Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 114th Congress · S. 1869 (Introduced in Senate) — To improve Federal network security and authorize and enhance an existing intrusion detection and prevention system f... · Sec. 5

Sec. 5. Federal cybersecurity best practices

256 words·~1 min read·/bill/114/s/1869/is/section-5·

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

The Secretary, in consultation with the Director, shall regularly assess and require implementation of best practices for securing agency information systems against intrusion and preventing data exfiltration in the event of an intrusion. Except as provided in paragraph (2), not later than 1 year after the date of enactment of this Act, the head of each agency shall— identify sensitive and mission critical data stored by the agency consistent with the inventory required under the first subsection
(c)(relating to the inventory of major information systems) and the second subsection
(c)(relating to the inventory of information systems) of section 3505 of title 44, United States Code; assess access controls to the data described in subparagraph (A), the need for readily accessible storage of the data, and individuals' need to access the data; encrypt the data described in subparagraph
(A)that is stored on or transiting agency information systems consistent with standards and guidelines promulgated under section 11331 of title 40, United States Code; implement a single sign-on trusted identity platform for individuals accessing each public website of the agency that requires user authentication, as developed by the Administrator of General Services in collaboration with the Secretary; and implement multi-factor authentication consistent with standards and guidelines promulgated under section 11331 of title 40, United States Code, for— remote access to an agency information system; and each user account with elevated privileges on an agency information system. The requirements under paragraph
(1)shall not apply to the Department of Defense or an element of the intelligence community.
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.