ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

6 U.S.C. § 1526Inventory of cryptographic systems; migration to post-quantum cryptography

submitted 4 years ago by Pub. L. 117-260 to r/title-6-DOMESTIC-SECURITY · 687 words · no verdicts yet

in plain englishAI-generated · not legal advice

OMB must guide agencies in inventorying technology vulnerable to quantum decryption, require reports and migration plans, coordinate interoperability, and report to Congress on post-quantum cryptography.

(a) Inventory. (1) Within 180 days after December 21, 2022, the OMB Director, coordinating with the National Cyber Director and consulting the CISA Director, must issue guidance on moving information technology to post-quantum cryptography. At minimum it must require each agency to keep a current inventory of technology vulnerable to decryption by quantum computers, prioritized under (B); provide criteria for prioritizing inventory work; and describe information required under (b). (2) The guidance must also describe technology to prioritize for migration and an evaluation process for migration progress, automated as much as practicable. (3) The OMB Director must update the guidance as necessary, coordinating with the National Cyber Director and consulting the CISA Director. (b) Agency reports. Within 1 year after December 21, 2022, and continually afterward, each agency head must give the OMB Director, CISA Director, and National Cyber Director the inventory in (a)(1) and other information required under (a)(1)(C). (c) Migration and assessment. Within 1 year after the NIST Director issues post-quantum cryptography standards, the OMB Director must issue guidance requiring each agency to (1) prioritize the technology described in (a)(2)(A) for migration and (2) create a migration plan consistent with that priority. (d) Interoperability. The OMB Director must ensure the priorities under (c)(1) are assessed and coordinated to ensure interoperability. (e) OMB reports. (1) Within 15 months after December 21, 2022, the OMB Director, coordinating with the National Cyber Director and consulting the CISA Director, must report to the Senate Homeland Security and Governmental Affairs Committee and the House Oversight and Reform Committee on (A) a strategy for the risk that quantum computers could weaken or break agency encryption; (B) an estimate of agency funding needed to protect the technology in (a)(1)(A) from that risk; and (C) Federal civilian executive-branch coordination led by NIST, including timelines, to develop post-quantum standards, including Federal Information Processing Standards and voluntary consensus standards such as ISO standards. (2) Within 1 year after issuing guidance under (c)(2), and each year until 5 years after the standards are issued, the OMB Director, coordinating with the National Cyber Director and consulting the CISA Director, must report with the section 3553(c) report to those committees on agency progress in adopting post-quantum standards.
the actual law source: uscode.house.gov ↗public domain
(a) Inventory
(1) Establishment

Not later than 180 days after December 21, 2022, the Director of OMB, in coordination with the National Cyber Director and in consultation with the Director of CISA, shall issue guidance on the migration of information technology to post-quantum cryptography, which shall include at a minimum—

(A)

a requirement for each agency to establish and maintain a current inventory of information technology in use by the agency that is vulnerable to decryption by quantum computers, prioritized using the criteria described in subparagraph (B);

(B)

criteria to allow agencies to prioritize their inventory efforts; and

(C)

a description of the information required to be reported pursuant to subsection (b).

(2) Additional content in guidance

In the guidance established by paragraph (1), the Director of OMB shall include, in addition to the requirements described in that paragraph—

(A)

a description of information technology to be prioritized for migration to post-quantum cryptography; and

(B)

a process for evaluating progress on migrating information technology to post-quantum cryptography, which shall be automated to the greatest extent practicable.

(3) Periodic updates

The Director of OMB shall update the guidance required under paragraph (1) as the Director of OMB determines necessary, in coordination with the National Cyber Director and in consultation with the Director of CISA.

(b) Agency reports

Not later than 1 year after December 21, 2022, and on an ongoing basis thereafter, the head of each agency shall provide to the Director of OMB, the Director of CISA, and the National Cyber Director—

(1)

the inventory described in subsection (a)(1); and

(2)

any other information required to be reported under subsection (a)(1)(C).

(c) Migration and assessment

Not later than 1 year after the date on which the Director of NIST has issued post-quantum cryptography standards, the Director of OMB shall issue guidance requiring each agency to—

(1)

prioritize information technology described under subsection (a)(2)(A) for migration to post-quantum cryptography; and

(2)

develop a plan to migrate information technology of the agency to post-quantum cryptography consistent with the prioritization under paragraph (1).

(d) Interoperability

The Director of OMB shall ensure that the prioritizations made under subsection (c)(1) are assessed and coordinated to ensure interoperability.

(e) Office of Management and Budget reports
(1) Report on post-quantum cryptography

Not later than 15 months after December 21, 2022, the Director of OMB, in coordination with the National Cyber Director and in consultation with the Director of CISA, shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives a report on the following:

(A)

A strategy to address the risk posed by the vulnerabilities of information technology of agencies to weakened encryption due to the potential and possible capability of a quantum computer to breach that encryption.

(B)

An estimate of the amount of funding needed by agencies to secure the information technology described in subsection (a)(1)(A) from the risk posed by an adversary of the United States using a quantum computer to breach the encryption of the information technology.

(C)

A description of Federal civilian executive branch coordination efforts led by the National Institute of Standards and Technology, including timelines, to develop standards for post-quantum cryptography, including any Federal Information Processing Standards developed under chapter 35 of title 44, as well as standards developed through voluntary, consensus standards bodies such as the International Organization for Standardization.

(2) Report on migration to post-quantum cryptography in information technology

Not later than 1 year after the date on which the Director of OMB issues guidance under subsection (c)(2), and thereafter until the date that is 5 years after the date on which post-quantum cryptographic standards are issued, the Director of OMB, in coordination with the National Cyber Director and in consultation with the Director of CISA, shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives, with the report submitted pursuant to section 3553(c) of title 44, a report on the progress of agencies in adopting post-quantum cryptography standards.

Source credit: (Pub. L. 117–260, § 4, Dec. 21, 2022, 136 Stat. 2390.)

history & why it existsrecord from the source credit
  • 2022Enacted · Pub. L. 117-260 · 136 Stat. 2390

A history note hasn’t been published yet. The record shows enactment by Pub. L. 117-260 on 2022-12-21.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case