Sec. 6309. Enforcement of cybersecurity requirements for national security systems
425 words·~2 min read·
/bill/117/hr/7776/eah/section-6309·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
In this section: The term cybersecurity requirements for national security systems means the minimum cybersecurity requirements established by the National Manager, consistent with the direction of the President and in consultation with the Director of National Intelligence, that applies to all national security systems operated by, on the behalf of, or administered by the head of an element of the intelligence community. The term National Manager means the National Manager for National Security Systems designated by the President.
The term national security systems includes— national security systems (as defined in section 3552(b) of title 44, United States Code); and information systems described in paragraph
(2)or
(3)of section 3553(e) of such title. The cybersecurity requirements for national security systems shall include appropriate deadlines by which all elements of the intelligence community shall have fully implemented the requirements. Not less frequently than once every 2 years, the National Manager shall reevaluate and update the cybersecurity requirements for national security systems. Each head of an element of the intelligence community that owns or operates a national security system shall update plans of the element to prioritize resources in such a manner as to fully implement the cybersecurity requirements for national security systems by the deadline established pursuant to subsection
(b)for the next 10 fiscal years. The head of an element of the intelligence community may exempt a national security system owned or operated by the element from the cybersecurity requirements for national security systems if done so in accordance with the procedures established under paragraph (2). The National Manager shall, consistent with the direction of the President, establish procedures that govern— the circumstances under which the head of an element of the intelligence community may exempt a national security system under paragraph (1); and the process for implementing the exemption. Each year, the National Manager and the Director of National Intelligence shall— submit to the congressional intelligence committees an annual report documenting all exemptions made under paragraph
(1)during the period covered by the report, along with the justifications for the exemptions; and in the case of an exemption made by the Assistant Secretary of State for Intelligence and Research under such paragraph, submit to the Committee on Foreign Relations of the Senate and the Committee on Foreign Affairs of the House of Representatives a separate report describing the exemption and the justification for it. Each report submitted under subparagraph
(A)shall be submitted with such classification as the Director considers appropriate and with due regard for the protection of sensitive intelligence sources and methods.