Sec. 3. Definitions
261 words·~1 min read·
/bill/117/hr/6497/ih/section-3·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
In this Act, unless otherwise specified: The term additional cybersecurity procedure has the meaning given the term in section 3552(b) of title 44, United States Code, as amended by this Act. The term agency has the meaning given the term in section 3502 of title 44, United States Code. The term appropriate congressional committees means— the Committee on Homeland Security and Governmental Affairs of the Senate; the Committee on Oversight and Reform of the House of Representatives; and the Committee on Homeland Security of the House of Representatives.
The term Director means the Director of the Office of Management and Budget. The term incident has the meaning given the term in section 3552(b) of title 44, United States Code. The term national security system has the meaning given the term in section 3552(b) of title 44, United States Code. The term penetration test has the meaning given the term in section 3552(b) of title 44, United States Code, as amended by this Act. The term threat hunting means iteratively searching systems for threats that evade detection by automated threat detection systems.
The term zero trust architecture means a security model, a set of system design principles, and a coordinated cybersecurity and system management strategy that employs continuous monitoring, risk-based access controls, or system security automation techniques to address the cybersecurity principle that threats exist both inside and outside traditional network boundaries with an assumption that a breach is inevitable or has likely already occurred, and therefore employs least-privileged access for network or system users while monitoring for anomalous or malicious activity.