Sec. 1004. Management of Defense information technology systems
1,179 words·~5 min read·
/bill/113/hr/4435/eh/section-1004·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Section 2222 of title 10, United States Code, is amended to read as follows: Funds available to the Department of Defense, whether appropriated or non-appropriated, may not be obligated for a defense information technology system program that will have a total cost in excess of $1,000,000 over the period of the current future-years defense program submitted to Congress under section 221 of this title unless— the appropriate pre-certification authority for the covered defense information technology system program has determined that— the defense information technology system program is in compliance with the enterprise architecture developed under subsection
(b)and appropriate business process re-engineering efforts have been undertaken to ensure that— the business process supported by the defense information technology system program is or will be as streamlined and efficient as practicable; and the need to tailor commercial-off-the-shelf systems to meet unique requirements or incorporate unique requirements or incorporate unique interfaces has been eliminated or reduced to the maximum extent practicable; the defense information technology system program is necessary to achieve a critical national security capability or address a critical requirement in an area such as safety or security; or the defense information technology system program is necessary to prevent a significant adverse effect on a project that is needed to achieve an essential capability, taking into consideration the alternative solutions for preventing such adverse effect; and the covered defense information technology system program has been reviewed and certified by the investment review board established under subsection (e). The Secretary of Defense shall develop an enterprise architecture, known as the joint information technology enterprise architecture, to cover all defense information technology systems, and the functions and activities supported by defense information technology systems, which shall be sufficiently defined to effectively guide, constrain, and permit implementation of interoperable defense information technology system solutions and consistent with the policies and procedures established by the Director of the Office of Management and Budget. The Secretary of Defense shall delegate responsibility and accountability for the defense information technology enterprise architecture content, including unambiguous definitions of functional processes, business rules, and standards, as follows: For the warfighting mission area, the Joint Staff shall be responsible and accountable for the content of those portions of the defense information systems enterprise architecture. For the business systems mission area, the Deputy Chief Management Officer of the Department of Defense shall be responsible and accountable for the content of those portions of the defense information technology enterprise architecture. For the Enterprise Information environment mission area, the Chief Information Officer of the Department of Defense shall be responsible and accountable for the content of those portions of the defense information technology enterprise architecture. The defense information technology enterprise architecture developed under subsection (b)(1)(A) shall include the following: An information infrastructure that, at a minimum, would enable the Department of Defense to comply with all applicable law. Policies, procedures, data standards, performance measures, and system interface requirements that are to apply uniformly throughout the Department of Defense. A target defense information technology systems computing environment, compliant with the defense information technology enterprise architecture, as determined by the Chief Information Officer of the Department of Defense. For purposes of subsections
(a)and (e), the appropriate pre-certification authority for a defense information technology system program is as follows: In the case of an Army program, the Secretary of the Army. In the case of a Navy program, the Secretary of the Navy. In the case of an Air Force program, the Secretary of the Air Force. In the case of a program of a Defense Agency, the Director, or equivalent, of such Defense Agency, unless otherwise approved by the Secretary of Defense. In the case of a program that will support the business processes of more than one military department or Defense Agency, an appropriate pre-certification authority designated by the Secretary of Defense. The Secretary of Defense shall establish an investment review board and investment management process to review and certify the planning, design, acquisition, development, deployment, operation, maintenance, modernization, and project cost benefits and risks of covered defense information technology systems programs. The investment review board and investment management process so established shall specifically address the requirements of subsection (a). The review of defense information technology systems programs under the investment management process shall include the following: Review and approval by an investment review board of each covered defense information technology system program before the obligation of funds on the system in accordance with the requirements of subsection (a). Periodic review of all covered defense information technology system programs, grouped in mission areas. Representation on each investment review board by appropriate officials from among the Office of the Secretary of Defense, the armed forces, the combatant commands, the Joint Chiefs of Staff, and the Defense Agencies, including representation from each of the following: The appropriate pre-certification authority for the defense information technology system under review. The appropriate senior official of the Department of Defense for the functions and activities supported by the defense information technology system under review. The Chief Information Officer of the Department of Defense. Use of threshold criteria to ensure an appropriate level of review within the Department of Defense of, and accountability for, defense information technology system programs depending on scope, complexity, and cost. Use of procedures for making certifications in accordance with the requirements of subsection (a). In the materials that the Secretary submits to Congress in support of the budget submitted to Congress under section 1105 of title 31 for fiscal year 2015 and fiscal years thereafter, the Secretary of Defense shall include the following information: Identification of each defense information technology system program for which funding is proposed in that budget. Identification of all funds, by appropriation, proposed in that budget for each such program, including— funds for current services (to operate and maintain the system covered by such program); and funds for information technology systems modernization, identified for each specific appropriation. For each such program, identification of the appropriate pre-certification authority and senior official of the Department of Defense designated under subsection (d). For each such program, a description of each approval made under subsection (a)(3) with regard to such program, including— specific milestones and actual performance against specified performance measures, and any revision of such milestones and performance measures; and specific actions on the defense information technology system programs submitted for certification under such subsection. Identification of any covered defense information technology system program during the preceding fiscal year that was not approved under subsection (a), and the reasons for the lack of approval. In this section: The term enterprise architecture has the meaning given that term in section 3601(4) of title 44. The terms information system and information technology have the meanings given those terms in section 11101 of title 40. The term national security system has the meaning given that term in section 3542(b)(2) of title 44. . The item relating to section 2222 in the table of chapters at the beginning of chapter 131 of such title is amended to read as follows: 2222. Management of Defense information technology systems. .