Federal · Title 44 — Public Printing and Documents

44 U.S.C. § 3554: Federal agency responsibilities

Read the full statutory text
information collected or maintained by or on behalf of the agency; and information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency; information security standards promulgated under section 11331 of title 40 ; operational directives developed by the Secretary under section 3553(b); policies and procedures issued by the Director; information security standards and guidelines for national security systems issued in accordance with law and as directed by the President; emergency directives issued by the Secretary under section 3553(h); and responsibilities relating to assessing and avoiding, mitigating, transferring, or accepting supply chain risks under section 1326 of title 41 , and complying with exclusion and removal orders issued under section 1323 of such title; and ensuring that information security management processes are integrated with agency strategic, operational, and budgetary planning processes; assessing the risk and magnitude of the harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of such information or information systems; determining the levels of information security appropriate to protect such information and information systems in accordance with standards promulgated under section 11331 of title 40 , for information security classifications and related requirements; implementing policies and procedures to cost-effectively reduce risks to an acceptable level; and periodically testing and evaluating information security controls and techniques to ensure that they are effectively implemented; carry out the Chief Information Officer’s responsibilities under this section; possess professional qualifications, including training and experience, required to administer the functions described under this section; have information security duties as that official’s primary duty; and head an office with the mission and resources to assist in ensuring agency compliance with this section; developing and maintaining an agencywide information security program as required by subsection (b); developing and maintaining information security policies, procedures, and control techniques to address all applicable requirements, including those issued under section 3553 of this title and section 11331 of title 40 ; training and overseeing personnel with significant responsibilities for information security with respect to such responsibilities; and assisting senior agency officials concerning their responsibilities under paragraph (2); ensure that the agency has trained personnel sufficient to assist the agency in complying with the requirements of this subchapter and related policies, procedures, standards, and guidelines; ensure that the agency Chief Information Officer, in coordination with other senior agency officials, reports annually to the agency head on the effectiveness of the agency information security program, including progress of remedial actions; ensure that senior agency officials, including chief information officers of component agencies or equivalent officials, carry out responsibilities under this subchapter as directed by the official delegated authority under paragraph (3); and ensure that all personnel are held accountable for complying with the agency-wide information security program implemented under subsection (b). periodic assessments of the risk and magnitude of the harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems that support the operations and assets of the agency, which may include using automated tools consistent with standards and guidelines promulgated under section 11331 of title 40 ; are based on the risk assessments required by paragraph (1); cost-effectively reduce information security risks to an acceptable level; ensure that information security is addressed throughout the life cycle of each agency information system; and the requirements of this subchapter; policies and procedures as may be prescribed by the Director, and information security standards promulgated under section 11331 of title 40 ; minimally acceptable system configuration requirements, as determined by the agency; and any other applicable requirements, including standards and guidelines for national security systems issued in accordance with law and as directed by the President; subordinate plans for providing adequate information security for networks, facilities, and systems or groups of information systems, as appropriate; information security risks associated with their activities; and their responsibilities in complying with agency policies and procedures designed to reduce these risks; shall include testing of management, operational, and technical controls of every information system identified in the inventory required under section 3505(c); 1 1 So in original. Section 3505 contains two subsecs. (c). may include testing relied on in an evaluation under section 3555; and shall include using automated tools, consistent with standards and guidelines promulgated under section 11331 of title 40 ; a process for planning, implementing, evaluating, and documenting remedial action to address any deficiencies in the information security policies, procedures, and practices of the agency; shall be consistent with the standards and guidelines described in section 3556(b); may include using automated tools; and mitigating risks associated with such incidents before substantial damage is done; notifying and consulting with the Federal information security incident center established in section 3556; and law enforcement agencies and relevant Offices of Inspector General and Offices of General Counsel; an office designated by the President for any incident involving a national security system; not later than 7 days after the date on which there is a reasonable basis to conclude that the major incident has occurred; and after the initial notification under item (aa), within a reasonable period of time after additional information relating to the incident is discovered, including the summary required under subsection (c)(1)(A)(i); and any other agency or office, in accordance with law or as directed by the President; and plans and procedures to ensure continuity of operations for information systems that support the operations and assets of the agency. the threats and threat actors, vulnerabilities, and impacts relating to the incident; the risk assessments conducted under section 3554(a)(2)(A) of the affected information systems before the date on which the incident occurred; the status of compliance of the affected information systems with applicable security requirements at the time of the incident; and the detection, response, and remediation actions; the total number of information security incidents, including a description of incidents resulting in significant compromise of information security, system impact levels, types of incident, and locations of affected systems; the number of individuals whose information was affected by the major information security incident; and a description of the information that was breached or exposed; and any other information as the Director or the Secretary, in consultation with the Director, may require. Each report submitted under subparagraph (A) shall be in unclassified form, but may include a classified annex. The head of an agency shall ensure that, to the greatest extent practicable, information is included in the unclassified version of the reports submitted by the agency under subparagraph (A). Each agency shall address the adequacy and effectiveness of information security policies, procedures, and practices in management plans and reports. the time periods; and the resources, including budget, staffing, and training, The description under paragraph (1) shall be based on the risk assessments required under subsection (b)(1). Each agency shall provide the public with timely notice and opportunities for comment on proposed information security policies and procedures to the extent that such policies and procedures affect communication with the public. develop guidance on what constitutes a major incident for purposes of section 3554(b) of title 44 , United States Code, as added by subsection (a); and provide to Congress periodic briefings on the status of the developing of the guidance until the date on which the guidance is issued.”

Verify at the official source: Federal legislative text

Facing this? Know exactly what happens next.

MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.

This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.