Federal · Title 10 — Armed Forces
10 U.S.C. § 2224: Defense Information Assurance Program
Read the full statutory text
The Secretary of Defense shall carry out a program, to be known as the “Defense Information Assurance Program”, to protect and defend Department of Defense information, information systems, and information networks that are critical to the Department and the armed forces during day-to-day operations and operations in times of crisis. The objectives of the program shall be to provide continuously for the availability, integrity, authentication, confidentiality, nonrepudiation, and rapid restitution of information and information systems that are essential elements of the Defense Information Infrastructure. A vulnerability and threat assessment of elements of the defense and supporting nondefense information infrastructures that are essential to the operations of the Department and the armed forces. Development of essential information assurances technologies and programs. Organization of the Department, the armed forces, and supporting activities to defend against information warfare. Joint activities of the Department with other departments and agencies of the Government, State and local agencies, and elements of the national information infrastructure. The conduct of exercises, war games, simulations, experiments, and other activities designed to prepare the Department to respond to information warfare threats. Development of proposed legislation that the Secretary considers necessary for implementing the program or for otherwise responding to the information warfare threat. In carrying out the program, the Secretary shall coordinate, as appropriate, with the head of any relevant Federal agency and with representatives of those national critical information infrastructure systems that are essential to the operations of the Department and the armed forces on information assurance measures necessary to the protection of these systems. Repealed. Pub. L. 108–136, div. A, title X, § 1031(a)(12) , Nov. 24, 2003 , 117 Stat. 1597 .] an integrated organization structure to plan and facilitate the conduct of simulations, war games, exercises, experiments, and other activities to prepare and inform the Department regarding information warfare threats; and organization and planning means for the conduct by the Department of the integrated or joint exercises and experiments with elements of the national information systems infrastructure and other non-Department of Defense organizations that are responsible for the oversight and management of critical information systems and infrastructures on which the Department, the armed forces, and supporting activities depend for the conduct of daily operations and operations during crisis. Not later than one year after the date of the enactment of this Act [ Dec. 18, 2025 ], the Secretary of Defense shall develop and implement requirements that ensure qualified biological data resources created by research entirely funded by the Department of Defense are collected and stored in a manner that facilitates the use of such qualified biological data resources for advanced computational methods, including artificial intelligence. The type of biological data generated. The size of the dataset involved. The amount of Federal funds awarded to the research that created such qualified biological data resource. The level of sensitivity of the biological data generated. Any other factor determined appropriate by the Secretary of Defense. Guidance on the metrics and metadata included under such requirements to indicate data quality, including usability, interoperability, and completeness. Requirements for tiered levels of cybersecurity safeguards and access controls for the storage of biological data. Exceptions to such requirements, including for biological data that may implicate national security. Requirements for the protection of the privacy of individuals. consult with the Secretaries of the military departments, the heads of the research laboratories of each of the Armed Forces, and relevant individuals and entities in the private sector and academia who have received funding for research from the Department of Defense to ensure that such requirements are not overly burdensome; and review and incorporate, to the extent the Secretary determines appropriate, existing Federal frameworks and standards for the use of qualified biological data resources for advanced computational methods.” Beginning not later than 90 days after the date of enactment of this Act [ Dec. 18, 2025 ], the Secretary of Defense shall ensure that each wireless mobile phone the Department of Defense provides to a senior official of the Department or any other employee of the Department who performs sensitive national security functions, as determined by the Secretary, and all related telecommunications services are acquired under contracts or other agreements that require the enhanced cybersecurity protections described in subsection (b). encryption of data on the wireless mobile phones and of all telecommunications to and from the wireless mobile phones through such telecommunication services; capabilities to mitigate or obfuscate persistent device identifiers, including periodic rotation of network or hardware identifiers to reduce the risk of inappropriate tracking of the activity or location of the wireless mobile phones; and the capability to continuously monitor the wireless mobile phones. a list of the contracts or other agreements entered into pursuant to subsection (a); the criteria used by the Secretary to determine which employees of the Department of Defense performs [sic] sensitive national security functions for the purposes of subsection (a), and the total number of such employees; and the total costs of wireless mobile phones and telecommunication services required by subsection (a).” The Secretary of Defense shall develop a framework for the implementation of cybersecurity and physical security standards and best practices relating to covered artificial intelligence and machine learning technologies to mitigate risks to the Department of Defense from the use of such technologies. Risk posed to and by the workforce of the Department of Defense, including insider threat risks. Artificial intelligence security awareness. Artificial intelligence-specific threats and vulnerabilities. Development of a continuum of professional development and education of artificial intelligence security expertise. Risks to the supply chains of such systems, including counterfeit parts or data poisoning risks. Risks relating to adversarial tampering with artificial intelligence systems. Risks relating to the unintended exposure or theft of artificial intelligence systems or data. Security posture management practices, including governance of security measures, continuous monitoring, and incident reporting procedures. An evaluation of commercially available platforms for continuous monitoring and assessment of such systems. The framework developed under paragraph (1) shall be risk-based, including security that is proportional to the national security or foreign policy risks posed by the covered artificial intelligence and machine learning technology being stolen or tampered with. draw on existing cybersecurity reference documents, including the NIST Special Publication 800 series; and be implemented as an extension or augmentation of existing cybersecurity frameworks developed by the Department of Defense, including the Cybersecurity Maturity Model Certification framework. The framework developed under paragraph (1) shall prioritize the most highly capable artificial intelligence systems that may be of highest interest to cyber threat actors, based on risk assessments and threat reporting. The Secretary shall ensure that the framework developed under paragraph (1) imposes requirements for security on contractors that are designed to mitigate the cyberesecurity risks posed by the cyber threat actors described in subparagraph (A), with the most stringent security requirements under such frameworks providing protection that is similar to the protection offered by national security systems (as defined in section 3552(b)(6) of title 44 , United States Code). To the extent feasible, any additional security requirements developed pursuant to subparagraph (B) shall be designed generally for all software systems of the Department of Defense, but may contain components designed specifically for highly capable artificial intelligence systems. The Secretary of Defense shall amend the Defense Federal Acquisition Regulation Supplement, or take other similar action, to require covered entities to implement the best practices described in subsection (a) under the framework developed under such subsection. Any requirements implemented pursuant to paragraph (1) shall, to the extent practicable, be narrowly tailored to the specific covered artificial intelligence and machine learning technologies developed, deployed, stored, or hosted by a covered entity, and shall be calibrated accordingly to the different tasks involved in development, deployment, storage, or hosting of components of such covered artificial intelligence and machine learning technologies. consider the costs and benefits to the Department of Defense and to the national security and technological leadership of the United States, of imposing security requirements on covered entities; and to the extent feasible, design the requirements implemented pursuant to such paragraph to allow for trade space analysis by the Department in a transparent manner between competing requirements in order to minimize the costs and maximize the benefits of such requirements. In carrying out subparagraph (A), the Secretary shall weigh the costs of slowing the development and deployment of artificial intelligence and machine learning against the benefits of mitigating national security risks and potential security risks to the Department of Defense from using commercial software for imposing additional physical or cybersecurity requirements for such systems. In carrying out the requirements of subsection (a), the Secretary of Defense shall seek to collaborate with industry and academia in the development of the framework under such subsection using a process for consultation that uses a new or existing mechanism for public-private partnerships. establishes timelines and milestones for achieving the objectives outlined in the framework; identifies resource requirements and funding mechanisms; and provides metrics for measuring progress and effectiveness. Not later than 180 days after the date of the enactment of this Act [ Dec. 18, 2025 ], the Secretary shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] an update on the status of implementation of the requirements of this section. The term ‘artificial intelligence’ has the meaning given such term in [section] 238(g) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 ( Public Law 115–232 ; 10 U.S.C. 4061 note prec.). The term ‘covered artificial intelligence and machine learning technology’ means an artificial intelligence or machine learning system acquired by the Department of Defense or an element of the Department and all associated components involved in the development and deployment lifecycle of such system, including source code, numerical parameters (including model weights) of the trained artificial intelligence or machine learning system, details of any methods and algorithms used to develop such system, data used in the development of such system, and software used for evaluating the trustworthiness of the artificial intelligence or machine learning system during development or deployment. The term ‘covered entity’ means an entity that enters into a contract or other agreement with the Department of Defense under which such entity engages in the development, deployment, storage, or hosting of one or more covered artificial intelligence and machine learning technologies.” Except as provided in subsection (b), not later than 30 days after the date of the enactment of this Act [ Dec. 18, 2025 ], the Secretary of Defense shall require the exclusion and removal of covered artificial intelligence from the systems and devices of the Department of Defense. Not later than 30 days after the date of the enactment of this Act, the Secretary of Defense shall consider issuing Department of Defense-wide guidance to exclude and remove from systems and devices of the Department artificial intelligence developed by a covered artificial intelligence company which the Secretary determines poses a risk to national security. Except as provided in subsection (b), not later than 30 days after the date of enactment of this Act, no contractor may, during the period of performance of such contractor under a contract with the Department of Defense, use covered artificial intelligence with respect to the performance of a contract with the Department. Except as provided in subsection (b), if the Secretary of Defense issues guidance described in paragraph (2) with respect to an artificial intelligence described in such paragraph, no contractor may, during the period of performance of such contractor under a contract with the Department of Defense, use such artificial intelligence with respect to the performance of a contract with the Department. for the purpose of scientifically valid research (as defined in section 102 of the Education Sciences Reform Act of 2002 ( 20 U.S.C. 9501 )); for the purpose of evaluation, training, testing, or other analysis needed for national security; for the purpose of conducting counter terrorism, counterintelligence, or other operational military activities supporting national security; or for the purpose of fulfilling mission critical functions. If the Secretary of Defense issues a waiver pursuant to paragraph (1), the Secretary shall take such steps as the Secretary considers necessary to mitigate any risks due to the issuance of the waiver. The term ‘artificial intelligence’ has the meaning given such term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 ( 15 U.S.C. 9401 ) and includes the systems and techniques described in paragraphs (1) through (5) of section 238(g) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 ( Public Law 115–232 ; 10 U.S.C. 4061 note prec.). any artificial intelligence, or successor artificial intelligence, developed by the Chinese company DeepSeek; or any artificial intelligence, or successor artificial intelligence, developed by High Flyer or an entity owned by, funded by, or supported by High Flyer or an entity with respect to which High Flyer directly or indirectly owns at least a 20 percent stake. The term ‘covered nation’ has the meaning given such term in section 4872 of title 10 , United States Code. the Consolidated Screening List maintained by the International Trade Administration of the Department of Commerce; or the civil-military fusion list maintained under section 1260H of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 ( Public Law 116–283 ; 10 U.S.C. 113 note); is domiciled in a covered nation; or is subject to unmitigated foreign ownership, control, or influence by a covered nation, as determined by the Secretary of Defense in accordance with the National Industrial Security Program or any successor to such program.” a strategy for the Department of Defense, including each of the military departments, to identify, implement, and use modern data formats as the primary method of electronic communication for command and control activities and for weapon systems, including sensors associated with such weapon systems; and an associated five-year roadmap for the Department of Defense, including each of the military departments, to implement modern data formats under the strategy described in subparagraph (A). The activities of the Chief Digital and Artificial Intelligence Officer of the Department of Defense to increase and synchronize the use of modern data formats and modern data sharing standards across the Department of Defense. Development of standard definitions for modern and antiquated data formats, including a representative catalog of the types of data formats that fall under each category. The activities of the military departments to increase the use of modern data formats and modern data sharing standards for command and control systems, weapon systems, and sensors associated with such weapon systems. An identification of barriers to the use of modern data formats and modern data sharing standards within weapon systems and sensors associated with such weapon systems across the Department of Defense. An identification of barriers to the use of modern data formats and modern data sharing standards within command and control systems across the Department of Defense. An identification of limitations on combined joint all-domain command and control capabilities resulting from the use of antiquated data formats. An identification of policy documents, instructions, or other guidance requiring an update pursuant to such strategy. The sources of funding for each military department with respect to implementation of such strategy. Upon completion of the strategy and roadmap required under this subsection, the Secretary of Defense shall submit to the Committees on Armed Services of the Senate and the House of Representatives such strategy. the JavaScript Object Notation data format; the Binary JavaScript Object Notation data format; the Protocol Buffers data format; and such other data formats that the Secretary of Defense determines would meet the requirements in this section. the Secretary of Defense shall establish a pilot program under which the Department of Defense, other than the military departments, shall use modern data formats to improve the usability and functionality of information stored or produced in antiquated data formats, including by the automated conversion of such information to modern data formats; and each Secretary of a military department shall establish a pilot program under which such military department shall use modern data formats as described in subparagraph (A). Not later than 180 days after the completion of the strategy required by subsection (a), the Secretary of Defense and the Secretaries of the military departments shall each submit to the Committees on Armed Services of the Senate and the House of Representatives a briefing on the progress of the pilot program established by such Secretary under this subsection, including specific examples of the use of modern data formats under such pilot program to improve the usability and functionality of information stored or produced in antiquated data formats. Each pilot program established under this subsection shall terminate on the date that is five years after the date of the enactment of this Act. In this section, the term ‘military department’ has the meaning given such term in section 101(a) of title 10 , United States Code.” Not later than 180 days after the date of the enactment of this Act [ Dec. 23, 2024 ], the Under Secretary of Defense for Intelligence and Security shall update the policy of the Department of Defense regarding the protection of biometric data. Standards for encrypting and protecting data on biometric collection devices. A requirement to sanitize biometric data from collection devices and hard drives prior to disposal of the devices and