Sec. 1734. Assessment of effect of inconsistent timing and use of Network Address Translation in Department of Defense networks
263 words·~1 min read·
/bill/116/hr/6395/enr/section-1734·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than March 1, 2021, the Chief Information Officer of the Department of Defense shall conduct comprehensive assessments as follows: The Chief Information Officer shall characterize— timing variability across Department information technology and operational technology networks, appliances, devices, applications, and sensors that generate time-stamped data and metadata used for cybersecurity purposes; how timing variability affects current, planned, and potential capabilities for detecting network intrusions that rely on correlating events and the sequence of events; and how to harmonize standard of timing across Department networks.
The Chief Information Officer shall characterize— why and how the Department is using Network Address Translation
(NAT)and multiple layers and nesting of Network Address Translation; how using Network Address Translation affects the ability to link malicious communications detected at various network tiers to specific endpoints or hosts to enable prompt additional investigations, quarantine decisions, and remediation activities; and what steps and associated cost and schedule are necessary to eliminate the use of Network Address Translation or to otherwise provide transparency to network defenders, including options to accelerate the transition from Internet Protocol version 4 to Internet Protocol version 6. The Chief Information Officer and the Principal Cyber Advisor shall submit to the Secretary of Defense a recommendation to address the assessments conducted under subsection (a), including whether and how to revise the cyber strategy of the Department. Not later than April 1, 2021, the Chief Information Officer shall brief the congressional defense committees on the findings of the Chief Information Officer with respect to the assessments conducted under subsection
(a)and the recommendation submitted under subsection (b).