Sec. 301. Cybersecurity
220 words·~1 min read·
/bill/116/hr/5470/ih/section-301·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Section 20301 of title 51, United States Code, is amended by adding at the end the following: The Administrator shall update and improve the cybersecurity of NASA space assets and supporting infrastructure. . The Administrator shall maintain a Security Operations Center, to identify and respond to cybersecurity threats to NASA information technology systems, including institutional systems and mission systems. The Administrator shall implement, to the maximum extent practicable, each of the recommendations contained in the report of the Inspector General of NASA entitled Audit of NASA’s Security Operations Center , issued on May 23, 2018.
The Administrator, in coordination with the Secretary of Homeland Security and the heads of other relevant Federal agencies, may implement a cyber threat hunt capability to proactively search NASA information systems for advanced cyber threats that otherwise evade existing security tools. In carrying out paragraph (1), the Administrator shall develop and document a threat-hunting process, including the roles and responsibilities of individuals conducting a cyber threat hunt. The Administrator shall implement, to the maximum extent practicable, the recommendations for NASA contained in the report of the Comptroller General of the United States entitled Information Security:
Agencies Need to Improve Controls over Selected High-Impact Systems , issued May 18, 2016, including— re-evaluating security control assessments; and specifying metrics for the continuous monitoring strategy of the Administration.