hard drives. A requirement that components of the Department maintain records that they have sanitized all data from biometric collection devices when the devices are turned in for disposal.” Not later than 90 days after the date of the enactment of this Act [ Dec. 22, 2023 ], the officials described in subsection (c) shall review, and assess the status of the implementation of, the recommendations set forth by the Secretary of Defense in response to the joint assessment requirement under section 1660 of the National Defense Authorization Act for Fiscal Year 2020 ( Public Law 116–92 ; 133 Stat. 1771 ). the timelines associated with each such recommendation, regardless of whether the recommendation is fully implemented or yet to be fully implemented; and a description of any impediments to the implementation of such recommendations encountered. a description of the funding necessary for such cyber red teams to achieve such capacity and capability; a description of any other resources, personnel, infrastructure, or authorities for access to information necessary for such cyber red teams to achieve such capacity and capability (including with respect to the emulation of threats from foreign countries with advanced cyber capabilities, automation, artificial intelligence or machine learning, and data collection and correlation); and updated joint service standards and metrics to ensure the training, staffing, and equipping of such cyber red teams at levels necessary to achieve such capacity and capability. Not later than one year after the date of enactment of this Act, the Secretary of Defense shall prescribe such regulations and issue such guidance as the Secretary determines necessary to implement the plan developed under subsection (a). The officials described in this subsection are the Principal Cyber Advisor to the Secretary of Defense, the Chief Information Officer of the Department of Defense, the Director of Operational Test and Evaluation, and the Commander of the United States Cyber Command. The results of test and evaluation events, including any resource or capability shortfalls limiting the capacity or capability of cyber red teams of the Department of Defense to meet operational requirements. The extent to which operations of such cyber red teams have expanded across the competition continuum, including during cooperation and competition phases, to match adversary positioning and cyber activities. A summary of identified categories of common gaps and shortfalls across cyber red teams of the military departments and Defense Agencies (as such terms are defined in section 101 of title 10 , United States Code). Any identified lessons learned that would affect training or operational employment decisions relating to the cyber red teams of the Department of Defense.” The Secretary of Defense may transfer to eligible private sector entities data and technology developed under the MOSAICS program to enhance cyber threat detection and protection of critical industrial control system assets used for electricity distribution. enter into cooperative research and development agreements under section 4026 of title 10 , United States Code; and use such other mechanisms for the transfer of technology and data as are authorized by law. An identification of the data or technology to be transferred. An identification of the eligible private sector entity, including an identification of the specific individual employed by or otherwise associated with such entity responsible for the security and integrity of the data or technology to be received. A detailed description of any special security handling instructions required pursuant to an agreement entered into between the Secretary and the eligible private sector entity for such transfer. Timelines associated with such transfer. has functions relevant to the civil electricity sector; and is determined by the Secretary of Defense to be eligible to receive data and technology transferred under subsection (a). The term ‘MOSAICS program’ means the program of the Department of Defense known as the ‘More Situational Awareness for Industrial Control Systems Joint Capabilities Technology Demonstration program’, or successor program.” The Secretary of Defense shall carry out a modernization program for network boundary and cross-domain defense against cyber attacks. In carrying out such modernization program, the Secretary shall expand upon the fiscal year 2023 pilot program on modernized network boundary defense capabilities and the initial deployment of such capabilities to the primary Internet access points of the Department of Defense managed by the Director of the Defense Information Systems Agency. The Secretary of Defense shall implement the modernization program under subsection (a) in phases, with the objective of completing such program by October 1, 2028 . the pilot program specified in subsection (a) and the deployment of modernized network boundary defense capabilities to the Internet access points managed by the Director of the Defense Information Systems Agency; and the extension of modernized network boundary defense capabilities to all additional Internet access points of the information network of the Department of Defense. By September 30, 2027 , the conduct of a survey, completion of a pilot program, and deployment of modernized network boundary defense capabilities to the access points and cross-domain capabilities of the Secret Internet Protocol Router Network. By September 30, 2028 , the conduct of a survey, completion of a pilot program, and deployment of modernized network boundary defense capabilities to any remaining classified network or enclave of the information network of the Department. a summary of findings from the pilot program specified in subsection (a); and an identification of the resources necessary for such implementation, including for implementing the phase of the modernization program specified in subsection (b)(2)(C).” Except as provided in subsection (b), not later than 120 days after the date of the enactment of this Act [ Dec. 22, 2023 ], the Secretary of Defense shall establish a program of record, governed by standard Department of Defense requirements and practices, and transition all covered activities to such program of record. Correcting weaknesses in authentication and credentialing security, including with respect to the program of the Department of Defense known as the ‘Public Key Infrastructure’ program (or any successor program), identified by the Director of Operational Test and Evaluation in a report submitted to Congress in April, 2023, titled ‘FY14–21 Observations of the Compromise of Cyber Credentials’. Implementing improved authentication technologies, such as biometric and behavioral authentication techniques and other non-password-based solutions. Not later than 150 days after the date of the enactment of this Act, the Secretary of Defense shall provide to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a briefing on the covered activities to be included under the program of record under subsection (a). The Secretary of Defense may waive the requirement under subsection (a) if the Secretary of Defense determines that the objectives listed in paragraph (2) of such subsection would be better achieved, and the level of rigor of the operational testing and oversight requirements applicable to such objectives would be improved, through a management approach other than the establishment of a program of record and transition of covered activities to such program of record. an explanation of why the establishment of a program of record is not the preferred approach to achieve the objectives listed in subsection (a)(2); details relating to the management approach proposed to be implemented in lieu of the establishment of a program of record; an implementation plan for such proposed alternative approach; and such other information as the Secretary of Defense determines appropriate. Not later than 120 days after the date of the enactment of this Act, the Chief Information Officer of the Department of Defense, in coordination with the Secretaries of the military departments, shall complete the designation of Tier 1 level data attributes to be used as a baseline set of standardized attributes for identity, credential, and access management, Defense-wide. Upon completing the requirement under subsection (c), the Chief Information Officer of the Department of Defense and the Secretaries of the military departments shall provide to the Committees on Armed Services of the House of Representatives and the Senate a briefing on the activities carried out under this section. The term ‘covered activity’ means any activity of the Office of the Secretary of Defense or a Defense Agency relating to the identity, credential, and access management initiative of the Department of Defense. The term ‘Defense Agency’ has the meaning given that term in section 101 of title 10 , United States Code.” Not later than 60 days after the date of the enactment of this Act [ Dec. 22, 2023 ], the Secretary of Defense shall establish a pilot program to be known as the ‘Assuring Critical Infrastructure Support for Military Contingencies Pilot Program’. Not later than 90 days after the date of the enactment of this Act, the Secretary of Defense, acting through the Assistant Secretary of Defense for Homeland Defense and Hemispheric Affairs, shall select not fewer than four geographically diverse military installations at which to carry out the pilot program under subsection (a). In selecting military installations under paragraph (1), the Secretary of Defense shall give priority to any military installation that the Secretary determines is a key component of not fewer than two contingency plans or operational plans, with further priority given to such plans in the area of responsibility of the United States Indo-Pacific Command or the United States European Command. connected to national-level infrastructure; located near a commercial port; or located near a national financial hub. to assess how to prioritize restoration of power, water, and telecommunications for a military installation in the event of a significant cyberattack on regional critical infrastructure that has similar impacts on State and local infrastructure; and to determine the recovery process needed to ensure the military installation has the capability to function and support an overseas contingency operation or a homeland defense mission, as appropriate; map dependencies on power, water, and telecommunications at the military installation and the connections to distribution and generation outside the military installation; recommend priorities for the order of recovery for the military installation in the event of a significant cyberattack, considering both the requirements needed for operations of the military installation and the potential participation of personnel at the military installation in an overseas contingency operation or a homeland defense mission; and develop a lessons-learned database from the exercises conducted under paragraph (1) across all military installations participating in the pilot program, to be shared with the Committees on Armed Services of the House of Representatives and the Senate. private entities that operate power, water, and telecommunications for a military installation participating in the pilot program under subsection (a); relevant military and civilian personnel; and any other entity that the Assistant Secretary of Defense for Homeland Defense and Hemispheric Affairs determines is relevant to the execution of activities under subsection (c). Not later than one year after the date of the enactment of this Act, the Secretary of Defense shall submit to the Assistant to the President for Homeland Security, the National Cyber Director, the head of any other relevant Sector Risk Management Agency, the Committees on Armed Services of the House of Representatives and the Senate, and, if the Secretary of Defense determines it appropriate, relevant private sector owners and operators of critical infrastructure a report on the activities carried out under pilot program under subsection (a), including a description of any operational challenges identified. The term ‘critical infrastructure’ has the meaning given that term in the Critical Infrastructures Protection Act of 2001 ( 42 U.S.C. 5195c ). The term ‘Sector Risk Management Agency’ has the meaning given that term in section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 ).” The Committee on National Security Systems Directive 504, issued on February 4, 2014 , relating to the protection of national security systems from insider threats (including any annex to such directive). Department of Defense Directive 5205.16, issued on September 30, 2014 , relating to the insider threat program of the Department of Defense. The Secretary of Defense shall require each head of a component of the Department of Defense to implement, with respect to systems, devices, and personnel of the component, automated controls to detect and prohibit privileged user accounts from performing general user activities not requiring privileged access. conducts insider threat testing using threat-realistic tactics, techniques, and procedures; and submits to the Under Secretary of Defense for Intelligence and Security, the Chief Information Officer of the Department of Defense, and the Director of Operational Test and Evaluation of the Department of Defense a report on the findings of the head with respect to the testing conducted pursuant to paragraph (1). Not later than 180 days after the date of the enactment of this Act [ Dec. 22, 2023 ], the Secretary of Defense shall submit to the appropriate congressional committees a report on the implementation of this section. the Committee on Armed Services and the Permanent Select Committee on Intelligence of the House of Representatives; and the Committee on Armed Services and the Select Committee on Intelligence of the Senate.” The Secretary of Defense shall evaluate and implement to the maximum extent practicable the recommendations of the Inspector General of the Department of Defense with respect to managing mobile applications contained in the report set forth by the Inspector General dated February 9, 2023 , and titled ‘Management Advisory: The DoD’s Use of Mobile Applications’ (Report No. DODIG–2023–041). The Secretary shall implement each of the recommendations specified in subsection (a) by not later than one year after the date of the enactment of this Act [ Dec. 22, 2023 ] unless the Secretary submits to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a written notification of any specific recommendation that the Secretary declines to implement or plans to implement after the date that is one year after the date of the enactment of this Act. the installation and use of covered applications on Federal Government devices; and the use of covered applications on the Department of Defense Information Network on personal devices. In this subsection, the term ‘covered applications’ means the social networking service TikTok, or any successor application or service developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.” establish requirements for and assign sufficient priority to ensuring electronic protection of military sensor, navigation, and communications systems and subsystems against jamming, spoofing, and unintended interference from military systems of the United States and foreign adversaries; and provide management oversight and supervision of the military departments to ensure military systems that emit and receive radio frequencies are protected against threats and interference from United States and foreign adversary military systems operating in the same or adjacent radio frequencies. Not later than 270 days after the date of the enactment of this Act [ Dec. 22, 2023 ], develop and approve requirements, through the Joint Requirements Oversight Council as appropriate, for every radar, signals intelligence, navigation, and communications system and subsystem subject to the Global Force Management process to ensure such systems and subsystems are able to withstand threat-realistic levels of jamming, spoofing, and unintended interference, including self-generated interference. Not less frequently than once every 4 years, test each system and subsystem described in paragraph (1) at a test range that permits threat-realistic electronic warfare attacks against the system or subsystem by a red team or simulated opposition force, with the first set of highest priority systems to be initially tested by not later than the end of fiscal year 2025. not later than 3 years after the initial failed test, retrofit the system or subsystem with electronic protection measures that can withstand threat-realistic jamming, spoofing, and unintended interference; and not later than 4 years after the initial failed test, retest such systems and subsystems. Survey, identify, and test available technology that can be practically and affordably retrofitted on the systems and subsystems described in paragraph (1) and which provides robust protection against threat-realistic jamming, spoofing, and unintended interference. Design and build electronic protection into ongoing and future development programs to withstand expected jamming and spoofing threats and unintended interference. The Secretary of Defense may establish a process for issuing waivers, on a case-by-case basis, for the testing requirement under paragraph (2) of subsection (b) and for the retrofit requirement under paragraph (3) of such subsection. aggregates and summarizes information received from the military departments and combat support agencies for purposes of the preparation of the report; and the activities carried out to implement the requirements of this section; the systems and subsystems subject to testing in the previous year and the results of such tests, including a description of the requirements for electronic protection established for the tested systems and subsystems; and each waiver issued in the previous year with respect to such requirements, together with a detailed rationale for the waiver and a plan for addressing any issues that formed the basis of the waiver request.” Not later than February 1, 2024 , the Chief Information Officer of the Department of Defense and the Chief Information Officers of the military departments shall develop and submit plans described in subsection (b) to the Director of Operational Test and Evaluation who may approve the implementation of the plans pursuant to subsection (c). ensure covered cybersecurity capabilities are appropriately tested, evaluated, and proven operationally effective, suitable, and survivable prior to operation on a Department of Defense network; and specify how test results will be expeditiously provided to the Director of Operational Test and Evaluation. Threat-realistic operational testing, including representative environments, variation of operational conditions, and inclusion of a realistic opposing force. The use of Department of Defense cyber red teams, as well as any enabling contract language required to permit threat-representative red team assessments. Collaboration with the personnel using the commercial cybersecurity capability regarding the results of the testing to improve operators’ ability to recognize and defend