Federal · Title 10 — Armed Forces

10 U.S.C. § 499: Annual assessment of cyber resiliency of nuclear command and control system

Read the full statutory text
Not less frequently than annually, the Commander of the United States Strategic Command and the Commander of the United States Cyber Command (in this section referred to collectively as the “Commanders”) shall jointly conduct an assessment of the cyber resiliency of the nuclear command and control system. conduct an assessment of the sufficiency and resiliency of the nuclear command and control system to operate through a cyber attack from the Russian Federation, the People’s Republic of China, or any other country or entity the Commanders identify as a potential threat; and develop recommendations for mitigating any concerns of the Commanders resulting from the assessment. The recommendations developed under subsection (b)(2). A statement of the degree of confidence of each of the Commanders in the mission assurance of the nuclear deterrent against a top tier cyber threat. A detailed description of the approach used to conduct the assessment required by subsection (a) and the technical basis of conclusions reached in conducting that assessment. Any other comments of the Commanders. The Council shall submit to the Secretary of Defense each report required by paragraph (1) and any comments of the Council on each report. Not later than 90 days after the date of the submission of a report under paragraph (1), the Secretary of Defense shall submit to the congressional defense committees the report, any comments of the Council on the report under paragraph (2), and any comments of the Secretary on the report. an assessment of any known, suspected, or potential impacts of such intrusions and anomalies to the mission effectiveness of military capabilities as of the date of the briefing; and with respect to cyber intrusions of contractor networks known or suspected to have resulted in the loss or compromise of design information regarding the nuclear command, control, and communications system; or if no such intrusion or anomaly occurred with respect to the quarter to be covered by that briefing, a notification of such lack of intrusions and anomalies. The term “anomaly” means a malicious, suspicious or abnormal cyber incident that potentially threatens the national security or interests of the United States, or that is likely to result in demonstrable harm to the national security of the United States. The term “intrusion” means an unauthorized and malicious cyber incident that compromises a nuclear command, control, and communications system by breaking the security of such a system or causing it to enter into an insecure state. The requirements of this section shall terminate on December 31, 2032 . Not later than 180 days after the date of the enactment of this Act [ Dec. 22, 2023 ], and consistent with section 911(c) of the National Defense Authorization Act for Fiscal Year 2017 ( Public Law 114–328 ; 10 U.S.C. 111 note), the Secretary of Defense shall establish a cross-functional team to develop and direct the implementation of a threat-driven cyber defense construct for the systems and networks that support the nuclear command, control, and communications (commonly referred to as ‘NC3’) mission (in this section referred to as the ‘cross-functional team’). The cross functional team shall be composed of senior officers selected from among each of the military departments, the Defense Information Systems Agency, the National Security Agency, the United States Cyber Command, the United States Strategic Command, and any other organization or element of the Department of Defense determined appropriate by the Secretary. The Secretary shall designate a senior officer from those selected under subparagraph (A) to serve as the leader of the cross-functional team. The Secretary shall ensure the heads of the organizations and elements specified in subparagraph (A) detail staff to support the cross-functional team in carrying out the duties under paragraph (3). The duties of the cross-functional team shall be to enhance the cyber defense of the systems and networks that support the nuclear command, control, and communications mission. the application of the principles of the approach to cybersecurity commonly referred to as ‘zero trust architecture’; an analysis of appropriately comprehensive endpoint and network telemetry data; and control capabilities enabling rapid investigation and remediation of indicators of compromise and threats to mission execution. During the 60-day period beginning on the date that is 30 days before the date on which the President submits to Congress the budget of the President pursuant to section 1105(a) of title 31 , United States Code, for each of fiscal years 2025 through 2028, the Secretary shall provide to the appropriate congressional committees a briefing on the implementation of this section. Except as provided in paragraph (2), the cross-functional team under this section shall terminate on October 31, 2028 . The Secretary of Defense may extend the date of termination under paragraph (1) as the Secretary determines appropriate. the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives]; and the Permanent Select Committee on Intelligence of the House of Representatives.” Not later than October 1, 2021 , the Secretary of Defense shall submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a comprehensive plan, including a schedule and resourcing plan, for the implementation of the findings and recommendations included in the first report submitted under section 499(c)(3) of title 10 , United States Code. roles and responsibilities of relevant entities within the Office of the Secretary, the military services, combatant commands, the Defense Agencies, and the Department of Defense Field Activities; and cybersecurity capabilities to be acquired and employed and operational tactics, techniques, and procedures, including cyber protection team and sensor deployment strategies, to be used to monitor, defend, and mitigate vulnerabilities in nuclear command and control systems; and roles and responsibilities of relevant entities within the Office of the Secretary, the military services, combatant commands, the Defense Agencies, and the Department of Defense Field Activities in overseeing the defense of the nuclear command and control system against cyber attacks; vulnerability assessments; and development, systems engineering, and acquisition activities; and processes for coordination of activities, policies, and programs relating to the cybersecurity and defense of the nuclear command and control system.”

Verify at the official source: Federal legislative text

Facing this? Know exactly what happens next.

MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.

This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.