Federal · Title 6 — Domestic Security
6 U.S.C. § 1524: Assessment; reports
Read the full statutory text
The term “agency information” has the meaning given the term in section 2213 of the Homeland Security Act of 2002 [ 6 U.S.C. 663 ]. The terms “cyber threat indicator” and “defensive measure” have the meanings given those terms in section 650 of this title . The term “intrusion assessments” means actions taken under the intrusion assessment plan to identify and remove intruders in agency information systems. The term “intrusion assessment plan” means the plan required under section 2210(b)(1) of the Homeland Security Act of 2002 [ 6 U.S.C. 660(b)(1) ]. The term “intrusion detection and prevention capabilities” means the capabilities required under section 2213(b) of the Homeland Security Act of 2002 [ 6 U.S.C. 663(b) ]. Not later than 3 years after December 18, 2015 , the Comptroller General of the United States shall conduct a study and publish a report on the effectiveness of the approach and strategy of the Federal Government to securing agency information systems, including the intrusion detection and prevention capabilities and the intrusion assessment plan. a description of privacy controls; a description of the technologies and capabilities utilized to detect cybersecurity risks in network traffic, including the extent to which those technologies and capabilities include existing commercial and noncommercial technologies; a description of the technologies and capabilities utilized to prevent network traffic associated with cybersecurity risks from transiting or traveling to or from agency information systems, including the extent to which those technologies and capabilities include existing commercial and noncommercial technologies; a list of the types of indicators or other identifiers or techniques used to detect cybersecurity risks in network traffic transiting or traveling to or from agency information systems on each iteration of the intrusion detection and prevention capabilities and the number of each such type of indicator, identifier, and technique; the number of instances in which the intrusion detection and prevention capabilities detected a cybersecurity risk in network traffic transiting or traveling to or from agency information systems and the number of times the intrusion detection and prevention capabilities blocked network traffic associated with cybersecurity risk; and a description of the pilot established under section 2213(c)(5) of the Homeland Security Act of 2002 [ 6 U.S.C. 663(c)(5) ], including the number of new technologies tested and the number of participating agencies. a list of each agency and the degree to which each agency has applied the intrusion detection and prevention capabilities to an agency information system; and the number of instances in which the intrusion detection and prevention capabilities detected a cybersecurity risk in network traffic transiting or traveling to or from an agency information system and the types of indicators, identifiers, and techniques used to detect such cybersecurity risks; and the number of instances in which the intrusion detection and prevention capabilities prevented network traffic associated with a cybersecurity risk from transiting or traveling to or from an agency information system and the types of indicators, identifiers, and techniques used to detect such agency information systems. the effectiveness of the system in detecting, disrupting, and preventing cyber-threat actors, including advanced persistent threats, from accessing agency information and agency information systems; whether the intrusion detection and prevention capabilities, continuous diagnostics and mitigation, and other systems deployed under subtitle D 1 of title II of the Homeland Security Act of 2002 ( 1 See References in Text note below. 6 U.S.C. 231 et seq.) are effective in securing Federal information systems; the costs and benefits of the intrusion detection and prevention capabilities, including as compared to commercial technologies and tools and including the value of classified cyber threat indicators; and the capability of agencies to protect sensitive cyber threat indicators and defensive measures if they were shared through unclassified mechanisms for use in commercial technologies and tools. not later than 6 months after December 18, 2015 , and 30 days after any update thereto, submit the intrusion assessment plan to the appropriate congressional committees; a description of the implementation of the intrusion assessment plan; the findings of the intrusion assessments conducted pursuant to the intrusion assessment plan; a description of the advanced network security tools included in the efforts to continuously diagnose and mitigate cybersecurity risks pursuant to section 1522(a)(1) of this title ; and a list by agency of compliance with the requirements of section 1523(b) of this title ; and a copy of the plan developed pursuant to section 1522(a)(2) of this title ; and the improved metrics developed pursuant to section 1522(c) of this title . Each report required under this section shall be submitted in unclassified form, but may include a classified annex.
Verify at the official source: Federal legislative text
Facing this? Know exactly what happens next.
MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.
This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.