Sec. 1626. Reporting requirements for cross domain compromises and exemptions to policies for information technology
220 words·~1 min read·
/bill/116/hr/6395/eh/section-1626·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Effective beginning in October 2020, the Secretary of Defense and the secretaries of the military services shall submit to the congressional defense committees a monthly report in writing that documents each instance or indication of a cross-domain compromise within the Department of Defense. The Secretary of Defense shall submit to the congressional defense committees procedures for complying with the requirements of subsection
(a)consistent with the national security of the United States and the protection of operational integrity. The Secretary shall promptly notify such committees in writing of any changes to such procedures at least 14 days prior to the adoption of any such changes. In this subsection, the term cross domain compromise means any unauthorized connection between software, hardware, or both designed for use on a network or system built for classified data and the public internet. Not later than 6 months after the date of the enactment of this Act and biannually thereafter, the Secretary of Defense and the secretaries of the military services shall submit to the congressional defense committees a report in writing that enumerates and details each current exemption to information technology policy, interim Authority To Operate
(ATO)order, or both. Each such report shall include other relevant information pertaining to each such exemption, including relating to the following: Risk categorization. Duration. Estimated time remaining.