Sec. 1631. Report on synchronization of efforts relating to cybersecurity in the Defense Industrial Base
348 words·~2 min read·
/bill/116/hr/2500/rh/section-1631·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than May 1, 2020, the Secretary of Defense shall submit to the congressional defense committees a report on efforts, and roles and responsibilities, relating to cybersecurity in the Defense Industrial Base. The report under subsection
(a)shall include the following: Definitions for Controlled Unclassified Information
(CUI)and For Official Use Only (FOUO), as well as policies regarding protecting information designated as such. A comprehensive list of Department of Defense programs to assist the Defense Industrial Base with cybersecurity compliance requirements of the Department. An evaluation of the resources and utilization of Department programs to assist the Defense Industrial Base in complying with cybersecurity compliance requirements referred to in paragraph (2). Optimal levels of resourcing required for activities, programs, and other Department efforts to assess and monitor compliance by the Defense Industrial Base with such cybersecurity compliance requirements. Roles and responsibilities of the Under Secretary of Defense for Acquisition and Sustainment, the Chief Information Officer, the Chief Management Officer, the Director of the Protecting Critical Technologies Task Force, and the Secretaries of the military services relating to the following: Establishing and ensuring compliance with cybersecurity standards, regulations, and policies. Deconflicting existing cybersecurity standards, regulations, and policies. Coordinating with and providing assistance to the Defense Industrial Base for cybersecurity matters, particularly such relates to the issues described in paragraphs (2), (3), and (8). Efforts to enhance the Department’s visibility into its entire supply chain without violating privity. An evaluation of methodologies to tier cybersecurity requirements for the Defense Industrial Base relative to risk. Efforts to support and enhance threat information sharing between the Department and the Defense Industrial Base. An evaluation of a single Sector Coordinating Council for the Defense Industrial Base. An explanation of the Department’s Protecting Critical Technologies Task Force efforts, and how its work will be incorporated into existing Department efforts. Any other information the Secretary of Defense determines relevant. In this section, the term Defense Industrial Base includes traditional and non-traditional defense contractors and academic institutions with contractual relationships with the Department of Defense related to activities involving information or technology requiring cybersecurity compliance.