against cyberattacks. The extent to which additional resources may be needed to remediate any shortfalls in capability to make the commercial cybersecurity capability effective, suitable, and cyber survivable in an operational environment of the Department. Identification of training requirements, and changes to training, sustainment practices, or concepts of operation or employment that may be needed to ensure the effectiveness, suitability, and cyber survivability of the commercial cybersecurity capability. Not later than February 1, 2024 , the Secretary of Defense shall issue such policies and guidance and prescribe such regulations as the Secretary determines necessary to carry out this section. The status of the plans developed under subsection (a). The number and type of test and evaluation events completed in the past year for such plans, disaggregated by component of the Department, and including resources devoted to each event. The results from such test and evaluation events, including any resource shortfalls affecting the number of commercial cybersecurity capabilities that could be assessed. A summary of identified categories of common gaps and shortfalls found during testing. The extent to which entities responsible for developing and testing commercial cybersecurity capabilities have responded to recommendations made by the Director in an effort to gain favorable determinations. Any identified lessons learned that would impact training, sustainment, or concepts of operation or employment decisions relating to the assessed commercial cybersecurity capabilities. Commercial products (as defined in section 103 of title 41 , United States Code) acquired and deployed by the Department of Defense to satisfy the cybersecurity requirements of one or more Department components. Commercially available off-the-shelf items (as defined in section 104 of title 41 , United States Code) acquired and deployed by the Department of Defense to satisfy the cybersecurity requirements of one or more Department components. Noncommercial items acquired through the Adaptive Acquisition Framework and deployed by the Department of Defense to satisfy the cybersecurity requirements of one or more Department components.” Not later than 180 days after the date of enactment of this Act [ Dec. 23, 2022 ], the Secretary of Defense, in consultation with commercial industry, shall implement a policy and plan for test and evaluation of the cybersecurity of the clouds of commercial cloud service providers that provide, or are intended to provide, storage or computing of classified data of the Department of Defense. the storage, compute, and enabling elements, including the control plane and virtualization hypervisor for mission elements of the Department supported by the cloud provider; and the supporting systems used in the fulfillment, facilitation, or operations relating to the mission of the Department under the contract, including the interfaces with these systems. An explanation as to how the Secretary intends to proceed on amending existing contracts with cloud service providers to permit the same level of assessments required for future contracts under paragraph (1). Identification and description of any proposed tiered test and evaluation requirements aligned with different impact and classification levels. The Secretary may include in the policy and plan under subsection (a) an authority to waive any requirement under subsection (b) if the waiver is jointly approved by the Chief Information Officer of the Department of Defense and the Director of Operational Test and Evaluation. Not later than 180 days after the date of enactment of this Act, the Secretary shall submit to the Committees on Armed Services of the Senate and the House of Representatives the policy and plan under subsection (a). are designed to accurately emulate cyber threats from advanced nation state adversaries, such as Russia and China; and include cooperative penetration testing and no-notice threat-emulation activities where personnel of the Department of Defense attempt to penetrate and gain control of the cloud-provider facilities, networks, systems, and defenses associated with, or which enable, the supported missions of the Department.” The Secretary of Defense shall ensure that the activities required by and conducted pursuant to section 1647 of the National Defense Authorization Act for Fiscal Year 2016 ( Public Law 114–92 ; 129 Stat. 1118 ) [ 10 U.S.C. 2224 note] and the amendments made by section 1712 of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 ( Public Law 116–283 ; 134 Stat. 4087 [amending section 1647 of Pub. L. 114–92 , set out as a note under this section, and section 1640 of Pub. L. 115–91 , formerly set out as a note under this section]) include regular assessments of the vulnerabilities to and mission risks presented by radio-frequency enabled cyber attacks with respect to the operational technology embedded in weapons systems, aircraft, ships, ground vehicles, space systems, sensors, and datalink networks of the Department of Defense. identification of such vulnerabilities and risks; ranking of vulnerability, severity, and priority; development and selection of options, with associated costs and schedule, to correct such vulnerabilities, including installation of intrusion detection capabilities; an evaluation of the cybersecurity sufficiency for Military Standard 1553; and development of integrated risk-based plans to implement the corrective actions selected. consider the missions supported by the assessed weapons systems, aircraft, ships, ground vehicles, space systems, sensors, or datalink networks, as the case may be, to ensure that the corrective actions focus on the vulnerabilities that create the greatest risks to the missions; be shared and coordinated with the principal staff assistant with primary responsibility for the strategic cybersecurity program; and address requirements for deployed and nondeployed members of the Armed Forces to analyze data collected on the weapons systems and respond to attacks. The assessments under subsection (a) shall be informed by intelligence, if available, and technical judgment regarding potential threats to embedded operational technology during operations of the Armed Forces. The assessments under subsection (a) shall be fully coordinated and integrated with activities described in such subsection. The Secretary shall ensure that the organizations conducting the assessments under subsection (a) in the military departments, the United States Special Operations Command, and the Defense Agencies coordinate with each other and share best practices, vulnerability analyses, and technical solutions with the principal staff assistant with primary responsibility for the Strategic Cybersecurity Program.” private sector entities operating inside the United States to defend against foreign malicious cyber actors could assist, or be coordinated with, the actions of United States Cyber Command operating outside the United States against such foreign malicious cyber actors; and United States Cyber Command operating outside the United States against foreign malicious cyber actors could assist, or be coordinated with, the actions of private sector entities operating inside the United States against such foreign malicious cyber actors. During the period beginning on March 1, 2022 , and ending on March 1, 2026 , the Commander of United States Cyber Command shall, not less frequently than once each year, provide to the Committee on Armed Services of the Senate and the Committee on Armed Services of the House of Representatives a briefing on the status of any activities conducted pursuant to subsection (a). Such recommendations for legislative or administrative action as the Commander of United States Cyber Command considers appropriate to improve and facilitate the exploration and development of methods and plans under subsection (a). Such recommendations as the Commander may have for increasing private sector participation in such exploration and development. A description of the challenges encountered in carrying out subsection (a), including any concerns expressed to the Commander by private sector partners regarding participation in such exploration and development. Information relating to how such exploration and development with the private sector could assist military planning by United States Cyber Command. Such other matters as the Commander considers appropriate. In developing the process described in subsection (a), the Commander of United States Cyber Command shall consult with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security and the heads of any other Federal agencies the Commander considers appropriate. The Joint Cyber Defense Collaborative of the Cybersecurity and Infrastructure Security Agency. The Cybersecurity Collaboration Center and Enduring Security Framework of the National Security Agency. The office for joint cyber planning of the Department of Homeland Security. The Commander of United States Cyber Command shall ensure that any trade secret or proprietary information of a private sector entity engaged with the Department of Defense through the process established under subsection (a) that is made known to the Department pursuant to such process remains private and protected unless otherwise explicitly authorized by such entity. Nothing in this section may be construed to authorize United States Cyber Command to conduct operations inside the United States or for private sector entities to conduct offensive cyber activities outside the United States, except to the extent such operations or activities are permitted by a provision of law in effect on the day before the date of the enactment of this Act [ Dec. 27, 2021 ].” Surveying components of the Department for the cyber data products and services needs of such components. Conducting market research of cyber data products and services. Developing or facilitating development of requirements, both independently and through consultation with components, for the acquisition of cyber data products and services. Developing and instituting model contract language for the acquisition of cyber data products and services, including contract language that facilitates components’ requirements for ingesting, sharing, using and reusing, structuring, and analyzing data derived from such products and services. Conducting procurement of cyber data products and services on behalf of the Department of Defense, including negotiating contracts with a fixed number of licenses based on aggregate component demand and negotiation of extensible contracts. Evaluating emerging cyber technologies, such as artificial intelligence-enabled security tools, for efficacy and applicability to the requirements of the Department of Defense. facilitating the development of cyber data products and services requirements for the Cyberspace Operations Forces, conducting market research regarding the future cyber data products and services needs of the Cyberspace Operations Forces, and conducting acquisitions pursuant to such requirements and market research; coordinating cyber data products and services acquisition and management activities with Joint Cyber Warfighting Architecture acquisition and management activities, including activities germane to data storage, data management, and development of analytics; implementing relevant Department of Defense and United States Cyber Command policy germane to acquisition of cyber data products and services; leading or informing the integration of relevant datasets and services, including Government-produced threat data, commercial cyber threat information, collateral telemetry data, topology-relevant data, sensor data, and partner-provided data; and facilitating the development of tradecraft and operational workflows based on relevant cyber data products and services. In implementing this section, each component of the Department of Defense shall coordinate its cyber data products and services requirements and potential procurement plans relating to such products and services with the program management office established pursuant to subsection (a) so as to enable such office to determine if satisfying such requirements or procurement of such products and services on an enterprise-wide basis would serve the best interests of the Department. such component is able to procure such product or service at a lower per-unit price than that available through such office; such office has approved such independent purchase; or the compelling need for such product or service; and either the urgency for such product or service or the need to ensure competition in the market for such product or service supports such independent procurement by such component. United States Cyber Command and the National Security Agency may conduct joint procurements of products and services, including cyber data products and services, except that the requirements of subsections (b) and (c) shall not apply to the National Security Agency. In this section, the term ‘cyber data products and services’ means commercially-available datasets and analytic services germane to offensive cyber, defensive cyber, and DODIN operations, including products and services that provide technical data, indicators, and analytic services relating to the targets, infrastructure, tools, and tactics, techniques, and procedures of cyber threats.” Not later than 120 days after the date of the enactment of this Act [ Dec. 27, 2021 ], the Secretary of Defense shall ensure each component of the Department of Defense uses a Protective Domain Name System (PDNS) instantiation offered by the Department. The Secretary of Defense may exempt a component of the Department from using a PDNS instantiation for any reason except with respect to cost or technical application. each component of the Department of Defense that uses a PDNS instantiation offered by the Department; each component exempt from using a PDNS instantiation pursuant to subsection (b); and efforts to ensure that each PDNS instantiation offered by the Department connects and shares relevant and timely data.” access, acquire, and use mission-relevant data to support offensive cyber, defensive cyber, and DODIN operations from the intelligence community, other elements of the Department of Defense, and the private sector; intelligence data; internet traffic, topology, and activity data; cyber threat information; Department of Defense Information Network sensor, tool, routing infrastructure, and endpoint data; and other data management and analytic platforms pertinent to United States Cyber Command missions that align with the principles of Joint All Domain Command and Control; pilot efforts to develop operational workflows and tactics, techniques, and procedures for the operational use of mission-relevant data by the Cyberspace Operations Forces; and evaluate data management platforms used to carry out paragraphs (1), (2), and (3) to ensure such platforms operate consistently with the Deputy Secretary of Defense’s Data Decrees signed on May 5, 2021 . United States Cyber Command. Program offices responsible for the components of the Joint Cyber Warfighting Architecture. The military services. Entities in the Office of the Secretary of Defense. Any other program office, headquarters element, or operational component newly instantiated or determined relevant by the Secretary. Not later than 300 days after the date of the enactment of this Act, the Secretary of Defense shall provide to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a briefing on the roles and responsibilities established under paragraph (1).” the zero trust strategy of the Department of Defense developed under section 1528 of the National Defense Authorization Act for Fiscal Year 2022 ( 10 U.S.C. 2224 note) [set out below] applies to Internet of Things hardware, including human-wearable devices, sensors, and other smart technology used by the United States in military operations; and the role identity, credential, and access management technologies serve in enforcing such zero trust strategy. In this section, the term ‘Internet of Things’ has the meaning given such term by the National Institution of Standards and Technology in NIST Special Publication 800-172 and any amendatory or superseding document relating thereto.” Not later than 270 days after the date of the enactment of this Act [ Dec. 27, 2021 ], the Chief Information Officer of the Department of Defense and the Commander of United States Cyber Command shall jointly develop a zero trust strategy, principles, and a model architecture to be implemented across the Department of Defense Information Network, including classified networks, operational technology, and weapon systems. Identity, credential, and access management. Macro and micro network segmentation, whether in virtual, logical, or physical environments. Traffic inspection. Application security and containment. Transmission, ingest, storage, and real-time analysis of cybersecurity metadata endpoints, networks, and storage devices. Data management, data rights management, and access controls. End-to-end encryption. User access and behavioral monitoring, logging, and analysis. Data loss detection and prevention methodologies. Least privilege, including system or network administrator privileges. Endpoint cybersecurity, including secure host, endpoint detection and response, and comply-to-connect requirements. Automation and orchestration. Configuration management of virtual machines, devices, servers, routers, and similar to be maintained on a single virtual device approved list (VDL). Policies specific to operational technology, critical data, infrastructures, weapon systems, and classified networks. Specification of enterprise-wide acquisitions of capabilities conducted or to be conducted pursuant to the policies referred to in paragraph (2). Specification of standard zero trust principles supporting reference architectures and metrics-based assessment plan. at combatant commands, military services, and defense agencies; and Joint Forces Headquarters-Department of Defense Information Network. the Principal Cyber Advisor to the Secretary of Defense; the Director of the National Security Agency Cybersecurity Directorate; the Director of the Defense Advanced Research Projects Agency; the Chief Information Officer of each military service; the Commanders of the cyber components of the military services; the Principal Cyber Advisor of each military service; the Chairman of the Joints Chiefs of Staff; and any other component of the Department of Defense as determined by the Chief Information Officer and the Commander; assess the utility of the Joint Regional Security Stacks, automated continuous endpoint monitoring program, assured compliance assessment solution, and each of the defenses at the Internet Access Points for their relevance and applicability to the zero trust architecture and opportunities for integration or divestment; executive level; cybersecurity professional or implementer level; and general knowledge levels for Department of Defense users; facilitate cyber protection team and cybersecurity service provider threat hunting and discovery of novel adversary activity; assess and implement means to effect Joint Force Headquarters-Department of Defense Information Network’s automated command and control of the