Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 113th Congress · H.R. 3979 (EAH) — 113 HR 3979 EAH: Carl Levin and Howard P. ‘Buck’ McKeon National Defense Authorization Act for Fiscal Year 2015 · Sec. 1632

Sec. 1632. Reporting on cyber incidents with respect to networks and information systems of operationally critical contractors

798 words·~4 min read·/bill/113/hr/3979/eah/section-1632

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

Part I of subtitle A of title 10, United States Code, is amended by inserting after chapter 18 the following new chapter: Sec. 391. Reporting on cyber incidents with respect to networks and information systems of operationally critical contractors. The Secretary of Defense shall designate a component of the Department of Defense to receive reports of cyber incidents from contractors in accordance with this section and with section 941 of the National Defense Authorization Act for Fiscal Year 2013 ( 10 U.S.C. 2224 note) or from other governmental entities.
The Secretary of Defense shall establish procedures that require an operationally critical contractor to report in a timely manner to component designated under subsection
(a)each time a cyber incident occurs with respect to a network or information system of such operationally critical contractor. The procedures established pursuant to subsection
(a)shall include a process for— designating operationally critical contractors; and notifying a contractor that it has been designated as an operationally critical contractor. The procedures established pursuant to subsection
(a)shall require each operationally critical contractor to rapidly report to the component of the Department designated pursuant to subsection (d)(2)(A) on each cyber incident with respect to any network or information systems of such contractor. Each such report shall include the following: An assessment by the contractor of the effect of the cyber incident on the ability of the contractor to meet the contractual requirements of the Department. The technique or method used in such cyber incident. A sample of any malicious software, if discovered and isolated by the contractor, involved in such cyber incident. A summary of information compromised by such cyber incident. The procedures established pursuant to subsection
(a)shall— include mechanisms for Department personnel to, if requested, assist operationally critical contractors in detecting and mitigating penetrations; and provide that an operationally critical contractor is only required to provide access to equipment or information as described in subparagraph
(A)to determine whether information created by or for the Department in connection with any Department program was successfully exfiltrated from a network or information system of such contractor and, if so, what information was exfiltrated. The procedures established pursuant to subsection
(a)shall provide for the reasonable protection of trade secrets, commercial or financial information, and information that can be used to identify a specific person. The procedures established pursuant to subsection
(a)shall limit the dissemination of information obtained or derived through the procedures to entities— with missions that may be affected by such information; that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents; that conduct counterintelligence or law enforcement investigations; or for national security purposes, including cyber situational awareness and defense purposes. In this section: The term cyber incident means actions taken through the use of computer networks that result in an actual or potentially adverse effect on an information system or the information residing therein. The term operationally critical contractor means a contractor designated by the Secretary for purposes of this section as a critical source of supply for airlift, sealift, intermodal transportation services, or logistical support that is essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation. . The Secretary shall establish the procedures required by subsection
(b)of section 391 of title 10, United States Code, as added by subsection
(a)of this section, not later than 90 days after the date of the enactment of this Act. Not later than 90 days after the date of the enactment of the Act, the Secretary of Defense shall complete an assessment of— requirements that were in effect on the day before the date of the enactment of this Act for contractors to share information with Department components regarding cyber incidents (as defined in subsection
(d)of such section 391) with respect to networks or information systems of contractors; and Department policies and systems for sharing information on cyber incidents with respect to networks or information systems of Department contractors. Upon completion of the assessment required by paragraph (1), the Secretary shall— designate a Department component under subsection
(a)of such section 391; and issue or revise guidance applicable to Department components that ensures the rapid sharing by the component designated pursuant to such section 391 or section 941 of the National Defense Authorization Act for Fiscal Year 2013 ( 10 U.S.C. 2224 note) of information relating to cyber incidents with respect to networks or information systems of contractors with other appropriate Department components. The table of chapters at the beginning of subtitle A of title 10, United States Code, and at the beginning of part I of such subtitle, are each amended by inserting after the item relating to chapter 18 the following new item: 19. Cyber matters 391 .
Connectionstraces to 1
Citation graph
cites case law
Sec. 1632
Reporting on cyber incidents with respect to networks and information systems of operationally critical contractors
Cites 1Cited by 0 across 0 sources
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.