Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 113th Congress · H.R. 3979 (EAH) — 113 HR 3979 EAH: Carl Levin and Howard P. ‘Buck’ McKeon National Defense Authorization Act for Fiscal Year 2015 · Sec. 832

Sec. 832. Enhanced transparency and improved risk management in information technology investments

880 words·~4 min read·/bill/113/hr/3979/eah/section-832

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

Section 11302(c) of title 40, United States Code, is amended— by redesignating paragraphs
(1)and
(2)as paragraphs
(2)and (5), respectively; by inserting before paragraph (2), as so redesignated, the following new paragraph (1): In this subsection: The term covered agency means an agency listed in section 901(b)(1) or 901(b)(2) of title 31. The term major information technology investment means an investment within a covered agency information technology investment portfolio that is designated by the covered agency as major, in accordance with capital planning guidance issued by the Director. The term national security system has the meaning provided in section 3542 of title 44. ; and by inserting after paragraph (2), as so redesignated, the following new paragraphs: The Director shall make available to the public a list of each major information technology investment, without regard to whether the investments are for new information technology acquisitions or for operations and maintenance of existing information technology, including data on cost, schedule, and performance. The Director shall issue guidance to each covered agency for reporting of data required by subparagraph
(A)that provides a standardized data template that can be incorporated into existing, required data reporting formats and processes. Such guidance shall integrate the reporting process into current budget reporting that each covered agency provides to the Office of Management and Budget, to minimize additional workload. Such guidance shall also clearly specify that the investment evaluation required under subparagraph
(C)adequately reflect the investment’s cost and schedule performance and employ incremental development approaches in appropriate cases. The Chief Information Officer of each covered agency shall provide the Director with the information described in subparagraph
(A)on at least a semi-annual basis for each major information technology investment, using existing data systems and processes. For each major information technology investment listed under subparagraph (A), the Chief Information Officer of the covered agency, in consultation with other appropriate agency officials, shall categorize the investment according to risk, in accordance with guidance issued by the Director. If either the Director or the Chief Information Officer of a covered agency determines that the information made available from the agency’s existing data systems and processes as required by subparagraph
(B)is not timely and reliable, the Chief Information Officer, in consultation with the Director and the head of the agency, shall establish a program for the improvement of such data systems and processes. The applicability of subparagraph
(A)may be waived or the extent of the information may be limited by the Director, if the Director determines that such a waiver or limitation is in the national security interests of the United States. The requirements of subparagraph
(A)shall not apply to national security systems or to telecommunications or information technology that is fully funded by amounts made available— under the National Intelligence Program, defined by section 3(6) of the National Security Act of 1947 ( 50 U.S.C. 3003(6) ); under the Military Intelligence Program or any successor program or programs; or jointly under the National Intelligence Program and the Military Intelligence Program (or any successor program or programs). For each major information technology investment listed under paragraph (3)(A) that receives a high risk rating, as described in paragraph (3)(C), for 4 consecutive quarters— the Chief Information Officer of the covered agency and the program manager of the investment within the covered agency, in consultation with the Administrator of the Office of Electronic Government, shall conduct a review of the investment that shall identify— the root causes of the high level of risk of the investment; the extent to which these causes can be addressed; and the probability of future success; the Administrator of the Office of Electronic Government shall communicate the results of the review under subparagraph
(A)to— the Committee on Homeland Security and Governmental Affairs and the Committee on Appropriations of the Senate; the Committee on Oversight and Government Reform and the Committee on Appropriations of the House of Representatives; and the committees of the Senate and the House of Representatives with primary jurisdiction over the agency; in the case of a major information technology investment of the Department of Defense, the assessment required by subparagraph
(A)may be accomplished in accordance with section 2445c of title 10, provided that the results of the review are provided to the Administrator of the Office of Electronic Government upon request and to the committees identified in subsection (B); and for a covered agency other than the Department of Defense, if on the date that is one year after the date of completion of the review required under subsection (A), the investment is rated as high risk under paragraph (3)(C), the Director shall deny any request for additional development, modernization, or enhancement funding for the investment until the date on which the Chief Information Officer of the covered agency determines that the root causes of the high level of risk of the investment have been addressed, and there is sufficient capability to deliver the remaining planned increments within the planned cost and schedule. Paragraphs (1), (3), and
(4)shall not be in effect on and after the date that is 5 years after the date of the enactment of the Carl Levin and Howard P. ‘Buck’ McKeon National Defense Authorization Act for Fiscal Year 2015. .
Connectionstraces to 1
Traces to 1 document
Citation graph
cites case law
Sec. 832
Enhanced transparency and improved risk management in information technology investments
Cites 1Cited by 0 across 0 sources
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.