entire Department of Defense Information Network; assess the potential of and, as appropriate, encourage, use of third-party cybersecurity-as-a-service models; engage with and conduct outreach to industry, academia, international partners, and other departments and agencies of the Federal Government on issues relating to deployment of zero trust architectures; assess the current Comply-to-Connect Plan; and utilization of networks designated for testing and accreditation under section 1658 of the National Defense Authorization Act for Fiscal Year 2020 ( Public Law 116–92 ; 10 U.S.C. 2224 note) [set out below]; use of automated red team products for assessment of pilot architectures; and accreditation of piloted cybersecurity products for enterprise use in accordance with the findings on enterprise accreditation standards conducted pursuant to section 1654 of such Act ( Public Law 116–92 ) [ 133 Stat. 1764 ]. Not later than one year after the finalization of the zero trust strategy, principles, and model architecture required under subsection (a), the head of each military department and the head of each component of the Department of Defense shall transmit to the Chief Information Officer of the Department and the Commander of Joint Forces Headquarters-Department of Defense Information Network a draft plan to implement such zero trust strategy, principles, and model architecture across the networks of their respective components and military departments. Specific acquisitions, implementations, instrumentations, and operational workflows to be implemented across unclassified and classified networks, operational technology, and weapon systems. A detailed schedule with target milestones and required expenditures. Interim and final metrics, including a phase migration plan. Identification of additional funding, authorities, and policies, as may be required. Requested waivers, exceptions to Department of Defense policy, and expected delays. adequacy and responsiveness to the zero trust strategy, principles, and model architecture required under subsection (a); and appropriate use of enterprise-wide acquisitions; ensure, at a high level, the interoperability and compatibility of individual components’ Solutions Architectures, including the leveraging of enterprise capabilities where appropriate through standards derivation, policy, and reviews; use the annual investment guidance of the Chief to ensure appropriate implementation of such plans, including appropriate use of enterprise-wide acquisitions; track use of waivers and exceptions to policy; use the Cybersecurity Scorecard to track and drive implementation of Department components; and leverage the authorities of the Commander of Joint Forces Headquarters-Department of Defense Information Network and the Director of the Defense Information Systems Agency to begin implementation of such zero trust strategy, principles, and model architecture. Not later than March 31, 2024 , and annually thereafter, each Principal Cyber Advisor of a military service shall include in the annual budget certification of such military service, as required by section 392a(c)(4) of title 10 , United States Code, an assessment of the adequacy of funding requested for each proposed budget for the purposes of carrying out the implementation plan for such military service under subsection (d)(1). Not later than 90 days after finalizing the zero trust strategy, principles, and model architecture required under subsection (a), the Chief Information Officer of the Department of Defense and the Commander of Joint Forces Headquarters-Department of Defense Information Network shall provide to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a briefing on such zero trust strategy, principles, and model architecture. Not later than 90 days after the receipt by the Chief Information Officer of the Department of Defense of an implementation plan transmitted pursuant to subsection (d)(1), the secretary of a military department, in the case of an implementation plan pertaining to a military department or a military service, or the Chief Information Officer of the Department, in the case of an implementation plan pertaining to a remaining component of the Department, as the case may be, shall provide to the congressional defense committees a briefing on such implementation plan. Effective February 1, 2022 , at each of the annual cybersecurity budget review briefings of the Chief Information Officer of the Department of Defense and the military services for congressional staff, until January 1, 2030 , the Chief Information Officer and the head of each of the military services shall provide updates on the implementation in their respective networks of the zero trust strategy, principles, and model architecture.” mitigating cyber hygiene challenges; supporting ongoing efforts of the Department to assess weapon systems resiliency; quantifying enterprise security effectiveness of enterprise security controls, to inform future acquisition decisions of the Department; assisting portfolio managers with balancing capability costs and capability coverage of the threat landscape; and supporting the Department’s Cybersecurity Analysis and Review threat framework. integration into automated security validation tools of advanced commercially available threat intelligence; metrics and scoring of security controls; cyber analysis, cyber campaign tracking, and cybersecurity information sharing; integration into cybersecurity enclaves and existing cybersecurity controls of security instrumentation and testing capability; endpoint sandboxing; and use of actual adversary attack methodologies. In carrying out the demonstration program required under subsection (a), the Chief Information Officer, acting through the Director of the Defense Information Systems Agency, shall coordinate demonstration program activities with complementary efforts on-going within the military services, defense agencies, and field agencies. In carrying out the demonstration program required under subsection (a), the Chief Information Officer, acting through the Director of the Defense Information Systems Agency and in coordination with the Director, Operational Test and Evaluation, shall perform operational testing to evaluate the operational effectiveness, suitability, and cybersecurity of the capabilities developed under the demonstration program. Not later than April 1, 2022 , the Chief Information Officer shall brief the Committee on Armed Services of the Senate and the Committee on Armed Services of the House of Representatives on the plans and status of the Chief Information Officer with respect to the demonstration program required under subsection (a). Not later than October 31, 2024 , the Chief Information Officer shall brief the Committee on Armed Services of the Senate and the Committee on Armed Services of the House of Representatives on the results and findings of the Chief Information Officer with respect to the demonstration program required under subsection (a).” any steps being taken by the host country to mitigate any potential risks to the weapon systems, military units, or personnel, and the Department of Defense’s assessment of those efforts; any steps being taken by the United States Government, separately or in collaboration with the host country, to mitigate any potential risks to the weapon systems, permanently deployed forces, or personnel; any defense mutual agreements between the host country and the United States intended to allay the costs of risk mitigation posed by the at-risk infrastructure; and any other matters the Secretary determines to be relevant. apply with respect to the permanent long-term stationing of equipment and permanently assigned forces; and do not apply with respect to the short-term deployment or rotational presence of equipment or forces to a military installation outside the United States in connection with any exercise, dynamic force employment, contingency operation, or combat operation. the risk to personnel, equipment, and operations of the Department of Defense in host countries posed by the current or intended use by such countries of 5G or 6G telecommunications architecture provided by at-risk vendors, including Huawei and ZTE; and measures required to mitigate the risk described in paragraph (1). The report required by paragraph (1) shall be submitted in a classified form with an unclassified summary. In this section, the term ‘major weapon system’ has the meaning given that term in section 101(a) of title 10 , United States Code.” In this section, the term ‘critical infrastructure’ has the meaning given such term in section 1016(e) of the Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism (USA PATRIOT ACT) Act of 2001 ( 42 U.S.C. 5195c(e) ). Not later than 30 days after the date of the enactment of the National Defense Authorization Act for Fiscal Year 2024 [ Dec. 22, 2023 ], the Secretary of Defense shall designate a principal staff assistant from within the Office of the Secretary of Defense who shall serve as the coordinating authority for cybersecurity issues relating to the defense industrial base. The Sector Risk Management Agency functions under Presidential Policy Directive-21 the Department of Defense has assigned to the Under Secretary of Defense for Policy for implementation. The Under Secretary of Defense for Acquisition and Sustainment’s policies and programs germane to contracting and contractual enforcement as such relate to cybersecurity assessment and assistance, and industrial base health and security. The Under Secretary of Defense for Intelligence and Security’s policies and programs germane to physical security, information security, industrial security, acquisition security and cybersecurity, all source intelligence, classified threat intelligence sharing related to defense industrial base cybersecurity activities, counterintelligence, and foreign ownership control or influence, including the Defense Intelligence Agency and National Security Agency support provided to the Department of Defense – Defense Industrial Base Collaborative Information Sharing Environment and cyber intrusion damage assessment analysis as part of defense industrial base cybersecurity activities. The Department of Defense Chief Information Officer’s policies and programs for cybersecurity standards and integrating cybersecurity threat intelligence-sharing activities and enhancing Department of Defense and defense industrial base cyber situational awareness. The Under Secretary of Defense for Research and Engineering’s policies and programs germane to protection planning requirements of emerging technologies as such relate to cybersecurity assessment and assistance, and industrial base health and security. Other Department of Defense components’ policies and programs germane to the cybersecurity of the defense industrial base, including the policies and programs of the military services and the combatant commands. coordinate or facilitate coordination with relevant Federal departments and agencies, defense industrial base entities, independent regulatory agencies, and with State, local, territorial, and Tribal entities, as appropriate; facilitate or coordinate the provision of incident management support to defense industrial base entities, as appropriate; facilitate or coordinate the provision of technical assistance to and consultations with defense industrial base entities to identify cyber or cyber-physical vulnerabilities and minimize the damage of potential incidents, as appropriate; and support or facilitate the supporting of the statutorily required reporting requirements of such relevant Federal departments and agencies by providing or facilitating the provision to such departments and agencies on an annual basis relevant critical infrastructure information, as appropriate. A plan for implementation of this section, including an assessment of the roles and responsibilities of entities across the Department of Defense and mechanisms and processes for coordination of policy and programs germane to defense industrial base cybersecurity. An analysis of the feasibility and advisability of separating cybersecurity functions of a Sector Risk Management Agency pursuant to section 9002 of the National Defense Authorization Act for Fiscal Year 2021 ( 6 U.S.C. 652a ) from non-cybersecurity functions of a Sector Risk Management Agency.” Recommendations regarding how to improve and better utilize such programs, including regarding individuals who have completed such programs. An implementation plan to carry out such recommendations. Not later than 90 days after the submission of the report required under paragraph (1), the Secretary of Defense shall carry out such elements of the implementation plan required under paragraph (1)(B) as the Secretary considers appropriate and notify the congressional defense committees of the determinations of the Secretary relating thereto.” Effective beginning on the date of the enactment of this Act [ Jan. 1, 2021 ], the Secretary of Defense and the secretaries of the military services shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a monthly report in writing that documents each instance or indication of a cross-domain incident within the Department of Defense. The Secretary of Defense shall submit to the congressional defense committees procedures for complying with the requirements of paragraph (1) consistent with the national security of the United States and the protection of operational integrity. The Secretary shall promptly notify such committees in writing of any changes to such procedures at least 14 days prior to the adoption of any such changes. In this subsection, the term ‘cross domain incident’ means any unauthorized connection of any duration between software, hardware, or both that is either used on, or designed for use on a network or system built for classified data, and systems not accredited or authorized at the same or higher classification level, including systems on the public internet, regardless of whether the unauthorized connection is later determined to have resulted in the exfiltration, exposure, or spillage of data across the cross domain connection. Risk categorization. Duration. Estimated time remaining. The requirement of the Secretary of Defense to submit a monthly report under subsection (a) shall terminate on December 31, 2025 .” The Secretary of Defense, acting through the Chief Information Officer of the Department of Defense and the Commander of United States Cyber Command, shall conduct a pilot program to assess the feasibility and advisability of developing and using speed-based metrics to measure the performance and effectiveness of security operations centers and cyber security service providers in the Department of Defense. Not later than July 1, 2021 , the Chief Information Officer and the Commander shall jointly develop metrics described in subsection (a) to carry out the pilot program under such subsection. The Chief Information Officer and the Commander shall ensure that the metrics developed under subparagraph (A) are commensurate with the representative timelines of nation-state and non-nation-state actors when gaining access to, and compromising, Department networks. Not later than December 1, 2021 , the Secretary shall, in carrying out the pilot program required by subsection (a), begin using the metrics developed under paragraph (1) of this subsection to assess select security operations centers and cyber security service providers, which the Secretary shall select specifically for purposes of the pilot program, for a period of not less than four months. In carrying out the pilot program under subsection (a), the Secretary shall evaluate the effectiveness of operators, capabilities available to operators, and operators’ tactics, techniques, and procedures. over the course of their mission performance; or in the testing and accreditation of cybersecurity products and services on test networks designated pursuant to section 1658 of the National Defense Authorization Act for Fiscal Year 2020 ( Public Law 116–92 ) [set out as a note below]; and assess select elements’ use of security orchestration and response technologies, modern endpoint security technologies, Big Data Platform instantiations, and technologies relevant to zero trust architectures. Not later than March 1, 2022 , the Secretary shall brief the Committee on Armed Services of the Senate and the Committee on Armed Services of the House of Representatives on the findings of the Secretary with respect to the pilot program required by subsection (a). The pilot metrics developed under subsection (b)(1). The findings of the Secretary with respect to the assessments carried out under subsection (b)(2). An analysis of the utility of speed-based metrics in assessing security operations centers and cyber security service providers. An analysis of the utility of the extension of the pilot metrics to or speed-based assessment of the Cyber Mission Forces. An assessment of the technical and procedural measures that would be necessary to meet the speed-based metrics developed and applied in the pilot program.” The Secretary of Defense shall integrate the plans, capabilities, and systems for user activity monitoring, and the plans, capabilities, and systems for endpoint cybersecurity and the collection of metadata on network activity for cybersecurity to enable mutual support and information sharing. consider using the Big Data Platform instances that host cybersecurity metadata for storage and analysis of all user activity monitoring data collected across the Department of Defense Information Network at all security classification levels; develop policies and procedures governing access to user activity monitoring data or data derived from user activity monitoring by cybersecurity operators; and develop processes and capabilities for using metadata on host and network activity for user activity monitoring in support of the insider threat mission. Not later than October 1, 2021 , the Secretary shall provide a briefing to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] on actions taken to carry out this section.” Not later than 270 days after the date of the enactment of this Act [ Jan. 1, 2021 ], the Secretary of Defense shall complete an assessment of the feasibility, suitability, and definition of, and resourcing required to establish, a defense industrial base threat information sharing program to collaborate and share threat information with, and obtain threat information from, the defense industrial base. extend beyond mandatory cybersecurity incident reporting requirements as in effect on the day before the date of the enactment of this Act; set specific, consistent timeframes for all categories of cybersecurity incident reporting; establish a single clearinghouse for all mandatory cybersecurity incident reporting to the Department of Defense, including incidents involving covered unclassified information, and classified information; and provide that, unless authorized or required by another provision of law or the element of the defense industrial base making the report consents, nonpublic information of which the Department becomes aware only because of a report provided pursuant to the program shall be disseminated and used only for a cybersecurity purpose (as such term is defined in section 102 of the Cybersecurity Information