Sec. 202. Management of information technology
499 words·~2 min read·
/bill/113/hr/1468/ih/section-202·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Section 11331 of title 40, United States Code, is amended to read as follows: Except as provided under paragraph (2), the Secretary of Commerce shall prescribe standards and guidelines pertaining to Federal information systems— in consultation with the Secretary of Homeland Security; and on the basis of standards and guidelines developed by the National Institute of Standards and Technology under paragraphs
(2)and
(3)of section 20(a) of the National Institute of Standards and Technology Act ( 15 U.S.C. 278g–3(a)(2) and (a)(3)). Standards and guidelines for national security systems shall be developed, prescribed, enforced, and overseen as otherwise authorized by law and as directed by the President. The Secretary of Commerce shall make standards and guidelines under subsection (a)(1) compulsory and binding to the extent determined necessary by the Secretary of Commerce to improve the efficiency of operation or security of Federal information systems. Standards and guidelines under subsection (a)(1) shall include information security standards that— provide minimum information security requirements as determined under section 20(b) of the National Institute of Standards and Technology Act ( 15 U.S.C. 278g–3(b) ); and are otherwise necessary to improve the security of Federal information and information systems. Information security standards under subparagraph
(A)shall be compulsory and binding. To ensure fiscal and policy consistency, the Secretary of Commerce shall exercise the authority conferred by this section subject to direction by the President and in coordination with the Director. The head of an executive agency may employ standards for the cost-effective information security for information systems within or under the supervision of that agency that are more stringent than the standards and guidelines the Secretary of Commerce prescribes under this section if the more stringent standards and guidelines— contain at least the applicable standards and guidelines made compulsory and binding by the Secretary of Commerce; and are otherwise consistent with the policies, directives, and implementation memoranda issued under section 3553(a) of title 44. The decision by the Secretary of Commerce regarding the promulgation of any standard or guideline under this section shall occur not later than 6 months after the date of submission of the proposed standard to the Secretary of Commerce by the National Institute of Standards and Technology under section 20 of the National Institute of Standards and Technology Act ( 15 U.S.C. 278g–3 ). A decision by the Secretary of Commerce to significantly modify, or not promulgate, a proposed standard submitted to the Secretary by the National Institute of Standards and Technology under section 20 of the National Institute of Standards and Technology Act ( 15 U.S.C. 278g–3 ) shall be made after the public is given an opportunity to comment on the Secretary’s proposed decision. In this section: The term Federal information system has the meaning given the term in section 3552 of title 44. The term information security has the meaning given the term in section 3552 of title 44. The term national security system has the meaning given the term in section 3552 of title 44. .
Connections3 off-index
3 references not yet in our index
- 15 USC 278g–3(a)(2)
- 15 USC 278g–3(b)
- 15 USC 278g–3
Citation graph
cites case law
Sec. 202
Management of information technology
Cite15 USC 278g–3(a)(2)
Cite15 USC 278g–3(b)
Cite15 USC 278g–3
Cites 3Cited by 0 across 0 sources