ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

42 U.S.C. § 18445Information security

submitted 16 years ago by Pub. L. 111-267 to r/title-42-THE-PUBLIC-HEALTH-AND-WELFARE · 364 words · no verdicts yet

in plain englishAI-generated · not legal advice

NASA's chief information officer must monitor cybersecurity risks and report to Congress every two years. NASA must also train everyone who uses its information systems on security awareness, with rewards for high achievers. The section defines "information infrastructure."

(a) Monitoring risk (1) Update on system implementation — Every 2 years starting 120 days after October 11, 2010, NASA's chief information officer must work with other national security agencies and report to the right congressional committees on three things: (A) how NASA is doing on building a system that gives real-time information about the risk of unauthorized access — whether it's remote, close-up ("proximity"), or from insiders — to all of NASA's information systems and networks, including contractor networks; (B) whether this system has actually and measurably lowered network risk compared to other ways of measuring security; and (C) how much progress each NASA center and facility has made in putting the system in place. (2) Existing assessments — The Inspector General already has to check NASA's systems under a separate law (title 44, section 3545). Those checks must also judge whether the risk-monitoring system described above is actually working. (b) Information security awareness and education (1) In general — The chief information officer, working with the Department of Education and other agencies, must create a security awareness and training program for everyone who operates or uses NASA's information systems. The goal is to cut down on unauthorized remote, proximity, and insider access. (2) Program requirements — (A) The program must include ongoing briefings on threats, both classified and unclassified, plus automated drills that simulate real attack methods. (B) Every NASA employee and contractor who works with NASA's information systems must take part in the program. (C) Only people who keep meeting the program's requirements may access NASA's information systems. (D) NASA's chief human capital officer, working with the chief information officer, must create a system to reward people who consistently do well in the program. (c) Information infrastructure defined — "Information infrastructure" means the underlying framework — including programmable electronic devices, communications networks, and any related hardware, software, or data — that information systems depend on to process, send, receive, or store information electronically.
the actual law source: uscode.house.gov ↗public domain
(a) Monitoring risk
(1) Update on system implementation

Not later than 120 days after October 11, 2010, and on a biennial basis thereafter, the chief information officer of NASA, in coordination with other national security agencies, shall provide to the appropriate committees of Congress

(A)

an update on efforts to implement a system to provide dynamic, comprehensive, real-time information regarding risk of unauthorized remote, proximity, and insider use or access, for all information infrastructure under the responsibility of the chief information officer, and mission-related networks, including contractor networks;

(B)

an assessment of whether the system has demonstrably and quantifiably reduced network risk compared to alternative methods of measuring security; and

(C)

an assessment of the progress that each center and facility has made toward implementing the system.

(2) Existing assessments

The assessments required of the Inspector General under section 3545 1 of title 44 shall evaluate the effectiveness of the system described in this subsection.

(b) Information security awareness and education
(1) In general

In consultation with the Department of Education, other national security agencies, and other agency directorates, the chief information officer shall institute an information security awareness and education program for all operators and users of NASA information infrastructure, with the goal of reducing unauthorized remote, proximity, and insider use or access.

(2) Program requirements
(A)

The program shall include, at a minimum, ongoing classified and unclassified threat-based briefings, and automated exercises and examinations that simulate common attack techniques.

(B)

All agency employees and contractors engaged in the operation or use of agency information infrastructure shall participate in the program.

(C)

Access to NASA information infrastructure shall only be granted to operators and users who regularly satisfy the requirements of the program.

(D)

The chief human capital officer of NASA, in consultation with the chief information officer, shall create a system to reward operators and users of agency information infrastructure for continuous high achievement in the program.

(c) Information infrastructure defined

In this section, the term “information infrastructure” means the underlying framework that information systems and assets rely on to process, transmit, receive, or store information electronically, including programmable electronic devices and communications networks and any associated hardware, software, or data.

Source credit: (Pub. L. 111–267, title XII, § 1207, Oct. 11, 2010, 124 Stat. 2844.)

history & why it existsrecord from the source credit
  • 2010Enacted · Pub. L. 111-267 · 124 Stat. 2844

A history note hasn’t been published yet. The record shows enactment by Pub. L. 111-267 on 2010-10-11.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case