ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

6 U.S.C. § 1524Assessment; reports

submitted 11 years ago by Pub. L. 114-113 to r/title-6-DOMESTIC-SECURITY · 1,034 words · no verdicts yet

in plain englishAI-generated · not legal advice

This section requires reviews and reports about Federal agency cybersecurity systems, intrusion detection, prevention, and assessment. It defines the terms used and permits the reports to include a classified annex.

(a) Definitions. In this section: (1) “Agency information” has the meaning given in section 2213 of the Homeland Security Act of 2002 (6 U.S.C. 663). (2) “Cyber threat indicator” and “defensive measure” have the meanings given in section 650 of this title. (3) “Intrusion assessments” means actions under the intrusion assessment plan to find and remove intruders from agency information systems. (4) “Intrusion assessment plan” means the plan required by section 2210(b)(1) of the Homeland Security Act of 2002 (6 U.S.C. 660(b)(1)). (5) “Intrusion detection and prevention capabilities” means the capabilities required by section 2213(b) of that Act (6 U.S.C. 663(b)). (b) Third-party assessment. No later than 3 years after December 18, 2015, the Comptroller General must study and publish a report on how effective the Federal Government’s approach and strategy are for securing agency information systems. The study must include the intrusion detection and prevention capabilities and the intrusion assessment plan. (c) Reports to Congress. (1) Intrusion detection and prevention capabilities. (A) Secretary of Homeland Security report. No later than 6 months after December 18, 2015, and every year after that, the Secretary must send the appropriate congressional committees a report on implementation of the intrusion detection and prevention capabilities. The report must include: (i) a description of privacy controls; (ii) the technologies and capabilities used to detect cybersecurity risks in network traffic, including how much they use existing commercial and noncommercial technologies; (iii) the technologies and capabilities used to stop network traffic linked to cybersecurity risks from traveling to or from agency information systems, including how much they use existing commercial and noncommercial technologies; (iv) for each version of the capabilities, the types of indicators, identifiers, or techniques used to detect cybersecurity risks in such traffic and the number of each type; (v) the number of times the capabilities detected a cybersecurity risk in such traffic and the number of times they blocked traffic linked to a cybersecurity risk; and (vi) a description of the pilot under section 2213(c)(5) of the Homeland Security Act of 2002 (6 U.S.C. 663(c)(5)), including the number of new technologies tested and participating agencies. (B) OMB report. No later than 18 months after December 18, 2015, and every year after that, the Director must include in the report required by section 3553(c) of title 44 an analysis of how agencies applied the capabilities. It must list each agency and how extensively it applied them to an agency information system. For each agency it must also list (I) the number of times the capabilities detected a cybersecurity risk in traffic to or from an agency information system and the types of indicators, identifiers, and techniques used; and (II) the number of times they stopped such traffic and the types of indicators, identifiers, and techniques used to detect cybersecurity risks in that traffic. (C) Federal Chief Information Officer. Between 18 months and 2 years after December 18, 2015, the Federal Chief Information Officer must review and report to the appropriate congressional committees on the intrusion detection and prevention capabilities. The report must assess (i) how effectively the system detects, disrupts, and prevents cyber-threat actors, including advanced persistent threats, from accessing agency information and systems; (ii) whether those capabilities, continuous diagnostics and mitigation, and other systems under subtitle D of title II of the Homeland Security Act of 2002 (6 U.S.C. 231 et seq.) secure Federal information systems effectively; (iii) the costs and benefits of the capabilities compared with commercial technologies and tools, including the value of classified cyber threat indicators; and (iv) whether agencies can protect sensitive cyber threat indicators and defensive measures if they are shared through unclassified mechanisms for commercial technologies and tools. (2) OMB report on the intrusion assessment plan, advanced internal defenses, and Federal cybersecurity requirements. The Director must: (A) no later than 6 months after December 18, 2015, and 30 days after each update, send the plan to the appropriate congressional committees; (B) no later than 1 year after December 18, 2015, and every year after that, include in the section 3553(c) report (i) a description of implementation of the plan; (ii) the findings of assessments under the plan; (iii) a description of advanced network-security tools used to continuously diagnose and mitigate cybersecurity risks under section 1522(a)(1); and (iv) an agency-by-agency list of compliance with section 1523(b); and (C) no later than 1 year after December 18, 2015, send the appropriate congressional committees (i) a copy of the plan under section 1522(a)(2); and (ii) the improved metrics under section 1522(c). (d) Form. Each report required by this section must be submitted in unclassified form, but it may include a classified annex.
the actual law source: uscode.house.gov ↗public domain
(a) Definitions

In this section:

(1) Agency information

The term “agency information” has the meaning given the term in section 2213 of the Homeland Security Act of 2002 [6 U.S.C. 663].

(2) Cyber threat indicator; defensive measure

The terms “cyber threat indicator” and “defensive measure” have the meanings given those terms in section 650 of this title.

(3) Intrusion assessments

The term “intrusion assessments” means actions taken under the intrusion assessment plan to identify and remove intruders in agency information systems.

(4) Intrusion assessment plan

The term “intrusion assessment plan” means the plan required under section 2210(b)(1) of the Homeland Security Act of 2002 [6 U.S.C. 660(b)(1)].

(5) Intrusion detection and prevention capabilities

The term “intrusion detection and prevention capabilities” means the capabilities required under section 2213(b) of the Homeland Security Act of 2002 [6 U.S.C. 663(b)].

