Federal · Title 6 — Domestic Security

6 U.S.C. § 1523: Federal cybersecurity requirements

Read the full statutory text
Consistent with section 3553 of title 44 , the Secretary, in consultation with the Director, shall exercise the authority to issue binding operational directives to assist the Director in ensuring timely agency adoption of and compliance with policies and standards promulgated under section 11331 of title 40 1 for securing agency information systems. 1 See References in Text note below. identify sensitive and mission critical data stored by the agency consistent with the inventory required under the first subsection (c) (relating to the inventory of major information systems) and the second subsection (c) (relating to the inventory of information systems) of section 3505 of title 44 ; assess access controls to the data described in subparagraph (A), the need for readily accessible storage of the data, and individuals’ need to access the data; encrypt or otherwise render indecipherable to unauthorized users the data described in subparagraph (A) that is stored on or transiting agency information systems; implement a single sign-on trusted identity platform for individuals accessing each public website of the agency that requires user authentication, as developed by the Administrator of General Services in collaboration with the Secretary; and remote access to an agency information system; and each user account with elevated privileges on an agency information system. operational requirements articulated in the certification and related to the agency information system would make it excessively burdensome to implement the cybersecurity requirement; the cybersecurity requirement is not necessary to secure the agency information system or agency information stored on or transiting it; and the agency has taken all necessary steps to secure the agency information system and agency information stored on or transiting it; and the head of the agency or the designee of the head of the agency has submitted the certification described in subparagraph (A) to the appropriate congressional committees and the agency’s authorizing committees. Nothing in this section shall be construed to alter the authority of the Secretary, the Director, or the Director of the National Institute of Standards and Technology in implementing subchapter II of chapter 35 of title 44. Nothing in this section shall be construed to affect the National Institute of Standards and Technology standards process or the requirement under section 3553(a)(4) of such title or to discourage continued improvements and advancements in the technology, standards, policies, and guidelines used to promote Federal information security. The requirements under this section shall not apply to the Department of Defense, a national security system, or an element of the intelligence community.

Verify at the official source: Federal legislative text

Facing this? Know exactly what happens next.

MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.

This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.