Sec. 1623. Defense industrial base cybersecurity sensor architecture plan
313 words·~1 min read·
/bill/116/hr/6395/eas/section-1623·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than February 1, 2021, the Principal Cyber Advisor of the Department of Defense, in consultation with the Chief Information Officer of the Department, the Under Secretary of Defense for Acquisition and Sustainment, the Under Secretary of Defense for Intelligence and Security, and the Commander of United States Cyber Command, shall develop a comprehensive plan for the deployment of commercial-off-the-shelf solutions on supplier networks to monitor the public-facing Internet attack surface in the defense industrial base. The plan required by subsection
(a)shall include the following: Definition of an architecture, concept of operations, and governance structure that— will allow for the instrumentation and collection of cybersecurity data on the public-facing Internet attack surfaces of defense industrial base contractors in a manner that is compatible with the Department’s existing or future capabilities for analysis, and instrumentation and collection, as appropriate, of cybersecurity data within the Department of Defense Information Network; includes the expected scale, schedule, and guiding principles of deployment; is consistent with the defense industrial base cybersecurity policies and programs of the Under Secretary of Defense for Acquisition and Sustainment and the Chief Information Officer; and includes an acquisition strategy for sensor capabilities that optimizes required capability, scalability, cost, and intelligence and cybersecurity requirements. Roles and responsibilities of the persons referred to in subsection
(a)in implementing and executing the plan. In developing the plan required by subsection (a), the Principal Cyber Advisor shall ensure that extensive consultation with representative companies of the defense industrial base occurs so as to ensure that prospective participants in the defense industrial base understand and agree that emerging solutions are acceptable, practical, and effective. Not later than March 1, 2021, the Principal Cyber Advisor shall provide a briefing to the Committee on Armed Services of the Senate and the Committee on Armed Services of the House of Representatives on the plan developed pursuant to subsection (a).