(b) Third-party assessment

Not later than 3 years after December 18, 2015, the Comptroller General of the United States shall conduct a study and publish a report on the effectiveness of the approach and strategy of the Federal Government to securing agency information systems, including the intrusion detection and prevention capabilities and the intrusion assessment plan.

(c) Reports to Congress
(1) Intrusion detection and prevention capabilities
(A) Secretary of Homeland Security report

Not later than 6 months after December 18, 2015, and annually thereafter, the Secretary shall submit to the appropriate congressional committees a report on the status of implementation of the intrusion detection and prevention capabilities, including—

(i)

a description of privacy controls;

(ii)

a description of the technologies and capabilities utilized to detect cybersecurity risks in network traffic, including the extent to which those technologies and capabilities include existing commercial and noncommercial technologies;

(iii)

a description of the technologies and capabilities utilized to prevent network traffic associated with cybersecurity risks from transiting or traveling to or from agency information systems, including the extent to which those technologies and capabilities include existing commercial and noncommercial technologies;

(iv)

a list of the types of indicators or other identifiers or techniques used to detect cybersecurity risks in network traffic transiting or traveling to or from agency information systems on each iteration of the intrusion detection and prevention capabilities and the number of each such type of indicator, identifier, and technique;

(v)

the number of instances in which the intrusion detection and prevention capabilities detected a cybersecurity risk in network traffic transiting or traveling to or from agency information systems and the number of times the intrusion detection and prevention capabilities blocked network traffic associated with cybersecurity risk; and

(vi)

a description of the pilot established under section 2213(c)(5) of the Homeland Security Act of 2002 [6 U.S.C. 663(c)(5)], including the number of new technologies tested and the number of participating agencies.

(B) OMB report

Not later than 18 months after December 18, 2015, and annually thereafter, the Director shall submit to Congress, as part of the report required under section 3553(c) of title 44, an analysis of agency application of the intrusion detection and prevention capabilities, including—

(i)

a list of each agency and the degree to which each agency has applied the intrusion detection and prevention capabilities to an agency information system; and

(ii)

a list by agency of—

(I)

the number of instances in which the intrusion detection and prevention capabilities detected a cybersecurity risk in network traffic transiting or traveling to or from an agency information system and the types of indicators, identifiers, and techniques used to detect such cybersecurity risks; and

(II)

the number of instances in which the intrusion detection and prevention capabilities prevented network traffic associated with a cybersecurity risk from transiting or traveling to or from an agency information system and the types of indicators, identifiers, and techniques used to detect such agency information systems.

(C) Chief information officer

Not earlier than 18 months after December 18, 2015, and not later than 2 years after December 18, 2015, the Federal Chief Information Officer shall review and submit to the appropriate congressional committees a report assessing the intrusion detection and intrusion prevention capabilities, including—

(i)

the effectiveness of the system in detecting, disrupting, and preventing cyber-threat actors, including advanced persistent threats, from accessing agency information and agency information systems;

(ii)

whether the intrusion detection and prevention capabilities, continuous diagnostics and mitigation, and other systems deployed under subtitle D 1 of title II of the Homeland Security Act of 2002 (6 U.S.C. 231 et seq.) are effective in securing Federal information systems;

(iii)

the costs and benefits of the intrusion detection and prevention capabilities, including as compared to commercial technologies and tools and including the value of classified cyber threat indicators; and

(iv)

the capability of agencies to protect sensitive cyber threat indicators and defensive measures if they were shared through unclassified mechanisms for use in commercial technologies and tools.

(2) OMB report on development and implementation of intrusion assessment plan, advanced internal defenses, and Federal cybersecurity requirements

The Director shall—

(A)

not later than 6 months after December 18, 2015, and 30 days after any update thereto, submit the intrusion assessment plan to the appropriate congressional committees;

(B)

not later than 1 year after December 18, 2015, and annually thereafter, submit to Congress, as part of the report required under section 3553(c) of title 44

(i)

a description of the implementation of the intrusion assessment plan;

(ii)

the findings of the intrusion assessments conducted pursuant to the intrusion assessment plan;

(iii)

a description of the advanced network security tools included in the efforts to continuously diagnose and mitigate cybersecurity risks pursuant to section 1522(a)(1) of this title; and

(iv)

a list by agency of compliance with the requirements of section 1523(b) of this title; and

(C)

not later than 1 year after December 18, 2015, submit to the appropriate congressional committees—

(i)

a copy of the plan developed pursuant to section 1522(a)(2) of this title; and

(ii)

the improved metrics developed pursuant to section 1522(c) of this title.

(d) Form

Each report required under this section shall be submitted in unclassified form, but may include a classified annex.

Source credit: (Pub. L. 114–113, div. N, title II, § 226, Dec. 18, 2015, 129 Stat. 2969; Pub. L. 115–278, § 2(h)(1)(F), Nov. 16, 2018, 132 Stat. 4182; Pub. L. 117–263, div. G, title LXXI, § 7143(d)(1)(B), Dec. 23, 2022, 136 Stat. 3663.)

history & why it existsrecord from the source credit
  • 2015Enacted · Pub. L. 114-113 · 129 Stat. 2969
  • 2018Amended · Pub. L. 115-278 · 132 Stat. 4182
  • 2022Amended · Pub. L. 117-263 · 136 Stat. 3663

A history note hasn’t been published yet. The record shows enactment by Pub. L. 114-113 on 2015-12-18.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case