Sec. 1534. Standardization of authority to operate applications in the Department of Defense
327 words·~1 min read·
/bill/117/hr/7900/pcs/section-1534A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than 270 days after the date of the enactment of this Act, the Chief Information Officer of the Department of Defense shall establish a policy with criteria for the reciprocity of authority to operate for software and hardware between all networks of the Department of Defense. The policy under paragraph
(1)shall contain the following: Procedures for requesting an authority to operate that applies to all networks of the Department. Guidance on when authorizing officials should grant an information technology platform that has already received an authority to operate on another network of the Federal Government a reciprocal authority to operate on a network of the Department of Defense. A standardized format for documentation to support the evaluation of a request for an authority to operate. Not later than one year after the date of the enactment of this Act, the Chief Information Officer shall implement a single software tool or platform for the submission and review of requests for an authority to operate applications. The tool or platform shall— be used by all authorizing officials of the Department for the receipt, review, and adjudication of all such requests; and authorize persons who submit such requests to see the progress of the request at all steps in the review process. Not later than one year after the date of the enactment of this Act, the Chief Information Officer shall submit to the congressional defense committees a report on the following: The operational status of the software tool or platform implemented under subsection (b). A list of all networks and authorizing officials of the Department that are using the software tool or platform. A list of all networks and authorizing officials of the Department that are not using the software tool or platform. In this section, the term authority to operate means the official management decision given by a senior organizational official to authorize operation of an information system and accept the risk to organizational operations.