Sec. 2. Definitions
416 words·~2 min read·
/bill/117/hr/8403/ih/section-2A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
In this Act: The term active defense technique means an action taken on an information system of an agency to increase the security of such system against an attacker, including— the use of a deception technology or other purposeful feeding of false or misleading information to an attacker accessing such system; and proportional action taken in response to an unlawful breach. The term agency means any Government corporation, Government-controlled corporation, or other establishment of the executive branch of the Government (including the Executive Office of the President), or any independent regulatory agency, but does not include the following:
The Government Accountability Office. The Federal Election Commission. The governments of the District of Columbia and of the territories and possessions of the United States, and their various subdivisions. Government-owned contractor-operated facilities, including laboratories engaged in national defense research and production activities. The term continuous monitoring means continuous experimentation conducted by an agency on an information system of such agency to evaluate the resilience of such system against a malicious attack or condition that could compromise such system for the purpose of improving design, resilience, or incident response with respect to such system.
The term deception technology means an isolated digital environment, system, or platform containing a replication of an active information system with realistic data flows used to attract, mislead, or observe an attacker. The term department means the following: The Department of State. The Department of the Treasury. The Department of Defense. The Department of Justice. The Department of the Interior. The Department of Agriculture. The Department of Commerce. The Department of Labor.
The Department of Health and Human Services. The Department of Housing and Urban Development. The Department of Transportation. The Department of Energy. The Department of Education. The Department of Veterans Affairs. The Department of Homeland Security. The term Director means the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security. The term information system has the meaning given the term in section 3502 of title 44, United States Code.
The term national laboratory has the meaning given the term in section 2 of the Energy Policy Act of 2005 ( 42 U.S.C. 15801 ). The terms penetration test and penetration testing mean an assessment conducted on an information system of an agency that emulates an attack or other exploitation capability to identify and test vulnerabilities that could be exploited. The term rules of engagement means a set of rules established by an agency for use during penetration testing.
Connectionstraces to 1
Traces to 1 document
U.S. Code