Federal · Title 10 — Armed Forces

10 U.S.C. § 391: Reporting on cyber incidents with respect to networks and information systems of operationally critical contractors and certain other contractors

Read the full statutory text
The Secretary of Defense shall designate a component of the Department of Defense to receive reports of cyber incidents from contractors in accordance with this section and section 393 of this title or from other governmental entities. The Secretary of Defense shall establish procedures that require an operationally critical contractor to report in a timely manner to component designated under subsection (a) each time a cyber incident occurs with respect to a network or information system of such operationally critical contractor. designating operationally critical contractors; and notifying a contractor that it has been designated as an operationally critical contractor. An assessment by the contractor of the effect of the cyber incident on the ability of the contractor to meet the contractual requirements of the Department. The technique or method used in such cyber incident. A sample of any malicious software, if discovered and isolated by the contractor, involved in such cyber incident. A summary of information compromised by such cyber incident. include mechanisms for Department personnel to, if requested, assist operationally critical contractors in detecting and mitigating penetrations; and provide that an operationally critical contractor is only required to provide access to equipment or information as described in subparagraph (A) to determine whether information created by or for the Department in connection with any Department program was successfully exfiltrated from a network or information system of such contractor and, if so, what information was exfiltrated. The procedures established pursuant to subsection (a) shall provide for the reasonable protection of trade secrets, commercial or financial information, and information that can be used to identify a specific person. with missions that may be affected by such information; that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents; that conduct counterintelligence or law enforcement investigations; or for national security purposes, including cyber situational awareness and defense purposes. No cause of action shall lie or be maintained in any court against any operationally critical contractor, and such action shall be promptly dismissed, for compliance with this section and contract requirements established pursuant to Defense Federal Acquisition Regulation Supplement clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, that is conducted in accordance with procedures established pursuant to subsection (b) and such contract requirements. to require dismissal of a cause of action against an operationally critical contractor that has engaged in willful misconduct in the course of complying with the procedures established pursuant to subsection (b); or to undermine or limit the availability of otherwise applicable common law or statutory defenses. In any action claiming that paragraph (1) does not apply due to willful misconduct described in subparagraph (A), the plaintiff shall have the burden of proving by clear and convincing evidence the willful misconduct by each operationally critical contractor subject to such claim and that such willful misconduct proximately caused injury to the plaintiff. intentionally to achieve a wrongful purpose; knowingly without legal or factual justification; and in disregard of a known or obvious risk that is so great as to make it highly probable that the harm will outweigh the benefit. The term “cyber incident” means actions taken through the use of computer networks that result in an actual or potentially adverse effect on an information system or the information residing therein. The term “operationally critical contractor” means a contractor designated by the Secretary for purposes of this section as a critical source of supply for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation. To provide the Secretary a formal mechanism to communicate with consortium members regarding the Department of Defense’s cybersecurity strategic plans, cybersecurity requirements, and priorities for basic and applied cybersecurity research. To advise the Secretary on the needs of academic institutions related to cybersecurity and research conducted on behalf of the Department and provide feedback to the Secretary from members of the consortium or consortia. To serve as a focal point or focal points for the Secretary and the Department for the academic community on matters related to cybersecurity, cybersecurity research, conceptual and academic developments in cybersecurity, and opportunities for closer collaboration between academia and the Department. To provide to the Secretary access to the expertise of the institutions of the consortium or consortia on matters relating to cybersecurity. To align the efforts of such members in support of the Department. The consortium established under subsection (a) shall be open to all universities that have been designated as centers of academic excellence by the Director of the National Security Agency or the Secretary of Homeland Security. The Secretary of Defense shall designate the National Defense University College of Information and Cyberspace to function as the administrative chair of the consortium established pursuant to subsection (a). act as the leader of the consortium; be the liaison between the consortium and the Secretary; distribute requests from the Secretary for advice and assistance to appropriate members of the consortium and coordinate responses back to the Secretary; and act as a clearinghouse for Department of Defense requests relating to assistance on matters relating to cybersecurity and to provide feedback to the Secretary from members of the consortium. The Secretary, in consultation with the administrative chair, may form an executive committee for the consortium that is comprised of representatives of the Federal Government to assist the chair with the management and functions of the consortium. The Secretary shall meet with such members of the consortium as the Secretary considers appropriate, not less frequently than twice each year or at such periodicity as is agreed to by the Secretary and the consortium. The Secretary shall establish procedures for organizations within the Department to access the work product produced by and the research, capabilities, and expertise of a consortium established under subsection (a) and the universities that constitute such consortium. The Secretary shall establish a center to provide support to the consortium established under subsection (a). have been designated as centers of academic excellence by the Director of the National Security Agency or the Secretary of Homeland Security; and are eligible for access to classified information. The Secretary shall publish in the Federal Register the process for selection of universities to serve as the center established under paragraph (1). To promote the consortium established under subsection (a). To distribute on behalf of the Department requests for information or assistance to members of the consortium. To collect and assemble responses from requests distributed under subparagraph (B). To provide additional administrative support for the consortium. In carrying out this section, the Secretary of Defense shall act through the Director of the office established under section 2192c of title 10 , United States Code.” requirements that were in effect on the day before the date of the enactment of this Act for contractors to share information with Department components regarding cyber incidents (as defined in subsection (d) [now (e)] of such section 391 [ 10 U.S.C. 391(e) ]) with respect to networks or information systems of contractors; and Department policies and systems for sharing information on cyber incidents with respect to networks or information systems of Department contractors. designate a Department component under subsection (a) of such section 391; and issue or revise guidance applicable to Department components that ensures the rapid sharing by the component designated pursuant to such section 391 or section 941 of the National Defense Authorization Act for Fiscal Year 2013 [ Pub. L. 112–239 ] ( 10 U.S.C. 2224 note) of information relating to cyber incidents with respect to networks or information systems of contractors with other appropriate Department components.”

Verify at the official source: Federal legislative text

Facing this? Know exactly what happens next.

MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.

This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.