ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

6 U.S.C. § 663Federal intrusion detection and prevention system

submitted 11 years ago by Pub. L. 107-296 to r/title-6-DOMESTIC-SECURITY · 834 words · no verdicts yet

in plain englishAI-generated · not legal advice

This section requires a Federal intrusion-detection and prevention capability and sets rules for its operation, information use, private contractors, privacy, and liability. It defines “agency,” “agency information,” and “agency information system.”

(a) Definitions. In this section: (1) “Agency” has the meaning in section 3502 of title 44. (2) “Agency information” means information an agency collects or maintains, or that someone collects or maintains for it. (3) “Agency information system” has the meaning in section 660 of this title. (b) Requirement. (1) No later than one year after December 18, 2015, the Secretary must deploy, operate, and maintain, for any agency’s use with or without reimbursement: (A) a capability to detect cybersecurity risks in network traffic going to, from, or through an agency information system; and (B) a capability to stop traffic associated with those risks from doing so, or change it to remove the risk. (2) The Secretary must regularly add new technology and change existing technology as appropriate to improve those capabilities. (c) Activities. To carry out subsection (b), the Secretary (1) may access information going to, from, or through an agency system, and an agency head may disclose it to the Secretary or an assisting private entity, regardless of access location, despite other laws that would restrict or prevent disclosure; (2) may contract or otherwise obtain private-entity assistance to deploy, operate, and maintain the technology; (3) may keep, use, and disclose obtained information only to protect information and systems from cybersecurity risks; (4) must regularly test and evaluate advanced protective technologies in real or simulated environments, including commercial, noncommercial, and non-signature-based detection, and acquire, test, and deploy them when appropriate; (5) must create a pilot to acquire, test, and deploy those technologies as quickly as possible; and (6) must periodically update the privacy-impact assessment required by section 208(b) of the E-Government Act of 2002. (d) Principles. The Secretary must ensure that (1) activities are reasonably necessary to protect agency information and systems from cybersecurity risk; (2) accessed information is kept no longer than reasonably necessary for that protection; (3) system users receive notice that their communications may be accessed to protect information and the system; and (4) activities follow policies and procedures governing the capabilities. (e) Private entities. (1) A private assisting entity may not (A) disclose system traffic to anyone except the Department or the agency that disclosed it, including specific personal information not directly related to a cybersecurity risk, or (B) use the traffic for any purpose other than protecting agency information and systems from risks, administering an agreement under subsection (c)(2), or another contract with the Secretary. (2) No court action may be brought against a private entity for assistance provided under this section or an agreement under subsection (c)(2). (3) This protection does not authorize an Internet service provider to break a customer’s user agreement without the customer’s consent. (f) Privacy Officer review. Within one year after December 18, 2015, the Privacy Officer appointed under section 142, consulting the Attorney General, must review the program’s policies and guidelines to ensure consistency with privacy laws, including laws governing acquiring, intercepting, keeping, using, and disclosing communications.
the actual law source: uscode.house.gov ↗public domain
(a) Definitions

In this section—

(1)

the term “agency” has the meaning given the term in section 3502 of title 44;

(2)

the term “agency information” means information collected or maintained by or on behalf of an agency; 1

(3)

the term “agency information system” has the meaning given the term in section 660 of this title; and 2

(b) Requirement
(1) In general

Not later than 1 year after December 18, 2015, the Secretary shall deploy, operate, and maintain, to make available for use by any agency, with or without reimbursement—

(A)

a capability to detect cybersecurity risks in network traffic transiting or traveling to or from an agency information system; and

(B)

a capability to prevent network traffic associated with such cybersecurity risks from transiting or traveling to or from an agency information system or modify such network traffic to remove the cybersecurity risk.

(2) Regular improvement

The Secretary shall regularly deploy new technologies and modify existing technologies to the intrusion detection and prevention capabilities described in paragraph (1) as appropriate to improve the intrusion detection and prevention capabilities.

