ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

10 U.S.C. § 2225Insider threat detection

submitted 1 year ago by Pub. L. 119-60 to r/title-10-ARMED-FORCES · 370 words · no verdicts yet

in plain englishAI-generated · not legal advice

The Secretary must establish an insider-threat detection and information-protection program.

(a) The Secretary must establish an information-sharing, protection, and insider-threat program for Department systems to detect unauthorized access to, use of, or transmission of classified or controlled unclassified information. (b) The program must include (1) technology for centralized monitoring, including (A) external-port and read/write controls, (B) disabling removable-media ports, (C) electronic auditing and reporting of unusual or unauthorized activity, (D) data-loss prevention and data-rights management to prevent unauthorized export of information from a network or make the information unusable if it is exported without authorization, (E) role-based access certification, (F) cross-domain transfer guards, and (G) patch and security-update management; (2) supporting policies and procedures, with special attention to international and interagency partners and operations in hostilities; (3) governance integrating technology with those policies, including (A) coordination with clearance and suitability reviews, (B) existing anomaly detection used in counterintelligence or screening, and (C) faster classification review and marking; (4) continuing analysis of (A) security gaps and (B) technology, policies, and processes needed to increase the program’s capability beyond its initially established full operating capability to address those gaps; (5) a baseline framework measuring performance and effectiveness; (6) a plan for related security measures at other agencies with network access; and (7) uniform enforcement and implementation.
the actual law source: uscode.house.gov ↗public domain
(a)Program Required.—

The Secretary of Defense shall establish a program for information sharing protection and insider threat mitigation for the information systems of the Department of Defense to detect unauthorized access to, use of, or transmission of classified or controlled unclassified information.

(b)Elements.—

The program established under subsection (a) shall include the following:

(1)

Technology solutions for deployment within the Department of Defense that allow for centralized monitoring and detection of unauthorized activities, including—

(A)

monitoring the use of external ports and read and write capability controls;

(B)

disabling the removable media ports of computers physically or electronically;

(C)

electronic auditing and reporting of unusual and unauthorized user activities;

(D)

using data-loss prevention and data-rights management technology to prevent the unauthorized export of information from a network or to render such information unusable in the event of the unauthorized export of such information;

(E)

a roles-based access certification system;

(F)

cross-domain guards for transfers of information between different networks; and

(G)

patch management for software and security updates.

(2)

Policies and procedures to support such program, including special consideration for policies and procedures related to international and interagency partners and activities in support of ongoing operations in areas of hostilities.

(3)

A governance structure and process that integrates information security and sharing technologies with the policies and procedures referred to in paragraph (2). Such structure and process shall include—

(A)

coordination with the existing security clearance and suitability review process;

(B)

coordination of existing anomaly detection techniques, including those used in counterintelligence investigation or personnel screening activities; and

(C)

updating and expediting of the classification review and marking process.

(4)

A continuing analysis of—

(A)

gaps in security measures under the program; and

(B)

technology, policies, and processes needed to increase the capability of the program beyond the initially established full operating capability to address such gaps.

(5)

A baseline analysis framework that includes measures of performance and effectiveness.

(6)

A plan for how to ensure related security measures are put in place for other departments or agencies with access to Department of Defense networks.

(7)

A plan for enforcement to ensure that the program is being applied and implemented on a uniform and consistent basis.

Source credit: (Added Pub. L. 119–60, div. A, title XVI, § 1623(a), Dec. 18, 2025, 139 Stat. 1183.)

history & why it existsrecord from the source credit
  • 2025Enacted · Pub. L. 119-60 · 139 Stat. 1183

A history note hasn’t been published yet. The record shows enactment by Pub. L. 119-60 on 2025-12-18.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case