apply. If someone claims the protection should not apply because of willful misconduct, that person has the burden of proving — with clear and convincing evidence — that the contractor engaged in willful misconduct and that this misconduct actually caused the person's injury. "Willful misconduct" means an act or failure to act that was intentional and meant to achieve a wrongful purpose; done knowingly, without any legal or factual justification; and done while disregarding a known or obvious risk so great that harm was highly likely to outweigh any benefit. (e) Definitions: "Cleared defense contractor" means a private company the Department of Defense has cleared to access, receive, or store classified information, for bidding on a contract or supporting a Department program. "Covered network" means a network or information system of a cleared defense contractor that holds or processes Department-related information which the contractor is required to give enhanced protection.
the actual law source: uscode.house.gov ↗public domain
(a)Procedures for Reporting Penetrations.—

The Secretary of Defense shall establish procedures that require each cleared defense contractor to report to a component of the Department of Defense designated by the Secretary for purposes of such procedures when a network or information system of such contractor that meets the criteria established pursuant to subsection (b) is successfully penetrated.

(b)Networks and Information Systems Subject to Reporting.—
(1)Criteria.—

The Secretary of Defense shall designate a senior official to, in consultation with the officials specified in paragraph (2), establish criteria for covered networks to be subject to the procedures for reporting system penetrations under subsection (a).

(2)Officials.—

The officials specified in this subsection are the following:

(A)

The Under Secretary of Defense for Policy.

(B)

The Under Secretary of Defense for Acquisition and Sustainment.

(C)

the Under Secretary of Defense for Research and Engineering.

(D)

The Under Secretary of Defense for Intelligence and Security.

(E)

The Chief Information Officer of the Department of Defense.

(F)

The Commander of the United States Cyber Command.

(c)Procedure Requirements.—
(1)Rapid reporting.—

The procedures established pursuant to subsection (a) shall require each cleared defense contractor to rapidly report to a component of the Department of Defense designated pursuant to subsection (a) of each successful penetration of the network or information systems of such contractor that meet the criteria established pursuant to subsection (b). Each such report shall include the following:

(A)

A description of the technique or method used in such penetration.

(B)

A sample of the malicious software, if discovered and isolated by the contractor, involved in such penetration.

(C)

A summary of information created by or for the Department in connection with any Department program that has been potentially compromised due to such penetration.

(2)Access to equipment and information by department of defense personnel.—

The procedures established pursuant to subsection (a) shall—

(A)

include mechanisms for Department of Defense personnel to, upon request, obtain access to equipment or information of a cleared defense contractor necessary to conduct forensic analysis in addition to any analysis conducted by such contractor;

(B)

provide that a cleared defense contractor is only required to provide access to equipment or information as described in subparagraph (A) to determine whether information created by or for the Department in connection with any Department program was successfully exfiltrated from a network or information system of such contractor and, if so, what information was exfiltrated; and

(C)

provide for the reasonable protection of trade secrets, commercial or financial information, and information that can be used to identify a specific person.

(3)Dissemination of information.—

The procedures established pursuant to subsection (a) shall limit the dissemination of information obtained or derived through such procedures to entities—

(A)

with missions that may be affected by such information;

(B)

that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;

(C)

that conduct counterintelligence or law enforcement investigations; or

(D)

for national security purposes, including cyber situational awareness and defense purposes.

(d)Protection From Liability of Cleared Defense Contractors.—
(1)

No cause of action shall lie or be maintained in any court against any cleared defense contractor, and such action shall be promptly dismissed, for compliance with this section that is conducted in accordance with the procedures established pursuant to subsection (a).

(2)
(A)

Nothing in this section shall be construed—

(i)

to require dismissal of a cause of action against a cleared defense contractor that has engaged in willful misconduct in the course of complying with the procedures established pursuant to subsection (a); or

(ii)

to undermine or limit the availability of otherwise applicable common law or statutory defenses.

(B)

In any action claiming that paragraph (1) does not apply due to willful misconduct described in subparagraph (A), the plaintiff shall have the burden of proving by clear and convincing evidence the willful misconduct by each cleared defense contractor subject to such claim and that such willful misconduct proximately caused injury to the plaintiff.

(C)

In this subsection, the term “willful misconduct” means an act or omission that is taken—

(i)

intentionally to achieve a wrongful purpose;

(ii)

knowingly without legal or factual justification; and

(iii)

in disregard of a known or obvious risk that is so great as to make it highly probable that the harm will outweigh the benefit.

(e)Definitions.—

In this section:

(1)Cleared defense contractor.—

The term “cleared defense contractor” means a private entity granted clearance by the Department of Defense to access, receive, or store classified information for the purpose of bidding for a contract or conducting activities in support of any program of the Department of Defense.

(2)Covered network.—

The term “covered network” means a network or information system of a cleared defense contractor that contains or processes information created by or for the Department of Defense with respect to which such contractor is required to apply enhanced protection.

Source credit: (Added and amended Pub. L. 114–92, div. A, title XVI, § 1641(a), Nov. 25, 2015, 129 Stat. 1114; Pub. L. 116–92, div. A, title IX, § 902(8), title XVI, § 1621(e)(1)(A)(vi), Dec. 20, 2019, 133 Stat. 1543, 1733; Pub. L. 116–283, div. A, title X, § 1081(a)(15), Jan. 1, 2021, 134 Stat. 3871; Pub. L. 117–81, div. A, title X, § 1081(a)(9), Dec. 27, 2021, 135 Stat. 1920.)

history & why it existsrecord from the source credit
  • 2015Enacted · Pub. L. 114-92 · 129 Stat. 1114
  • 2019Amended · Pub. L. 116-92 · 133 Stat. 1543, 1733
  • 2021Amended · Pub. L. 116-283 · 134 Stat. 3871
  • 2021Amended · Pub. L. 117-81 · 135 Stat. 1920

A history note hasn’t been published yet. The record shows enactment by Pub. L. 114-92 on 2015-11-25.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case