ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

10 U.S.C. § 395Notification requirements for sensitive military cyber operations

submitted 9 years ago by Pub. L. 115-91 to r/title-10-ARMED-FORCES · 595 words · no verdicts yet

in plain englishAI-generated · not legal advice

This law requires the Secretary of Defense to notify Congress within 48 hours of sensitive military cyber operations. It defines what counts as sensitive using risk factors like collateral effects and detection risk. Training exercises and covert actions are excluded from this notice rule.

(a) In General: Except as (d) allows, the Secretary of Defense must promptly give the congressional defense committees written notice of any "sensitive military cyber operation" conducted under this title, no later than 48 hours after the operation happens. (b) Procedures: The Secretary must create and submit to the congressional defense committees procedures for meeting the requirement in (a), consistent with national security and protecting how operations work. If the Secretary changes these procedures, the committees must be notified in writing at least 14 days before the change takes effect. The congressional defense committees must make sure their own procedures for protecting classified national security information are strong enough to protect the information submitted to them under this section. If a sensitive military cyber operation covered by this section is disclosed without authorization, the Secretary must make sure, as much as practically possible, that the committees are notified immediately. That notice can be verbal or written, but if it is verbal, a written notice signed by the Secretary or the Secretary's designee must follow within 48 hours. (c) Sensitive Military Cyber Operation Defined: A "sensitive military cyber operation" is an offensive or defensive cyber operation that is carried out by U.S. armed forces; is meant to achieve a cyber effect against a foreign terrorist organization, or against a country — including its armed forces and that country's proxy forces elsewhere — where either U.S. armed forces are not involved in "hostilities" with that country, as defined in the War Powers Resolution, or the U.S. has not publicly acknowledged being involved in hostilities with that country; and either is determined to have a medium or high collateral-effects estimate, a medium or high risk of intelligence gain or loss, a medium or high chance of political retaliation based on a political-military assessment in the operation's plan, a medium or high chance of unintended detection, or medium or high collateral effects — or is an operation the Secretary decides should count as sensitive for other reasons. (d) Exceptions: The notification requirement in (a) does not apply to a training exercise done with the consent of every nation where the exercise's intended effects will happen, or to a "covert action," as defined in section 503 of the National Security Act of 1947. (e) Rule of Construction: Nothing in this section should be read to create new authority, or to change the War Powers Resolution, the 2001 Authorization for Use of Military Force, or any requirement under the National Security Act of 1947.
the actual law source: uscode.house.gov ↗public domain
(a)In General.—

Except as provided in subsection (d), the Secretary of Defense shall promptly submit to the congressional defense committees notice in writing of any sensitive military cyber operation conducted under this title no later than 48 hours following such operation.

(b)Procedures.—
(1)

The Secretary of Defense shall establish and submit to the congressional defense committees procedures for complying with the requirements of subsection (a) consistent with the national security of the United States and the protection of operational integrity. The Secretary shall promptly notify the congressional defense committees in writing of any changes to such procedures at least 14 days prior to the adoption of any such changes.

(2)

The congressional defense committees shall ensure that committee procedures designed to protect from unauthorized disclosure classified information relating to national security of the United States are sufficient to protect the information that is submitted to the committees pursuant to this section.

(3)

In the event of an unauthorized disclosure of a sensitive military cyber operation covered by this section, the Secretary shall ensure, to the maximum extent practicable, that the congressional defense committees are notified immediately of the sensitive military cyber operation concerned. The notification under this paragraph may be verbal or written, but in the event of a verbal notification a written notification, signed by the Secretary, or the Secretary’s designee, shall be provided by not later than 48 hours after the provision of the verbal notification.

(c)Sensitive Military Cyber Operation Defined.—
(1)

In this section, the term “sensitive military cyber operation” means an action described in paragraph (2) that—

(A)

is carried out by the armed forces of the United States;

(B)

is intended to achieve a cyber effect against a foreign terrorist organization or a country, including its armed forces and the proxy forces of that country located elsewhere—

(i)

with which the armed forces of the United States are not involved in hostilities (as that term is used in section 4 of the War Powers Resolution (50 U.S.C. 1543)); or

(ii)

with respect to which the involvement of the armed forces of the United States in hostilities has not been acknowledged publicly by the United States; and

(C)
(i)

is determined to—

(I)

have a medium or high collateral effects estimate;

(II)

have a medium or high intelligence gain or loss;

(III)

have a medium or high probability of political retaliation, as determined by the political military assessment contained within the associated concept of operations;

(IV)

have a medium or high probability of detection when detection is not intended; or

(V)

result in medium or high collateral effects; or

(ii)

is a matter the Secretary determines to be appropriate.

(2)

The actions described in this paragraph are the following:

(A)

An offensive cyber operation.

(B)

A defensive cyber operation.

(d)Exceptions.—

The notification requirement under subsection (a) does not apply—

(1)

to a training exercise conducted with the consent of all nations where the intended effects of the exercise will occur; or

(2)

to a covert action (as that term is defined in section 503 of the National Security Act of 1947 (50 U.S.C. 3093)).

(e)Rule of Construction.—

Nothing in this section shall be construed to provide any new authority or to alter or otherwise affect the War Powers Resolution (50 U.S.C. 1541 et seq.), the Authorization for Use of Military Force (Public Law 107–40; 50 U.S.C. 1541 note), or any requirement under the National Security Act of 1947 (50 U.S.C. 3001 et seq.).

Source credit: (Added Pub. L. 115–91, div. A, title XVI, § 1631(a), Dec. 12, 2017, 131 Stat. 1736, § 130j; renumbered § 395 and amended Pub. L. 115–232, div. A, title X, § 1081(a)(1), title XVI, § 1631(a), Aug. 13, 2018, 132 Stat. 1983, 2123; Pub. L. 116–92, div. A, title XVI, § 1632, Dec. 20, 2019, 133 Stat. 1745; Pub. L. 116–283, div. A, title XVII, § 1702, Jan. 1, 2021, 134 Stat. 4080.)

history & why it existsrecord from the source credit
  • 2017Enacted · Pub. L. 115-91 · 131 Stat. 1736
  • 2018Amended · Pub. L. 115-232 · 132 Stat. 1983, 2123
  • 2019Amended · Pub. L. 116-92 · 133 Stat. 1745
  • 2021Amended · Pub. L. 116-283 · 134 Stat. 4080

A history note hasn’t been published yet. The record shows enactment by Pub. L. 115-91 on 2017-12-12.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case