Sharing Act of 2015 ( 6 U.S.C. 1501 )) and in support of national defense activities. A mechanism for developing a shared and real-time picture of the threat environment. Options for joint, collaborative, and co-located analytics. Possible investments in technology and capabilities to support automated detection and analysis across the defense industrial base. Coordinated information tipping, sharing, and deconfliction, as necessary, with relevant Federal Government agencies with similar information sharing programs. Processes for direct sharing of threat information related to a specific defense industrial base entity with such entity. Mechanisms for providing defense industrial base entities with clearances for national security information access, as appropriate. Requirements to consent to queries of foreign intelligence collection databases related to a specific defense industrial base entity as a condition of participation in the threat information sharing program. Incentives for defense industrial base entities to participate in the threat information sharing program. Mandating minimum levels of threat information sharing program participation for any entity that is part of the defense industrial base. Procurement prohibitions on any defense industrial base entity that are not in compliance with the requirements of the threat information sharing program. Waiver authority and criteria. the role of and relative threats related to defense industrial base entities; and Cybersecurity Maturity Model Certification level. the existing program includes, or is modified to include, two-way sharing of threat information that is specifically relevant to the defense industrial base; and such a program is coordinated with other Federal Government agencies with existing information sharing programs where overlap occurs. Methods to encourage participation of defense industrial base entities in appropriate private sector information sharing and analysis centers (ISACs). Methods to coordinate collectively with defense industrial base entities to consider methods for mitigating compliance costs. The resources needed, governance roles and structures required, and changes in regulation or law needed for execution of a threat information sharing program, as well as any other considerations determined relevant by the Secretary. Identification of any barriers that would prevent the establishment of a defense industrial base threat information sharing program. In conducting the assessment required under subsection (a), the Secretary of Defense shall consult with and solicit recommendations from representative industry stakeholders across the defense industrial base regarding the elements described in subsection (b) and potential stakeholder costs of compliance. the findings of the Secretary with respect to such assessment and such determination; and such implementation plans as the Secretary may have arising from such findings. If the Secretary of Defense makes a positive determination pursuant to subsection (d) of the feasibility and suitability of establishing a defense industrial base threat information sharing program, the Secretary shall establish such program. Not later than 180 days after a positive determination, the Secretary of Defense shall promulgate such rules and regulations as are necessary to establish the defense industrial base threat information sharing program under this section.” Subject to the availability of appropriations, the Secretary of Defense, in consultation with the Director of the National Institute of Standards and Technology, may award financial assistance to a Center for the purpose of providing cybersecurity services to small manufacturers. If the Secretary carries out subsection (a), the Secretary, in consultation with the Director, shall establish and publish on the grants.gov website, or successor website, criteria for selecting recipients for financial assistance under this section. compliance with the cybersecurity requirements of the Department of Defense Supplement to the Federal Acquisition Regulation, including awareness, assessment, evaluation, preparation, and implementation of cybersecurity services; and achieving compliance with the Cybersecurity Maturity Model Certification framework of the Department of Defense; and may be used by a Center to employ trained personnel to deliver cybersecurity services to small manufacturers. Not less frequently than once every two years, the Secretary shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives], the Committee on Commerce, Science, and Transportation of the Senate, and the Committee on Science, Space, and Technology of the House of Representatives a report on financial assistance awarded under this section. The number of small manufacturers assisted. A description of the cybersecurity services provided. A description of the cybersecurity matters addressed. An analysis of the operational effectiveness and cost-effectiveness of such cybersecurity services. The authority of the Secretary to award financial assistance under this section shall terminate on the date that is five years after the date of the enactment of this section [ Jan. 1, 2021 ]. The term ‘Center’ has the meaning given such term in section 25(a) of the National Institute of Standards and Technology Act ( 15 U.S.C. 278k(a) ). The term ‘small manufacturer’ has the meaning given such term in section 1644(g) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 ( Public Law 115–232 ; 10 U.S.C. 2224 note).” Not later than 270 days after the date of the enactment of this Act [ Jan. 1, 2021 ], the Secretary of Defense shall complete an assessment of the feasibility, suitability, definition of, and resourcing required to establish a defense industrial base cybersecurity threat hunting program to actively identify cybersecurity threats and vulnerabilities within the defense industrial base. Existing defense industrial base cybersecurity threat hunting policies and programs, including the threat hunting elements at each level of the compliance-based Cybersecurity Maturity Model Certification program of the Department of Defense, including requirements germane to continuous monitoring, discovery, and investigation of anomalous activity indicative of a cybersecurity incident. Collection and analysis of metadata on network activity to detect possible intrusions. Rapid investigation and remediation of possible intrusions. Requirements for mitigating any vulnerabilities identified pursuant to the cybersecurity threat hunting program. Mechanisms for the Department of Defense to share with entities in the defense industrial base malicious code, indicators of compromise, and insights on the evolving threat landscape. Incentives for defense industrial base entities to share with the Department of Defense threat and vulnerability information collected pursuant to threat monitoring and hunting activities. Mandating minimum levels of program participation for any defense industrial base entity. Procurement prohibitions on any defense industrial base entity that is not in compliance with the requirements of the cybersecurity threat hunting program. Waiver authority and criteria. The cybersecurity maturity of defense industrial base entities. The roles of such entities. Whether each such entity possesses classified information or controlled unclassified information and covered defense networks. The covered defense information to which each such entity has access as a result of contracts with the Department of Defense. qualified prime contractors or subcontractors; accredited third-party cybersecurity vendors; United States Cyber Command; or a component of the Department of Defense other than United States Cyber Command; the deployment of network sensing technologies capable of identifying and filtering malicious network traffic; or a combination of the entities specified in subparagraphs (A) through (D). The resources necessary, governance structures or changes in regulation or law needed, and responsibility for execution of a defense industrial base cybersecurity threat hunting program, as well as any other considerations determined relevant by the Secretary. A timelime [sic] for establishing the defense industrial base cybersecurity threat hunting program not later than two years after the date of the enactment of this Act [ Jan. 1, 2021 ]. Identification of any barriers that would prevent such establishment. In conducting the assessment required under subsection (a), the Secretary of Defense shall consult with and solicit recommendations from representative industry stakeholders across the defense industrial base regarding the elements described in subsection (b) and potential stakeholder costs of compliance. the findings of the Secretary with respect to such assessment and such determination; and such implementation plans as the Secretary may have arising from such findings. If the Secretary of Defense makes a positive determination pursuant to subsection (d) of the feasibility and suitability of establishing a defense industrial base threat cybersecurity threat hunting program, the Secretary shall establish such program. Not later than 180 days after a positive determination, the Secretary of Defense shall promulgate such rules and regulations as are necessary to establish the defense industrial base cybersecurity threat hunting program under this section.” fit into an enterprise-wide cybersecurity architecture; are maximally interoperable with each other, including those programs and capabilities deployed by the components of the Department; enhance enterprise-level visibility and responsiveness to threats; and are developed, procured, instituted, and managed in a cost-efficient manner, exploiting economies of scale and enterprise-wide services and discouraging unnecessary customization and piecemeal acquisition. ensuring the cybersecurity architecture of the Department maximizes cybersecurity capability, network, and endpoint activity data sharing across Department components; ensuring the cybersecurity architecture of the Department supports improved automaticity of cybersecurity detection and response; and modernizing and configuring the Department’s standardized deployed perimeter, network-level, and endpoint capabilities to improve interoperability, meet pressing capability needs, and negate common adversary tactics, techniques, and procedures; establish mechanisms to enable and mandate, as necessary, cybersecurity capability and network and endpoint activity data-sharing across Department components; make mission data, through data tagging, automatic transmission, and other means, accessible and discoverable by Department components other than owners of such mission data; incorporate into the cybersecurity architecture of the Department emerging cybersecurity technologies from the Defense Advanced Research Projects Agency, the Strategic Capabilities Office, the Defense Innovation Unit, the laboratories of the military departments, and the commercial sector; ensure that the Department possesses the necessary computing infrastructure, through technology refresh, installation or acquisition of bandwidth, and the use of cloud computing power, to host and enable necessary cybersecurity capabilities; and the cybersecurity testing, architecting, and engineering expertise of the National Security Agency; and the technology policy, workforce, and engineering expertise of the Defense Digital Service.” either transfer or replicate and transfer such Department data in a prompt and secure manner to a secure repository with access by Department personnel appropriately limited on a need-to-know basis or otherwise ensure such consistent access to the relevant data by other means; ensure the Department applies such automated analytic tools and capabilities to the repository of potentially compromised data as are necessary to rapidly understand the scope and effect of the potential compromise; for high priority and mission critical Department systems, develop analytic products that characterize the scope of data compromised; ensure that relevant mission-affected entities in the Department are made aware of the theft or possible theft and, as damage assessment and mitigation proceeds, are kept apprised of the extent of the data stolen; and fully integrated with any damage assessment team assigned to the breach; fully informed of the data that have or potentially have been stolen and the effect of such theft; and provided resources and tasked, in conjunction with subject matter experts and responsible authorities, to immediately and appropriately respond, including through the development and execution of relevant countermeasures, to any breach involving espionage and data theft; or is in the possession of or under controls or restrictions imposed by the Federal Bureau of Investigation, or a national counterintelligence or intelligence organization, the Secretary shall determine, jointly with the Director of the Federal Bureau of Investigation or the Director of National Intelligence, as appropriate, the most expeditious process, means, and conditions for carrying out the activities otherwise required by paragraph (1). Not later than 90 days after the date of the enactment of this Act [ Dec. 20, 2019 ], the Secretary shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] such recommendations as the Secretary may have for legislative or administrative action to address such barriers that may be inhibiting the implementation of this section.” The National Security Agency shall, as a mission in its role in securing the information systems of the Department of Defense, advise and assist the Department of Defense in its evaluation and adoption of cybersecurity products and services from industry, especially the commercial cybersecurity sector. Consistent with subsection (a), the Director of the National Security Agency shall establish a permanent program consisting of market research, testing, and expertise transmission, or augments to existing programs, to improve the evaluation by the Department of Defense of cybersecurity products and services. generally known cyber operations techniques; and tools and cyber operations techniques and advanced tools and techniques available to the National Security Agency; develop and establish standard procedures, techniques, and threat-informed metrics to perform the testing and evaluation required by subparagraph (A); and any synergies between products; value; matters relating to operation and maintenance; and matters relating to customization requirements. be used to accredit cybersecurity products and services for use by the Department; create approved products lists; or be used for the procurement and fielding of cybersecurity products on behalf of the Department.” Not later than 180 days after the date of the enactment of the National Defense Authorization Act for Fiscal Year 2022 [ Dec. 27, 2021 ], the Secretary of Defense shall develop a consistent, comprehensive framework to enhance cybersecurity for the United States defense industrial base. Identification of unified cybersecurity standards, regulations, metrics, ratings, third-party certifications, or requirements to be imposed on the defense industrial base for the purpose of assessing the cybersecurity of individual contractors. Establishing and ensuring compliance with cybersecurity standards, regulations, and policies. Deconflicting existing cybersecurity standards, regulations, and policies. Coordinating with and providing assistance to the defense industrial base for cybersecurity matters, particularly as relates to the programs and processes described in paragraphs (8) and (9). Management and oversight of the acquisition process, including responsibility determination, solicitation, award, and contractor management, relating to cybersecurity standards, regulations, metrics, ratings, third-party certifications, or requirements. The responsibilities of the prime contractors, and all subcontractors in the supply chain, for implementing the required cybersecurity standards, regulations, metrics, ratings, third-party certifications, and requirements identified under paragraph (1). The extent to which the Department of Defense is identifying whether information is CUI via a contracting vehicle and marking documents, material, and media containing such information in a clear and consistent manner. Recommended regulatory or policy changes to ensure consistency and clarity in CUI identification and marking requirements. Circumstances under which commercial information is considered CUI, and any impacts to the commercial supply chain associated with security and marking requirements pursuant to this paragraph. Benefits and drawbacks of requiring all CUI to be marked with a unique CUI legend, versus requiring that all data marked with an appropriate restricted legend be handled as CUI. The extent to which the Department of Defense clearly delineates Federal Contract Information (FCI) from CUI. Examples or scenarios to illustrate information that is and is not CUI. Methods and programs for managing controlled unclassified information, and for limiting the presence of unnecessary sensitive information on contractor networks. A plan to provide implementation guidance, education, manuals, and, as necessary, direct technical support or assistance, to contractors on matters relating to cybersecurity. Quantitative metrics for assessing the effectiveness of the overall framework over time, with respect to the exfiltration of controlled unclassified information from the defense industrial base. A comprehensive list of current and planned Department of Defense programs to assist the defense industrial base with cybersecurity compliance requirements of the Department, including those programs that provide training, expertise, and funding, and maintain approved security products lists and approved providers lists. Processes for enhanced threat information sharing between the Department of Defense and the defense industrial base. Designating an official to be responsible for the cybersecurity of the defense industrial base. Risk-based methodologies, standards, metrics, and tiered cybersecurity requirements for the defense industrial base, including third-party certifications such as the Cybersecurity Maturity Model Certification pilot program, as the basis for a mandatory Department standard. Tailoring cybersecurity requirements for small- and medium-sized contractors based on a risk-based approach. Ensuring a consistent approach across the Department to cybersecurity standards, regulations, metrics, ratings, third-party certifications, or requirements of the defense industrial base. Ensuring the Department’s traceability and visibility of cybersecurity compliance of suppliers to all levels of the supply chain. Evaluating incentives and penalties for cybersecurity performance of suppliers. Integrating cybersecurity and traditional counterintelligence measures, requirements, and programs. Establishing a secure software development environment (DevSecOps) in a cloud environment inside the perimeter of the Department for contractors to perform their development work. Establishing a secure cloud environment through which contractors may access the data of the Department needed for their contract work. An evaluation of the resources and utilization of Department programs to assist the defense industrial base