Federal · Title 10 — Armed Forces

10 U.S.C. § 6228: Reporting on penetrations of networks of contractors and subcontractors

Read the full statutory text
The Administrator shall establish procedures that require each contractor and subcontractor to report to the Chief Information Officer when a covered network of the contractor or subcontractor that meets the criteria established pursuant to subsection (b) is successfully penetrated. The Administrator shall, in consultation with the officials specified in paragraph (2), establish criteria for covered networks to be subject to the procedures for reporting penetrations under subsection (a). The Deputy Administrator for Defense Programs. The Associate Administrator for Acquisition and Project Management. The Chief Information Officer. Any other official of the Administration the Administrator considers necessary. The procedures established pursuant to subsection (a) shall require each contractor or subcontractor to submit to the Chief Information Officer a report on each successful penetration of a covered network of the contractor or subcontractor that meets the criteria established pursuant to subsection (b) not later than 60 days after the discovery of the successful penetration. A description of the technique or method used in such penetration. A sample of the malicious software, if discovered and isolated by the contractor or subcontractor, involved in such penetration. A summary of information created by or for the Administration in connection with any program of the Administration that has been potentially compromised as a result of such penetration. include in the report all information available as of that date; and provide to the Chief Information Officer the additional information required by subparagraph (B) as the information becomes available. in the case of a penetration of a covered network of a management and operating contractor, enhance the access of personnel of the Administration to Government-owned equipment and information; and in the case of a penetration of a covered network of a contractor or subcontractor that is not a management and operating contractor, facilitate the access of personnel of the Administration to the equipment and information of the contractor or subcontractor; and include mechanisms for personnel of the Administration to, upon request, obtain access to equipment or information of a contractor or subcontractor necessary to conduct forensic analysis in addition to any analysis conducted by the contractor or subcontractor; provide that a contractor or subcontractor is only required to provide access to equipment or information as described in clause (i) to determine whether information created by or for the Administration in connection with any program of the Administration was successfully exfiltrated from a network of the contractor or subcontractor and, if so, what information was exfiltrated; and provide for the reasonable protection of trade secrets, commercial or financial information, and information that can be used to identify a specific person. with missions that may be affected by such information; that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents; that conduct counterintelligence or law enforcement investigations; or for national security purposes, including cyber situational awareness and defense purposes. The term “Chief Information Officer” means the Associate Administrator for Information Management and Chief Information Officer of the Administration. The term “contractor” means a private entity that has entered into a contract or contractual action of any kind with the Administration to furnish supplies, equipment, materials, or services of any kind. classified information; or sensitive unclassified information germane to any program of the Administration, as determined by the Administrator. The term “subcontractor” means a private entity that has entered into a contract or contractual action with a contractor or another subcontractor to furnish supplies, equipment, materials, or services of any kind in connection with another contract in support of any program of the Administration.

Verify at the official source: Federal legislative text

Facing this? Know exactly what happens next.

MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.

This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.