(c) Activities

In carrying out subsection (b), the Secretary—

(1)

may access, and the head of an agency may disclose to the Secretary or a private entity providing assistance to the Secretary under paragraph (2), information transiting or traveling to or from an agency information system, regardless of the location from which the Secretary or a private entity providing assistance to the Secretary under paragraph (2) accesses such information, notwithstanding any other provision of law that would otherwise restrict or prevent the head of an agency from disclosing such information to the Secretary or a private entity providing assistance to the Secretary under paragraph (2);

(2)

may enter into contracts or other agreements with, or otherwise request and obtain the assistance of, private entities to deploy, operate, and maintain technologies in accordance with subsection (b);

(3)

may retain, use, and disclose information obtained through the conduct of activities authorized under this section only to protect information and information systems from cybersecurity risks;

(4)

shall regularly assess through operational test and evaluation in real world or simulated environments available advanced protective technologies to improve detection and prevention capabilities, including commercial and noncommercial technologies and detection technologies beyond signature-based detection, and acquire, test, and deploy such technologies when appropriate;

(5)

shall establish a pilot through which the Secretary may acquire, test, and deploy, as rapidly as possible, technologies described in paragraph (4); and

(6)

shall periodically update the privacy impact assessment required under section 208(b) of the E-Government Act of 2002 (44 U.S.C. 3501 note).

(d) Principles

In carrying out subsection (b), the Secretary shall ensure that—

(1)

activities carried out under this section are reasonably necessary for the purpose of protecting agency information and agency information systems from a cybersecurity risk;

(2)

information accessed by the Secretary will be retained no longer than reasonably necessary for the purpose of protecting agency information and agency information systems from a cybersecurity risk;

(3)

notice has been provided to users of an agency information system concerning access to communications of users of the agency information system for the purpose of protecting agency information and the agency information system; and

(4)

the activities are implemented pursuant to policies and procedures governing the operation of the intrusion detection and prevention capabilities.

(e) Private entities
(1) Conditions

A private entity described in subsection (c)(2) may not—

(A)

disclose any network traffic transiting or traveling to or from an agency information system to any entity other than the Department or the agency that disclosed the information under subsection (c)(1), including personal information of a specific individual or information that identifies a specific individual not directly related to a cybersecurity risk; or

(B)

use any network traffic transiting or traveling to or from an agency information system to which the private entity gains access in accordance with this section for any purpose other than to protect agency information and agency information systems against cybersecurity risks or to administer a contract or other agreement entered into pursuant to subsection (c)(2) or as part of another contract with the Secretary.

(2) Limitation on liability

No cause of action shall lie in any court against a private entity for assistance provided to the Secretary in accordance with this section and any contract or agreement entered into pursuant to subsection (c)(2).

(3) Rule of construction

Nothing in paragraph (2) shall be construed to authorize an Internet service provider to break a user agreement with a customer without the consent of the customer.

(f) Privacy Officer review

Not later than 1 year after December 18, 2015, the Privacy Officer appointed under section 142 of this title, in consultation with the Attorney General, shall review the policies and guidelines for the program carried out under this section to ensure that the policies and guidelines are consistent with applicable privacy laws, including those governing the acquisition, interception, retention, use, and disclosure of communications.

Source credit: (Pub. L. 107–296, title XXII, § 2213, formerly title II, § 230, as added Pub. L. 114–113, div. N, title II, § 223(a)(6), Dec. 18, 2015, 129 Stat. 2964; renumbered title XXII, § 2213, and amended Pub. L. 115–278, § 2(g)(2)(I), (9)(A)(vii), Nov. 16, 2018, 132 Stat. 4178, 4181; Pub. L. 117–263, div. G, title LXXI, § 7143(b)(2)(H), Dec. 23, 2022, 136 Stat. 3660.)

history & why it existsrecord from the source credit
  • 2015Enacted · Pub. L. 107-296 · 129 Stat. 2964
  • 2018Amended · Pub. L. 115-278 · 132 Stat. 4178, 4181
  • 2022Amended · Pub. L. 117-263 · 136 Stat. 3660

A history note hasn’t been published yet. The record shows enactment by Pub. L. 107-296 on 2015-12-18.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case