in complying with cybersecurity compliance requirements referred to in subsection (b)(1). Technological means, operational concepts, reference architectures, offensive counterintelligence operation concepts, and plans for operationalization to complicate adversary espionage, including honeypotting and data obfuscation. Implementing enhanced security vulnerability assessments for contractors working on critical acquisition programs, technologies, manufacturing capabilities, and research areas. Identifying ways to better leverage technology and employ machine learning or artificial intelligence capabilities, such as Internet Protocol monitoring and data integrity capabilities, to be applied to contractor information systems that host, receive, or transmit controlled unclassified information. Developing tools to easily segregate program data to only allow subcontractors access to their specific information. Appropriate communications of threat assessments of the defense industrial base to the acquisition workforce at all classification levels. A single Sector Coordinating Council for the defense industrial base. Appropriate communications with the defense industrial base on the impact of cybersecurity requirements in contracting and procurement decisions. Industry groups representing the defense industrial base. Contractors in the defense industrial base. The Director of the National Institute of Standards and Technology. The Secretary of Energy. The Director of National Intelligence. Relevant Federal regulatory agencies. Not later than March 11, 2020 , the Secretary of Defense shall provide the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] with a briefing on the framework developed pursuant to subsection (a). An overview of the framework developed pursuant to subsection (a). Identification of such pilot programs as the Secretary considers may be required to improve the cybersecurity of the defense industrial base. Implementation timelines and identification of costs. Such recommendations as the Secretary may have for legislative action to improve the cybersecurity of the defense industrial base. Not less frequently than once each quarter after the briefing provided pursuant to subsection (e) until February 1, 2022 , the Secretary of Defense shall brief the congressional defense committees on the status of development and implementation of the framework developed pursuant to subsection (a). Each briefing under paragraph (1) shall be conducted in conjunction with a quarterly briefing under section 484(a) of title 10 , United States Code. The current status of the development and implementation of the framework developed pursuant to subsection (a). A description of the efforts undertaken by the Secretary to evaluate the matters for consideration set forth in subsection (c). The current status of any pilot programs the Secretary is carrying out to develop the framework.” Not later than April 1, 2020 , the Secretary of Defense shall designate, for use by the Defense Information Systems Agency and such other components of the Department of Defense as the Secretary considers appropriate, three test networks for the testing and accreditation of cybersecurity products and services. be of sufficient scale to realistically test cybersecurity products and services; feature substantially different architectures and configurations; be live, operational networks; and feature cybersecurity processes, tools, and technologies that are appropriate for test purposes and representative of the processes, tools, and technologies that are widely used throughout the Department. Upon request, information generated in the testing and accreditation of cybersecurity products and services shall be made available to the Office of the Director, Operational Test and Evaluation.” In the event of a significant loss of personally identifiable information of civilian or uniformed members of the Armed Forces, or a significant loss of controlled unclassified information by a cleared defense contractor, the Secretary of Defense shall promptly submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] notice in writing of such loss. Such notice may be submitted in classified or unclassified formats. Not later than 180 days after the date of the enactment of this Act [ Aug. 13, 2018 ], the Secretary of Defense shall establish and submit to the congressional defense committees procedures for complying with the requirement of subsection (a). Such procedures shall be consistent with the national security of the United States, the protection of operational integrity, the protection of personally identifiable information of civilian and uniformed members of the Armed Forces, and the protection of controlled unclassified information. The term ‘significant loss of controlled unclassified information’ means an intentional, accidental, or otherwise known theft, loss, or disclosure of Department of Defense programmatic or technical controlled unclassified information the loss of which would have significant impact or consequence to a program or mission of the Department of Defense, or the loss of which is of substantial volume. The term ‘significant loss of personally identifiable information’ means an intentional, accidental, or otherwise known disclosure of information that can be used to distinguish or trace an individual’s identity, such as the name, Social Security number, date and place of birth, biometric records, home or other phone numbers, or other demographic, personnel, medical, or financial information, involving 250 or more civilian or uniformed members of the Armed Forces.” Not later than March 1, 2019 , the Secretary of Defense shall transfer the operations and maintenance for the Sharkseer cybersecurity program from the National Security Agency to the Defense Information Systems Agency, including all associated funding and, as the Secretary considers necessary, personnel. Of the funds authorized to be appropriated by this Act [see Tables for classification] or otherwise made available for fiscal year 2019 or any subsequent fiscal year for research, development, test, and evaluation for the Information Systems Security Program for the National Security Agency, not more than 90 percent may be obligated or expended unless the Chief of Information Officer, in consultation with the Principal Cyber Advisor, certifies to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] that the operations and maintenance funding for the Sharkseer program for fiscal year 2019 and the subsequent fiscal years of the current Future Years Defense Program are available or programmed. Not later than 90 days after the date of the enactment of this Act [ Aug. 13, 2018 ], the Chief Information Officer shall provide to the congressional defense committees a report that assesses the transition of base operations of the SharkSeer program to the Defense Information Systems Agency, including with respect to staffing, acquisition, contracts, sensor management, and the ability to conduct cyber threat analyses and detect advanced malware. Such report shall also include a plan for continued capability development. The Secretary of Defense shall ensure that the decryption capability described in section 1636 of the Carl Levin and Howard P. ‘Buck’ McKeon National Defense Authorization Act for Fiscal Year 2015 ( Public Law 113–291 ) [ 128 Stat. 3644 ] is provided by the break and inspect subsystem of the Sharkseer cybersecurity program, unless the Chief of Information Officer, in consultation with the Principal Cyber Advisor, notifies the congressional defense committees on or before the date that is 90 days after the date of the enactment of this Act that a superior enterprise solution will be operational before October 1, 2019 . The Secretary shall take such actions as are necessary to integrate the break and inspect subsystem of the Sharkseer cybersecurity program with the Department of Defense public key infrastructure. The Secretary shall take such actions as are necessary to enable, by October 1, 2020 , the Sharkseer cybersecurity program and computer network defense service providers to instantly and automatically determine the specific identity and location of computer hosts and other endpoints that received or sent malware detected by the Sharkseer cybersecurity program or other network perimeter defenses. The Secretary shall use the Sharkseer cybersecurity program sandbox-as-a-service capability as an enterprise solution and terminate all other such projects, unless the Chief of Information Officer, in consultation with the Principal Cyber Advisor, notifies the congressional defense committees on or before the date that is 90 days after the date of the enactment of this Act that a superior enterprise solution will be operational before October 1, 2019 .” Not later than 180 days after the date of the enactment of this Act [ Aug. 13, 2018 ], the Secretary of Defense shall designate one official to be responsible for matters relating to integrating cybersecurity and industrial control systems for the Department of Defense. The official designated pursuant to subsection (a) shall be responsible for matters described in such subsection at all levels of command, from the Department’s leadership to the facilities owned by or operated on behalf of the Department of Defense using industrial control systems, including developing Department-wide certification standards for integration of industrial control systems and taking into consideration frameworks set forth by the National Institute of Standards and Technology for the cybersecurity of such systems.” The Secretary of Defense, in consultation with the Director of the National Institute of Standards and Technology, shall take such actions as may be necessary to enhance awareness of cybersecurity threats among small manufacturers and universities working on Department of Defense programs and activities. The Secretary of Defense shall prioritize efforts to increase awareness to help reduce cybersecurity risks faced by small manufacturers and universities referred to in paragraph (1). The Secretary of Defense shall carry out this subsection with a focus on such small manufacturers and universities as the Secretary considers critical. Under paragraph (1), the Secretary of Defense shall conduct outreach to support activities consistent with this section. Such outreach may include live events with a physical presence and outreach conducted through Internet websites. Such outreach may include training, including via courses and classes, to help small manufacturers and universities improve their cybersecurity. The Secretary of Defense shall ensure that cybersecurity for defense industrial base manufacturing is included in appropriate research and development roadmaps and threat assessments. The Secretary of Defense shall develop mechanisms to provide assistance to help small manufacturers and universities conduct voluntary self-assessments in order to understand operating environments, cybersecurity requirements, and existing vulnerabilities, including through the Mentor Protégé Program, small business programs, and engagements with defense laboratories and test ranges. The Secretary of Defense shall promote the transfer of appropriate technology, threat information, and cybersecurity techniques developed in the Department of Defense to small manufacturers and universities throughout the United States to implement security measures that are adequate to protect covered defense information, including controlled unclassified information. The Secretary of Defense shall coordinate efforts, when appropriate, with the expertise and capabilities that exist in Federal agencies and federally sponsored laboratories. In carrying out this subsection, the Secretary of Defense may enter into agreements with private industry, institutes of higher education, or a State, United States territory, local, or tribal government to ensure breadth and depth of coverage to the United States defense industrial base and to leverage resources. The Secretary of Defense shall establish a cyber counseling certification program, or approve a similar existing program, to certify small business professionals and other relevant acquisition staff within the Department of Defense to provide cyber planning assistance to small manufacturers and universities. The Secretary of Defense may establish an activity to assess and strengthen the cybersecurity resiliency of the defense industrial base, if the Secretary determines such is appropriate. The activity described in paragraph (1), if established, shall be known as the ‘Cybersecurity for Defense Industrial Base Manufacturing Activity’. The Cybersecurity for Defense Industrial Base Manufacturing Activity, if established, shall implement the requirements specified in subsections (a) through (c). The Manufacturing Technology Program established under section 4841 of title 10 , United States Code. The Centers for Science, Technology, and Engineering Partnership program under section 2368 of title 10 , United States Code [now 10 U.S.C. 4124 ]. The Manufacturing Engineering Education Program established under section 2196 of title 10 , United States Code [now 10 U.S.C. 4843 ]. The Small Business Innovation Research program. The mentor-protégé program. Other legal authorities as the Secretary determines necessary to effectively and efficiently carry out this section. The term ‘resources’ means guidelines, tools, best practices, standards, methodologies, and other ways of providing information. The term ‘small business concern’ means a small business concern as that term is used in section 3 of the Small Business Act ( 15 U.S.C. 632 ). The term ‘small manufacturer’ means a small business concern that is a manufacturer in the defense industrial supply chain. The term ‘State’ means each of the several States, Territories, and possessions of the United States, the District of Columbia, and the Commonwealth of Puerto Rico.” Except as provided by subsection (b), the Secretary of Defense shall develop and implement the plan outlined in Binding Operational Directive 18–01, issued by the Secretary of Homeland Security on October 16, 2017 , relating to email security and authentication and Internet website security, according to the schedule established by the Binding Operational Directive for the rest of the Executive Branch beginning with the date of enactment of this Act [ Aug. 13, 2018 ]. The Secretary may waive the requirements of subsection (a) if the Secretary submits to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives], the Committee on Oversight and Government Reform [now Committee on Oversight and Accountability] of the House of Representatives, and the Committee on Homeland Security and Government Affairs of the Senate a certification that existing or planned security measures for the Department of Defense either meet or exceed the information security requirements of Binding Operational Directive 18–01. The Chief Information Officer of the Department of Defense shall notify the congressional defense committees, the Committee on Oversight and Government Reform [now Committee on Oversight and Accountability] of the House of Representatives, and the Committee on Homeland Security and Government Affairs of the Senate within 180 days of the issuance by the Secretary of Homeland Security after the date of the enactment of this Act of any Binding Operational Directive for cybersecurity whether the Department of Defense will comply with the Directive or how the Department of Defense plans to meet or exceed the security objectives of the Directive.” Whether, and if so, when, within five years before or at any time after the date of the enactment of this Act, the person has allowed a foreign government to review the code of a non-commercial product, system, or service developed for the Department, or whether the person is under any obligation to allow a foreign person or government to review the code of a non-commercial product, system, or service developed for the Department as a condition of entering into an agreement for sale or other transaction with a foreign government or with a foreign person on behalf of such a government. Whether, and if so, when, within five years before or at any time after the date of the enactment of this Act, the person has allowed a foreign government listed in section 1654 [of Pub. L. 115–232 , 10 U.S.C. 394 note] to review the source code of a product, system, or service that the Department is using or intends to use, or is under any obligation to allow a foreign person or government to review the source code of a product, system, or service that the Department is using or intends to use as a condition of entering into an agreement for sale or other transaction with a foreign government or with a foreign person on behalf of such a government. Whether or not the person holds or has sought a license pursuant to the Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, the International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations, or successor regulations, for information technology products, components, software, or services that contain code custom-developed for the non-commercial product, system, or service the Department is using or intends to use. The Secretary of Defense shall issue regulations regarding the implementation of subsection (a). If information obtained from a person under subsection (a) or the contents of the registry under subsection (f) are the subject of a request under section 552 of title 5 , United States Code (commonly referred to as the ‘Freedom of Information Act’), the Secretary of Defense shall conduct a uniform review process, without regard to the office holding the information, to determine if the information is exempt from disclosure under such section 552. Procurement contracts for covered products or systems shall include a clause requiring the information contained in subsection (a) be disclosed during the period of the contract if an entity becomes aware of information requiring disclosure required pursuant to such subsection, including any mitigation measures taken or anticipated. If, after reviewing a disclosure made by a person under subsection (a), the Secretary determines that the disclosure relating to a product, system, or service entails a risk to the national security infrastructure or data of the United States, or any national security system under the control of the Department, the Secretary shall take such measures as the Secretary considers appropriate to mitigate such risks, including, as the Secretary considers appropriate, by conditioning any agreement for the use, procurement, or acquisition of the product, system, or service on the inclusion of enforceable conditions or requirements that would mitigate such risks. Not later than two years after the date of the enactment of this Act the Secretary shall develop such third-party testing standard as the Secretary considers acceptable for commercial off the shelf (COTS) products, systems, or services to use when dealing with foreign governments. This section shall not apply to open source software. establish within the operational capabilities of the Committee for National Security Systems (CNSS) or within such other agency as the Secretary considers appropriate a registry containing the information disclosed under subsection (a); and upon request, make such information