U.S. CODE
Rulings
AD/CVD
Notices
HTSUS
U.S. Code
Regs
More
Ports
About
Updates
Apps
Larger font
Smaller font
CustomsMobile Pro
beta now open!
Apply for a FREE beta account. Spaces are limited so apply today.
SIGNUP FOR BETA
SEARCH
Toggle Dropdown
Search US Code
Search Leg. Notes
Sort by Rank
Titles Ascending
Titles Descending
10 per page
25 Result/page
50 Result/page
U.S Code last checked for updates: Nov 22, 2024
All Titles
Title 6
Chapter 6
Subchapter II
§ 1523. Federal cybersecurity re...
§ 1525. Termination...
§ 1523. Federal cybersecurity re...
§ 1525. Termination...
U.S. Code
Notes
§ 1524.
Assessment; reports
(a)
Definitions
In this section:
(1)
Agency information
(2)
Cyber threat indicator; defensive measure
(3)
Intrusion assessments
(4)
Intrusion assessment plan
(5)
Intrusion detection and prevention capabilities
(b)
Third-party assessment
(c)
Reports to Congress
(1)
Intrusion detection and prevention capabilities
(A)
Secretary of Homeland Security report
Not later than 6 months after
December 18, 2015
, and annually thereafter, the Secretary shall submit to the appropriate congressional committees a report on the status of implementation of the intrusion detection and prevention capabilities, including—
(i)
a description of privacy controls;
(ii)
a description of the technologies and capabilities utilized to detect cybersecurity risks in network traffic, including the extent to which those technologies and capabilities include existing commercial and noncommercial technologies;
(iii)
a description of the technologies and capabilities utilized to prevent network traffic associated with cybersecurity risks from transiting or traveling to or from agency information systems, including the extent to which those technologies and capabilities include existing commercial and noncommercial technologies;
(iv)
a list of the types of indicators or other identifiers or techniques used to detect cybersecurity risks in network traffic transiting or traveling to or from agency information systems on each iteration of the intrusion detection and prevention capabilities and the number of each such type of indicator, identifier, and technique;
(v)
the number of instances in which the intrusion detection and prevention capabilities detected a cybersecurity risk in network traffic transiting or traveling to or from agency information systems and the number of times the intrusion detection and prevention capabilities blocked network traffic associated with cybersecurity risk; and
(vi)
a description of the pilot established under section 2213(c)(5) of the Homeland Security Act of 2002 [
6 U.S.C. 663
(c)(5)], including the number of new technologies tested and the number of participating agencies.
(B)
OMB report
Not later than 18 months after
December 18, 2015
, and annually thereafter, the Director shall submit to Congress, as part of the report required under
section 3553(c) of title 44
, an analysis of agency application of the intrusion detection and prevention capabilities, including—
(i)
a list of each agency and the degree to which each agency has applied the intrusion detection and prevention capabilities to an agency information system; and
(ii)
a list by agency of—
(I)
the number of instances in which the intrusion detection and prevention capabilities detected a cybersecurity risk in network traffic transiting or traveling to or from an agency information system and the types of indicators, identifiers, and techniques used to detect such cybersecurity risks; and
(II)
the number of instances in which the intrusion detection and prevention capabilities prevented network traffic associated with a cybersecurity risk from transiting or traveling to or from an agency information system and the types of indicators, identifiers, and techniques used to detect such agency information systems.
(C)
Chief information officer
Not earlier than 18 months after
December 18, 2015
, and not later than 2 years after
December 18, 2015
, the Federal Chief Information Officer shall review and submit to the appropriate congressional committees a report assessing the intrusion detection and intrusion prevention capabilities, including—
(i)
the effectiveness of the system in detecting, disrupting, and preventing cyber-threat actors, including advanced persistent threats, from accessing agency information and agency information systems;
(ii)
whether the intrusion detection and prevention capabilities, continuous diagnostics and mitigation, and other systems deployed under subtitle D
1
1
See References in Text note below.
of title II of the Homeland Security Act of 2002 (
6 U.S.C. 231
et seq.) are effective in securing Federal information systems;
(iii)
the costs and benefits of the intrusion detection and prevention capabilities, including as compared to commercial technologies and tools and including the value of classified cyber threat indicators; and
(iv)
the capability of agencies to protect sensitive cyber threat indicators and defensive measures if they were shared through unclassified mechanisms for use in commercial technologies and tools.
(2)
OMB report on development and implementation of intrusion assessment plan, advanced internal defenses, and Federal cybersecurity requirements
The Director shall—
(A)
not later than 6 months after
December 18, 2015
, and 30 days after any update thereto, submit the intrusion assessment plan to the appropriate congressional committees;
(B)
not later than 1 year after
December 18, 2015
, and annually thereafter, submit to Congress, as part of the report required under
section 3553(c) of title 44
—
(i)
a description of the implementation of the intrusion assessment plan;
(ii)
the findings of the intrusion assessments conducted pursuant to the intrusion assessment plan;
(iii)
a description of the advanced network security tools included in the efforts to continuously diagnose and mitigate cybersecurity risks pursuant to
section 1522(a)(1) of this title
; and
(iv)
a list by agency of compliance with the requirements of
section 1523(b) of this title
; and
(C)
not later than 1 year after
December 18, 2015
, submit to the appropriate congressional committees—
(i)
a copy of the plan developed pursuant to
section 1522(a)(2) of this title
; and
(ii)
the improved metrics developed pursuant to
section 1522(c) of this title
.
(d)
Form
(
Pub. L. 114–113, div. N, title II, § 226
,
Dec. 18, 2015
,
129 Stat. 2969
;
Pub. L. 115–278, § 2(h)(1)(F)
,
Nov. 16, 2018
,
132 Stat. 4182
;
Pub. L. 117–263, div. G, title LXXI, § 7143(d)(1)(B)
,
Dec. 23, 2022
,
136 Stat. 3663
.)
cite as:
6 USC 1524
.list_box li,p,.cm-search-info,.cm-search-detail,.abt span,.expand-collapse_top
Get the CustomsMobile app!