Federal · Title 10 — Armed Forces

10 U.S.C. § 4129: Joint Federated Assurance Center

Read the full statutory text
There is in the Office of the Under Secretary of Defense for Research and Engineering a Joint Federated Assurance Center (referred to in this section as the “Center”). The purpose of the Center shall be to serve as a joint, Department-wide federation of organizations and capabilities to support the assurance needs of the Department of Defense by ensuring, pursuant to policies related to hardware and software assurance and supply chain risk management, that the software and hardware developed, acquired, maintained, and used by the Department are free from intentional and unintentional vulnerability during the life-cycle of development and deployment of assured, trustworthy defense systems. The Center shall be governed by an Executive Steering Group. The Executive Steering Group shall continually evaluate the Center’s capabilities to support the hardware and software assurance needs of the Department. The Executive Steering Group shall be composed of one or more representatives from each of the organizations that comprise the Center. The Under Secretary of Defense for Research and Engineering and the Under Secretary of Defense for Acquisition and Sustainment shall serve as co-Chairpersons of the Executive Steering Group. Providing knowledge management capabilities for hardware and software assurance for the Department. Providing Department-wide visibility on strategy, use cases, procurement, investment, and other relevant activities to aggregate, to the extent practicable, assurance tool purchases by the Department. to support timely and cost-effective fielding of current and future technologies to the Department; to ensure sustainment of enduring capability needs across the life-cycle of Department of Defense programs and determine the sustainment factors related to the assurance of future hardware and software systems; to increase efficiencies across Department of Defense programs through the use of emerging assurance technologies; and to leverage economies of scale through coordinated acquisition and use of hardware and software assurance technologies. to mature assessment criteria and enable scalable deployment of commercial best practices, such as through the fostering and maturation of evidence-based assurance of trusted defense microelectronics system needs, with emphasis on commercial security protocols that are transferable to defense applications; to scale the Center for Department-wide access, through the resourcing of adequate personnel to address standardization and automation of data collection and analysis; to utilize data from commercial assurance processes to support the development of Department hardware and software that meet standards, applications, and requirements, including through comparative analysis and data modeling; to seek and apply commercial best practices, where practicable, through industry collaboration; and to develop and align Department policy, investments, and activities with commercial best practices, to the extent practicable. the consideration of evidence-based assurance processes and techniques that are included in the contract data requirements list, to the extent practicable; the use of commercial best practices, as applicable, for confidentiality, integrity and availability; and the development of a library of certified third-party intellectual property for reuse, including streamlining legal mechanisms for data collection and sharing, and enhanced use of automation technology to achieve efficiency. development and assessment of validation methods for such processes and techniques, in coordination with the developmental and operational test and evaluation community, as the Executive Steering Group determines necessary; development and assessment of threat models that comprehensively characterize the threat to microelectronics confidentiality, integrity, and availability across the entire supply chain, and the design, production, packaging, and deployment cycle to support risk management and risk mitigation; and support development of guides to inform use and decision-making by program evaluators, program offices, and industry to meet software and hardware assurance requirements. the role and authorities of the Center and the Executive Steering Group; the requirement of the Center to establish guidelines for the development of improved software code vulnerability analysis and testing tools; the requirement of the Center to establish guidelines for the development of improved hardware vulnerability testing and protection tools; and the manner in which the Center will connect to the Department’s major governance and resourcing processes to ensure the continuation of Center duties.

Verify at the official source: Federal legislative text

Facing this? Know exactly what happens next.

MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.

This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.