available to any agency conducting a procurement pursuant to the Federal Acquisition Regulations or the Defense Federal Acquisition Regulations. Not later than one year after the date of the enactment of this Act and not less frequently than once each year thereafter, the Secretary of Defense shall submit to the appropriate committees of Congress a report detailing the number, scope, product classifications, and mitigation agreements related to each product, system, and service for which a disclosure is made under subsection (a). the Committee on Armed Services, the Select Committee on Intelligence, and the Committee on Homeland Security and Governmental Affairs of the Senate; and the Committee on Armed Services, the Permanent Select Committee on Intelligence, the Committee on Homeland Security, and the Committee on Oversight and Government Reform [now Committee on Oversight and Accountability] of the House of Representatives. The term ‘commercial item’ has the meaning given such term in section 103 of title 41 , United States Code. The term ‘information technology’ has the meaning given such term in section 11101 of title 40 , United States Code. The term ‘national security system’ has the meaning given such term in section 3552(b) of title 44 , United States Code. The term ‘non-commercial product, system, or service’ means a product, system, or service that does not meet the criteria of a commercial item. The term ‘open source software’ means software for which the human-readable source code is available for use, study, re-use, modification, enhancement, and re-distribution by the users of such software.” establish processes and procedures to integrate strategic information operations and cyber-enabled information operations across the elements of the Department of Defense responsible for such operations, including the elements of the Department responsible for military deception, public affairs, electronic warfare, and cyber operations; and ensure that such processes and procedures provide for integrated Defense-wide strategy, planning, and budgeting with respect to the conduct of such operations by the Department, including activities conducted to counter and deter such operations by malign actors. The Secretary of Defense shall designate a senior official of the Department of Defense (in this section referred to as the ‘designated senior official’) who shall implement and oversee the processes and procedures established under paragraph (1). The designated senior official shall be selected by the Secretary from among individuals serving in the Department of Defense at or below the level of an Under Secretary of Defense. Oversight of strategic policy and guidance. Overall resource management for the integration of information operations and cyber-enabled information operations of the Department. Coordination with the head of the Global Engagement Center to support the purpose of the Center (as described [in] section 1287(a)(2) of the National Defense Authorization Act for Fiscal Year 2017 ( Public Law 114–328 ; 22 U.S.C. 2656 note)) and liaison with the Center and other relevant Federal Government entities to support such purpose. Development of a strategic framework for the conduct of information operations by the Department of Defense, including cyber-enabled information operations, coordinated across all relevant elements of the Department of Defense, including both near-term and long-term guidance for the conduct of such coordinated operations. Development and dissemination of a common operating paradigm across the elements of the Department of Defense specified in paragraph (1) to counter the influence, deception, and propaganda activities of key malign actors, including in cyberspace. Development of guidance for, and promotion of, the capability of the Department of Defense to liaison with the private sector, including social media, on matters relating to the influence activities of malign actors. The Secretary shall require each commander of a combatant command to develop, in coordination with the relevant regional Assistant Secretary of State or Assistant Secretaries of State and with the assistance of the Coordinator of the Global Engagement Center and the designated senior official, a regional information strategy and interagency coordination plan for carrying out the strategy, where applicable. The Secretary shall require each commander of a combatant command to develop such requirements and specific plans as may be necessary for the conduct of information operations in support of the strategy required under subparagraph (A), including plans for deterring information operations, including deterrence in the cyber domain, by malign actors against the United States, allies of the United States, and interests of the United States. review the strategy of the Department of Defense titled ‘Department of Defense Strategy for Operations in the Information Environment’ and dated June 2016; and submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a plan for implementation of such strategy. An accounting of the efforts undertaken in support of the strategy described in subparagraph (A)(i) in the period since it was issued in June 2016. A description of any updates or changes to such strategy that have been made since it was first issued, as well as any expected updates or changes resulting from the designation of the designated senior official. A description of the role of the Department of Defense as part of a broader whole-of-Government strategy for strategic communications, including a description of any assumptions about the roles and contributions of other departments and agencies of the Federal Government with respect to such a strategy. Defined actions, performance metrics, and projected timelines for achieving each of the 15 tasks specified in the strategy described in subparagraph (A)(i). An analysis of any personnel, resourcing, capability, authority, or other gaps that will need to be addressed to ensure effective implementation of the strategy described in subparagraph (A)(i) across all relevant elements of the Department of Defense. An investment framework and projected timeline for addressing any gaps identified under clause (v). Such other matters as the Secretary of Defense considers relevant. Not less frequently than once every 90 days during the three-year period beginning on the date on which the implementation plan is submitted under subparagraph (A)(ii), the designated senior official shall submit to the congressional defense committees a report describing the status of the efforts of the Department of Defense in accomplishing the tasks specified under clauses (iv) and (vi) of subparagraph (B). Consistent with the elements of the implementation plan under paragraph (2), the designated senior official shall recommend the establishment of programs to provide training and education to such members of the Armed Forces and civilian employees of the Department of Defense as the Secretary considers appropriate to ensure that such members and employees understand the role of information in warfare, the central goal of all military operations to affect the perceptions, views, and decision making of adversaries, and the effective management and conduct of operations in the information environment.” Subject to subsection (b), the Secretary of Defense, in consultation with the Secretary of Homeland Security, may carry out exercises relating to the cybersecurity of election systems of States as part of the exercise commonly known as the ‘Cyber Guard Exercise’. agrees to participate in such exercise; and agrees to allow vulnerability testing of the components of the State’s election system. Not later than 90 days after the completion of any Cyber Guard Exercise, the Secretary of Defense shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a report on the ability of the National Guard to assist States, if called upon, in defending election systems from cyberattacks. Such report shall include a description of the capabilities, readiness levels, and best practices of the National Guard with respect to the prevention of cyber attacks on State election systems.” Not later than January 1, 2018 , the Secretary of Defense shall make such changes to the cybersecurity scorecard as are necessary to ensure that the Secretary measures the progress of each element of the Department of Defense in securing the industrial control systems of the Department against cyber threats, including such industrial control systems as supervisory control and data acquisition systems, distributed control systems, programmable logic controllers, and platform information technology. In this section, the term ‘cybersecurity scorecard’ means the Department of Defense Cybersecurity Scorecard used by the Department to measure compliance with cybersecurity requirements as described in the plan of the Department titled ‘Department of Defense Cybersecurity Discipline Implementation Plan’.” to support a high state of mission readiness in the command through the use of one or more cyber opposition forces in continuous exercises and other training activities as considered appropriate by the commander of the command; and in conducting such exercises and training activities, [to] meet the standard required under subsection (b). Not later than March 31, 2017 , the Secretary of Defense shall issue a joint training and certification standard for use by all cyber opposition forces within the Department of Defense. provide for applied training and exercise capabilities; and use expertise and capabilities from other departments and agencies of the Federal Government, as appropriate. a list of each combatant command that has established an agreement under subsection (a); special conditions in the agreement placed on any cyber opposition force used by the command; the process for making decisions about deconfliction and risk mitigation of cyber opposition force activities in continuous exercises and training; identification of cyber opposition forces trained and certified to operate at the joint standard, as issued under subsection (b); identification of the annual exercises that will include participation of the cyber opposition forces; and identification of any shortfalls in resources that may prevent annual exercises using cyber opposition forces; and any other matters the Secretary of Defense considers appropriate.” Subject to a determination by the Secretary of Defense, the Secretary may provide cyber protection support for the personal technology devices of the personnel described in paragraph (2). who the Secretary determines to be highly vulnerable to cyber attacks and hostile information collection activities because of the positions occupied by such personnel in the Department; and whose personal technology devices are highly vulnerable to cyber attacks and hostile information collection activities. Subject to the availability of resources, the cyber protection support provided to personnel under subsection (a) may include training, advice, assistance, and other services relating to cyber attacks and hostile information collection activities. to encourage personnel of the Department of Defense to use personal technology devices for official business; or to authorize cyber protection support for senior Department personnel using personal devices and networks in an official capacity. a description of the methodology used to make the determination under subsection (a)(2); and guidance for the use of cyber protection support and tracking of support requests for personnel receiving cyber protection support under subsection (a). In this section, the term ‘personal technology devices’ means technology devices used by Department of Defense personnel outside of the scope of their employment with the Department and includes networks to which such devices connect.” the department or Defense Agency concerned completes operational test and evaluation activities to determine the effectiveness, suitability, and survivability of the joint regional security stacks system of such department or Defense Agency; and written certification that such testing and evaluation activities have been completed is provided to the Secretary of such department or the head of such Defense Agency by the appropriate operational test and evaluation organization of such department or Defense Agency. the Secretary of the military department or the head of the Defense Agency concerned; the Director of Operational Test and Evaluation for the Department of Defense; and the Chief Information Officer of the Department of Defense. the testing and evaluation activities required under subsection (a) are unnecessary, accompanied by an explanation of the reasons such activities are unnecessary; the effectiveness, suitability, and survivability of the joint regional security stacks system of the military department or Defense Agency concerned has been demonstrated by methods other than the testing and evaluation activities required under subsection (a), accompanied by supporting data; or national security needs justify full deployment of the joint regional security stacks system of the military department or Defense Agency concerned before the test and evaluation activities required under subsection (a) can be completed, accompanied by an explanation of such justification and a risk management plan.” Not later than 180 days after the date of the enactment of this Act [ Dec. 23, 2016 ], the Secretary shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a plan for the evaluation of the cyber vulnerabilities of the critical infrastructure of the Department of Defense. an identification of each of the military installations to be evaluated; and an estimate of the cost of the evaluation. the Armed Forces stationed at such military installations; and threats to such military installations. The plan under paragraph (1) shall build upon other efforts of Department of Defense relating to the identification and mitigation of cyber vulnerabilities of major weapon systems and critical infrastructure of the Department and shall not duplicate such efforts. to improve the defense of control systems against cyber attacks; to increase the resilience of military installations against cybersecurity threats; to prevent or mitigate the potential for high-consequence cyber attacks; to inform future requirements for the development of such control systems; and to assess the strategic benefits derived from, and the challenges associated with, isolating military infrastructure from the national electric grid and the use of microgrids. The Secretary shall carry out the pilot program under paragraph (1) at not fewer than two military installations selected by the Secretary from among military installations that support the most critical mission-essential functions of the Department of Defense as identified in the plan under subsection (a). In carrying out the pilot program under paragraph (1), the Secretary may use tools and solutions developed under subsection (e). a description of the activities carried out under the pilot program at each military installation concerned; an assessment of the value of the methodologies or tools applied during the pilot program in increasing the resilience of military installations against cybersecurity threats; recommendations for administrative or legislative actions to improve the ability of the Department to employ methodologies and tools for reducing cyber vulnerabilities in other activities of the Department of Defense; and recommendations for including such methodologies or tools as requirements for relevant activities, including technical requirements for systems or military construction projects. The authority of the Secretary to carry out the pilot program under this subsection shall terminate on September 30, 2020 . Not later than December 31, 2020 , the Secretary shall complete an evaluation of the cyber vulnerabilities of the critical infrastructure of the Department of Defense in accordance with the plan under subsection (a). The Secretary shall develop strategies for mitigating the risks of cyber vulnerabilities identified in the course of the evaluation under paragraph (1). develop tools that improve assessments of cyber vulnerabilities of Department of Defense critical infrastructure; conduct non-recurring engineering for the design of mitigation solutions for such vulnerabilities; and establish Department-wide information repositories to share findings relating to such assessments and to share such mitigation solutions. The term ‘critical infrastructure of the Department of Defense’ means any asset of the Department of Defense of such extraordinary importance to the functioning of the Department and the operation of the Armed Forces that the incapacitation or destruction of such asset by a cyber attack would have a debilitating effect on the ability of the Department to fulfill its missions. a research laboratory of the Department of Defense; or a research laboratory of the Department of Energy approved by the Secretary of Energy to carry out the pilot program under subsection (b).” a proposed information security architecture for the capability; a concept of operations for the capability; and requirements with respect to the functionality and interoperability of the tools, sensors, systems, processes, and other components of the continuous monitoring capability; and a comply-to-connect policy that requires systems to automatically comply with the configurations of the networks of the Department as a condition of connecting to such networks. In developing the plan and policy under paragraph (1), the Chief Information Officer and the Commander shall consult with the Principal Cyber Advisor to the Secretary of Defense. The Chief Information Officer and the Commander shall each issue such directives as they each consider appropriate to ensure compliance with the plan and policy developed under paragraph (1). The Secretary of Defense shall include funding and program plans relating to the plan and policy under paragraph (1) in the budget materials submitted by the Secretary in support of the budget of the President for fiscal year 2019 (as submitted to Congress under section 1105(a) of title 31 , United States Code). The Chief Information Officer and the Commander shall ensure that information generated through automated and automation-assisted processes for continuous monitoring, asset management, and comply-to-connect policies and processes shall be accessible and usable in machine-readable form to appropriate cyber protection teams and computer network defense service providers. The plan and policy required by paragraph (1) shall comply with the software license inventory requirements of the plan issued pursuant to section 937 of the National Defense Authorization Act for Fiscal Year 2013 ( Public Law 112–239 ; 10 U.S.C. 2223 note) and updated pursuant to section 935 of the National Defense Authorization Act for Fiscal Year 2014 ( Public Law 113–66 ; 10 U.S.C. 2223 note). to count the number of such licenses in use; and to determine the security status of each instance of use of the software licensed. beginning on January 1, 2018 , with respect to any contract entered into by the Secretary of Defense on or after such date for the licensing of software; and beginning on January 1, 2020 , with respect to any contract entered into by the Secretary for