ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

10 U.S.C. § 499Annual assessment of cyber resiliency of nuclear command and control system

submitted 9 years ago by Pub. L. 115-91 to r/title-10-ARMED-FORCES · 581 words · no verdicts yet

in plain englishAI-generated · not legal advice

Each year, Strategic Command and Cyber Command must jointly assess nuclear system cyber resiliency. They report results and recommendations up to the Secretary of Defense and Congress. They must also brief Congress quarterly on cyber intrusions; this duty ends in 2032.

(a) In General. Not less than once a year, the Commander of U.S. Strategic Command and the Commander of U.S. Cyber Command (called "the Commanders") must together assess how resilient the nuclear command and control system is against cyber attacks. (b) Elements. When they do this assessment, the Commanders must: (1) Check whether the nuclear command and control system is strong and resilient enough to keep working through a cyber attack from Russia, China, or any other country or group the Commanders name as a potential threat. (2) Come up with recommendations to fix any concerns the assessment raises. (c) Reports Required. (1) For each assessment, the Commanders must jointly send a report to the Chairman of the Joint Chiefs of Staff. The Chairman passes it to the Council on Oversight of the National Leadership Command, Control, and Communications System. The report must include: (A) The recommendations from subsection (b)(2). (B) How confident each Commander is that the nuclear deterrent can survive a top-tier cyber threat. (C) A detailed description of how the assessment was done and the technical reasoning behind its conclusions. (D) Any other comments the Commanders want to add. (2) The Council must send each report, plus its own comments, to the Secretary of Defense. (3) Within 90 days of getting a report, the Secretary of Defense must send it to the congressional defense committees, along with the Council's comments and the Secretary's own comments. (d) Quarterly Briefings. (1) At least once every quarter, the Deputy Secretary of Defense and the Vice Chairman of the Joint Chiefs of Staff must jointly brief the House and Senate Armed Services Committees. This briefing must cover: (A) Any intrusion or anomaly in the nuclear command, control, and communications system found during the previous quarter, including: (i) An assessment of any known, suspected, or possible impact on military mission effectiveness as of the briefing date; and (ii) Information about cyber intrusions into contractor networks that are known or suspected to have leaked design information about the nuclear command, control, and communications system; or (B) If no such intrusion or anomaly happened that quarter, a notice saying so. (2) This subsection defines two terms: (A) "Anomaly" means a malicious, suspicious, or abnormal cyber incident that could threaten U.S. national security or interests, or that is likely to cause real harm to U.S. national security. (B) "Intrusion" means an unauthorized, malicious cyber incident that breaks into a nuclear command, control, and communications system — either by breaking its security or by forcing it into an unsafe state. (e) Termination. All the requirements in this section end on December 31, 2032.
the actual law source: uscode.house.gov ↗public domain
(a)In General.—

Not less frequently than annually, the Commander of the United States Strategic Command and the Commander of the United States Cyber Command (in this section referred to collectively as the “Commanders”) shall jointly conduct an assessment of the cyber resiliency of the nuclear command and control system.

(b)Elements.—

In conducting the assessment required by subsection (a), the Commanders shall—

(1)

conduct an assessment of the sufficiency and resiliency of the nuclear command and control system to operate through a cyber attack from the Russian Federation, the People’s Republic of China, or any other country or entity the Commanders identify as a potential threat; and

(2)

develop recommendations for mitigating any concerns of the Commanders resulting from the assessment.

(c)Reports Required.—
(1)

For each assessment conducted under subsection (a), the Commanders shall jointly submit to the Chairman of the Joint Chiefs of Staff, for submission to the Council on Oversight of the National Leadership Command, Control, and Communications System established under section 171a of this title, a report on the assessment that includes the following:

(A)

The recommendations developed under subsection (b)(2).

(B)

A statement of the degree of confidence of each of the Commanders in the mission assurance of the nuclear deterrent against a top tier cyber threat.

(C)

A detailed description of the approach used to conduct the assessment required by subsection (a) and the technical basis of conclusions reached in conducting that assessment.

(D)

Any other comments of the Commanders.

(2)

The Council shall submit to the Secretary of Defense each report required by paragraph (1) and any comments of the Council on each report.

(3)

Not later than 90 days after the date of the submission of a report under paragraph (1), the Secretary of Defense shall submit to the congressional defense committees the report, any comments of the Council on the report under paragraph (2), and any comments of the Secretary on the report.

(d)Quarterly Briefings.—
(1)

Not less than once every quarter, the Deputy Secretary of Defense and the Vice Chairman of the Joint Chiefs of Staff shall jointly provide to the Committees on Armed Services of the House of Representatives and the Senate—

(A)

a briefing on any intrusion or anomaly in the nuclear command, control, and communications system that was identified during the previous quarter, including—

(i)

an assessment of any known, suspected, or potential impacts of such intrusions and anomalies to the mission effectiveness of military capabilities as of the date of the briefing; and

(ii)

with respect to cyber intrusions of contractor networks known or suspected to have resulted in the loss or compromise of design information regarding the nuclear command, control, and communications system; or

(B)

if no such intrusion or anomaly occurred with respect to the quarter to be covered by that briefing, a notification of such lack of intrusions and anomalies.

(2)

In this subsection:

(A)

The term “anomaly” means a malicious, suspicious or abnormal cyber incident that potentially threatens the national security or interests of the United States, or that is likely to result in demonstrable harm to the national security of the United States.

(B)

The term “intrusion” means an unauthorized and malicious cyber incident that compromises a nuclear command, control, and communications system by breaking the security of such a system or causing it to enter into an insecure state.

(e)Termination.—

The requirements of this section shall terminate on December 31, 2032.

Source credit: (Added Pub. L. 115–91, div. A, title XVI, § 1651(a), Dec. 12, 2017, 131 Stat. 1756; amended Pub. L. 117–81, div. A, title XV, § 1534, Dec. 27, 2021, 135 Stat. 2054; Pub. L. 117–263, div. A, title XVI, § 1636(a), (b), Dec. 23, 2022, 136 Stat. 2940.)

history & why it existsrecord from the source credit
  • 2017Enacted · Pub. L. 115-91 · 131 Stat. 1756
  • 2021Amended · Pub. L. 117-81 · 135 Stat. 2054
  • 2022Amended · Pub. L. 117-263 · 136 Stat. 2940

A history note hasn’t been published yet. The record shows enactment by Pub. L. 115-91 on 2017-12-12.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case