Sec. 942. Joint software assurance center for the Department of Defense
304 words·~1 min read·
/bill/113/s/1197/pcs/section-942·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
The Secretary of Defense shall provide for the establishment of a joint software assurance center for the Department of Defense (in this section referred to as the center ). The purpose of the center shall be to serve as a joint, Department-wide resource for efforts of the Department to ensure security in the software developed, acquired, maintained, and used by the Department. In providing for the establishment of the center, the Secretary shall consider whether the purpose of the center can be met by an existing software assurance center in the Department.
Not later than 180 days after the date of the enactment of this Act, the Secretary shall issue a charter for the center. The charter shall set forth the following: The role of the center in supporting program offices in implementing the supply chain risk management strategy of the Department. The software assurance expertise and capabilities of the center, including policies, standards, requirements, best practices, contracting, training, testing, and code analysis and remediation.
Requirements for the discharge by the center, in coordination with the Center for Assured Software of the National Security Agency, of a program of research and development to improve automated software code vulnerability analysis and testing tools. Requirements for the center to procure, manage, and distribute enterprise licenses for automated software vulnerability analysis tools. The Secretary shall submit to the congressional defense committees, at the time of the submittal to Congress of the budget of the President for fiscal year 2016 (as submitted pursuant to section 1105 of title 31, United States Code), a report on the funding and management of the center.
The report shall set forth such recommendations as the Secretary considers appropriate regarding the optimal placement of the center within the organizational structure of the Department, including responsibility for the funding and management of the center.