Sec. 1637. Evaluation of cyber vulnerabilities of Department of Defense critical infrastructure
350 words·~2 min read·
/bill/114/s/2943/pcs/section-1637A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
The Secretary of Defense shall, in accordance with the plan under subsection (b), complete an evaluation of the cyber vulnerabilities of Department of Defense critical infrastructure by not later than December 31, 2020. Not later than 180 days after the date of the enactment of this Act, the Secretary shall submit to the congressional defense committees the plan of the Secretary for the evaluation of Department of Defense critical infrastructure under subsection (a), including an identification of each of the facilities and locations to be evaluated and an estimate of the funding required to conduct the evaluation. The plan under paragraph
(1)shall accord a priority among evaluations based on the criticality of supporting infrastructure, as determined by the Chairman of the Joint Chiefs of Staff based on an assessment of employment of forces and threats. The plan under paragraph
(1)shall build upon existing efforts regarding the identification and mitigation of cyber vulnerabilities of major weapon systems and Department of Defense critical infrastructure, and shall not duplicate similar ongoing efforts. The Secretary shall inform the congressional defense committees of the activities undertaken in the evaluation of Department of Defense critical infrastructure under this section as part of the quarterly cyber operations briefings under section 484 of title 10, United States Code. As part of the evaluation of cyber vulnerabilities of Department of Defense critical infrastructure, the Secretary shall develop strategies for mitigating the risks of cyber vulnerabilities identified in the course of the evaluation. The Secretary may— develop tools that improve assessments of cyber vulnerabilities of Department of Defense critical infrastructure; conduct non-recurring engineering for the design of mitigation solutions for such vulnerabilities; and establish Department-wide information repositories to share findings relating to such assessments and to share such mitigation solutions. In this section, the term Department of Defense critical infrastructure means any asset of the Department of Defense of such extraordinary importance to the functioning of the Department and the operation of the military that its incapacitation or destruction from a cyber attack would have a debilitating effect on the ability of the Department to fulfill its missions.