the licensing of software that was in effect on December 31, 2017 .” Development and acquisition of cyber operations-peculiar equipment and capabilities. Acquisition and sustainment of cyber capability-peculiar equipment, capabilities, and services. Subject to the authority, direction, and control of the Secretary of Defense, the Commander shall have authority to exercise the functions of the head of an agency under chapter 137 of title 10, United States Code. to negotiate memoranda of agreement with the military departments and Department of Defense components to carry out the acquisition of equipment, capabilities, and services described in subsection (a)(1) on behalf of the Command; to supervise the acquisition of equipment, capabilities, and services described in subsection (a)(1); to represent the Command in discussions with the military departments regarding acquisition programs for which the Command is a customer; and to work with the military departments to ensure that the Command is appropriately represented in any joint working group or integrated product team regarding acquisition programs for which the Command is a customer. responsible to the Commander for rapidly delivering acquisition solutions to meet validated cyber operations-peculiar requirements; subordinate to the defense acquisition executive in matters of acquisition; subject to the same oversight as the service acquisition executives; and included on the distribution list for acquisition directives and instructions of the Department of Defense. program acquisition; the Joint Capabilities Integration and Development System Process; program management; system engineering; and costing. The personnel provided under this subsection shall be provided from among the existing personnel of the Department of Defense. development and acquisition of cyber operations-peculiar equipment; and acquisition and sustainment of other capabilities or services that are peculiar to cyber operations activities. Nothing in this section shall be construed to constitute authority to conduct any activity which, if carried out as an intelligence activity by the Department of Defense, would require a notice to the Select Committee on Intelligence of the Senate and the Permanent Select Committee on Intelligence of the House of Representatives under title V of the National Security Act of 1947 ( 50 U.S.C. 3091 et seq.). cyber operations-peculiar equipment and capabilities; and cyber capability-peculiar equipment, capabilities, and services. Summaries of the components to be negotiated in the memorandum of agreements with the military departments and other Department of Defense components to carry out the development, acquisition, and sustainment of equipment, capabilities, and services described in subparagraphs (A) and (B) of subsection (a)(1). Memorandum of agreement negotiation and approval timelines. Plan for oversight of the command acquisition executive established in subsection (b). Assessment of the acquisition workforce needs of the United States Cyber Command to support the authority in subsection (a) until 2021. Other matters as appropriate. Each year, the Cyber Investment Management Board shall review and assess the acquisition activities of the United States Cyber Command, including contracting and acquisition documentation, for the previous fiscal year, and provide any recommendations or feedback to the acquisition executive of Cyber Command.” The Secretary of Defense shall, in accordance with the plan under subsection (b), complete an evaluation of the cyber vulnerabilities of each major weapon system of the Department of Defense by not later than December 31, 2019 . The Secretary may waive the requirement of paragraph (1) with respect to a weapon system or complete the evaluation of a weapon system required by such paragraph after the date specified in such paragraph if the Secretary certifies to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] before that date that all known cyber vulnerabilities in the weapon system have minimal consequences for the capability of the weapon system to meet operational requirements or otherwise satisfy mission requirements. Not later than 180 days after the date of the enactment of this Act [ Nov. 25, 2015 ], the Secretary shall submit to the congressional defense committees the plan of the Secretary for the evaluations of major weapon systems under subsection (a), including an identification of each of the weapon systems to be evaluated and an estimate of the funding required to conduct the evaluations. The plan under paragraph (1) shall accord a priority among evaluations based on the criticality of major weapon systems, as determined by the Chairman of the Joint Chiefs of Staff based on an assessment of employment of forces and threats. The plan under paragraph (1) shall build upon existing efforts regarding the identification and mitigation of cyber vulnerabilities of major weapon systems, and shall not duplicate similar ongoing efforts such as Task Force Cyber Awakening of the Navy or Task Force Cyber Secure of the Air Force. develop tools to improve the detection and evaluation of cyber vulnerabilities; conduct non-recurring engineering for the design of solutions to mitigate cyber vulnerabilities; and establish Department-wide information repositories to share findings relating to the evaluation and mitigation of cyber vulnerabilities. As part of the evaluation of cyber vulnerabilities of major weapon systems of the Department under this section, the Secretary shall develop strategies for mitigating the risks of cyber vulnerabilities identified in the course of such evaluations. Of the funds authorized to be appropriated by this Act [see Tables for classification] or otherwise made available for fiscal year 2016 for research, development, test, and evaluation, Defense-wide, not more than $200,000,000 shall be available to the Secretary to conduct the evaluations under subsection (a)(1). An identification of each major weapon system for which an evaluation will not be complete by the date specified in subsection (a)(1), the anticipated date of completion of the evaluation of each such weapon system, and a description of the remaining work to be done for the evaluation of each such weapon system. A justification for the inability to complete such an evaluation by the date specified in subsection (a)(1). An identification of cyber vulnerabilities of each major weapon system requiring mitigation. An identification of current and planned efforts to address the cyber vulnerabilities of each major weapon system requiring mitigation, including efforts across the doctrine, organization, training, materiel, leadership and education, personnel, and facilities of the Department. A description of joint and common cyber vulnerability mitigation solutions and efforts, including solutions and efforts across the doctrine, organization, training, materiel, leadership and education, personnel, and facilities of the Department. A description of lessons learned and best practices regarding evaluations of the cyber vulnerabilities and cyber vulnerability mitigation efforts relating to major weapon systems, including an identification of useful tools and technologies for discovering and mitigating vulnerabilities, such as those specified in section 1657 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 ( Public Law 115–232 ) [ 132 Stat. 2151 ], and steps taken to institutionalize the use of these tools and technologies. A description of efforts to share lessons learned and best practices regarding evaluations of the cyber vulnerabilities and cyber vulnerability mitigation efforts of major weapon systems across the Department. An identification of measures taken to institutionalize evaluations of cyber vulnerabilities of major weapon systems, including an identification of which major weapon systems evaluated under this section will be reevaluated in the future, when these evaluations will occur, and how evaluations will occur for future major weapon systems. Information relating to guidance, processes, procedures, or other activities established to mitigate or address the likelihood of cyber vulnerabilities of major weapon systems by incorporation of lessons learned in the research, development, test, evaluation, and acquisition cycle, including promotion of cyber education of the acquisition workforce. An identification of systems to be incorporated into or that have been incorporated into the National Security Agency’s Strategic Cybersecurity Program and the status of these systems in the Program. Any other matters the Secretary determines relevant. The Secretary of Defense shall establish policies and requirements for each major weapon system, and the priority critical infrastructure essential to the proper functioning of major weapon systems in broader mission areas, to be re-assessed for cyber vulnerabilities, taking into account upgrades or other modifications to systems and changes in the threat landscape. Each secretary of a military department shall identify a senior official who shall be responsible for ensuring that cyber vulnerability assessments and mitigations for weapon systems and critical infrastructure are planned, funded, and carried out.” Not later than 30 days after the Secretary of Defense determines, through the use of open source information or the use of existing authorities (including section 806 of the National Defense Authorization Act for Fiscal Year 2011 ( Public Law 111–383 ; 124 Stat. 4260 ; 10 U.S.C. 2304 note)), that there is evidence of a national security threat described in paragraph (2), the Secretary shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a notification of such threat. A national security threat described in this paragraph is a threat to an information technology or telecommunications component or network by an agent of a foreign power in which the compromise of such technology, component, or network poses a significant risk to the programs and operations of the Department of Defense, as determined by the Secretary of Defense. A notification under this subsection shall be submitted in classified form. In the event that a notification is submitted pursuant to subsection (a), the Secretary shall work with the head of any department or agency affected by the national security threat to develop a plan of action for responding to the concerns leading to the notification. In this section, the term ‘agent of a foreign power’ has the meaning given such term in section 101(b) of the Foreign Intelligence Surveillance Act of 1978 ( 50 U.S.C. 1801(b) ).” The Secretary of Defense shall take such actions as the Secretary considers appropriate to provide the United States Cyber Command operational military units with infrastructure and equipment enabling access to the Internet and other types of networks to permit the United States Cyber Command to conduct the peacetime and wartime missions of the Command. The Secretary shall review existing cyber ranges and adapt one or more such ranges, as necessary, to support training and exercises of cyber units that are assigned to execute offensive military cyber operations. have not been previously identified and prepared for attack; and must be compromised or neutralized immediately without regard to whether the adversary can detect or attribute the attack. Transferred to section 392a(a) of this title .] The Secretary shall establish and maintain training capabilities and facilities in the Armed Forces and, as the Secretary considers appropriate, at the United States Cyber Command, to support the needs of the Armed Forces and the United States Cyber Command for personnel who are assigned offensive and defensive cyber missions in the Department of Defense.” the development of training standards for computer network operations tool developers for military, civilian, and contractor personnel supporting the cyber mission forces; the rapid enhancement of capacity to train personnel to those standards to meet the needs of the cyber mission forces for tool development; and actions necessary to ensure timely completion of personnel security investigations and adjudications of security clearances for tool development personnel.” The Under Secretary of Defense for Acquisition, Technology, and Logistics, in coordination with the Chief Information Officer of the Department of Defense, shall develop and implement a baseline software assurance policy for the entire lifecycle of covered systems. Such policy shall be included as part of the strategy for trusted defense systems of the Department of Defense. require use of appropriate automated vulnerability analysis tools in computer software code during the entire lifecycle of a covered system, including during development, operational testing, operations and sustainment phases, and retirement; require covered systems to identify and prioritize security vulnerabilities and, based on risk, determine appropriate remediation strategies for such security vulnerabilities; ensure such remediation strategies are translated into contract requirements and evaluated during source selection; promote best practices and standards to achieve software security, assurance, and quality; and support competition and allow flexibility and compatibility with current or emerging software methodologies. collect data on implementation of the policy developed under subsection (a) and measure the effectiveness of such policy, including the particular elements required under subsection (b); and identify and promote best practices, tools, and standards for developing and validating assured software for the Department of Defense. A research and development strategy to advance capabilities in software assurance and vulnerability detection. The state-of-the-art of software assurance analysis and test. How the Department might hold contractors liable for software defects or vulnerabilities. a major system, as that term is defined in section 3041 of title 10 , United States Code; a national security system, as that term is defined in [former] section 3542(b)(2) of title 44 , United States Code [see now 44 U.S.C. 3552(b)(6) ]; or a Department of Defense information system categorized as Mission Assurance Category I in Department of Defense Directive 8500.01E that is funded by the Department of Defense. The term ‘software assurance’ means the level of confidence that software functions as intended and is free of vulnerabilities, either intentionally or unintentionally designed or inserted as part of the software, throughout the life cycle.” The Secretary of Defense shall develop and implement a plan to augment the cybersecurity strategy of the Department of Defense through the acquisition of advanced capabilities to discover and isolate penetrations and attacks that were previously unknown and for which signatures have not been developed for incorporation into computer intrusion detection and prevention systems and anti-virus software systems. be adequate to enable well-trained analysts to discover the sophisticated attacks conducted by nation-state adversaries that are categorized as ‘advanced persistent threats’; endpoints or hosts; network-level gateways operated by the Defense Information Systems Agency where the Department of Defense network connects to the public Internet; and global networks owned and operated by private sector Tier 1 Internet Service Providers; automatic blocking of unauthorized software programs and accepting approved and vetted programs; constant monitoring of all key computer attributes, settings, and operations (such as registry keys, operations running in memory, security settings, memory tables, event logs, and files); and automatic baselining and remediation of altered computer settings and files; increasing the number and skill level of the analysts assigned to query stored data, whether by contracting for security services, hiring and training Government personnel, or both; and increasing the capacity of the system to handle the rates for data flow through the gateways and the storage requirements specified by the United States Cyber Command; and include the behavior-based threat detection capabilities of Tier 1 Internet Service Providers and other companies that operate on the global Internet. The capabilities to be acquired shall, to the maximum extent practicable, be acquired from commercial sources. In making decisions on the procurement of such capabilities from among competing commercial and Government providers, the Secretary shall take into consideration the needs of other departments and agencies of the Federal Government, State and local governments, and critical infrastructure owned and operated by the private sector for unclassified, affordable, and sustainable commercial solutions. The plan required by subsection (a) shall include mechanisms for improving the standardization, organization, and management of the security information and event management systems that are widely deployed across the Department of Defense to improve the ability of United States Cyber Command to understand and control the status and condition of Department networks, including mechanisms to ensure that the security information and event management systems of the Department receive and correlate data collected and analyses conducted at the host or endpoint, at the network gateways, and by Internet Service Providers in order to discover new attacks reliably and rapidly. The plan required by subsection (a) shall provide for the conduct of demonstrations, pilot projects, and other tests on cyber test ranges and operational networks in order to determine and verify that the capabilities to be acquired pursuant to the plan are effective, practical, and affordable. Not later than April 1, 2012 , the Secretary shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a report on the plan required by subsection (a). The report shall set forth the plan and include a comprehensive description of the actions being undertaken by the Department to implement the plan.” The Secretary of Defense shall establish an Institute for Defense Computer Security and Information Protection. to conduct research and technology development that is relevant to foreseeable computer and network security requirements and information assurance requirements of the Department of Defense with a principal focus on areas not being carried out by other organizations in the private or public sector; and to facilitate the exchange of information regarding cyberthreats, technology, tools, and other relevant issues. The Secretary shall enter into a contract with a not-for-profit entity, or a consortium of not-for-profit entities, to organize and operate the institute. The Secretary shall use competitive procedures for the selection of the contractor to the extent determined necessary by the Secretary. Of the amount authorized to be appropriated by section 301(5) [ 114 Stat. 1654 A–52], $5,000,000 shall be available for the Institute for Defense Computer Security and Information Protection. Not later than April 1, 2001 , the Secretary shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] the Secretary’s plan for implementing this section.”
Verify at the official source: Federal legislative text
Facing this? Know exactly what happens next.
MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.
This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.