Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 117th Congress · S. 1605 (EAH) — 117 S1605 EAH: National Defense Authorization Act for Fiscal Year 2022 · Sec. 1511

Sec. 1511. Comparative analysis of cybersecurity capabilities

494 words·~2 min read·/bill/117/s/1605/eah/section-1511·

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

Not later than 180 days after the date of the enactment of this Act, the Chief Information Officer and the Director of Cost Assessment and Program Evaluation
(CAPE)of the Department of Defense, in consultation with the Principal Cyber Advisor to the Secretary of Defense and the Chief Information Officers of each of the military departments, shall jointly sponsor a comparative analysis, to be conducted by the Director of the National Security Agency and the Director of the Defense Information Systems Agency, of the following: The cybersecurity tools, applications, and capabilities offered as options on enterprise software agreements for cloud-based productivity and collaboration suites, such as is offered under the Defense Enterprise Office Solution and Enterprise Software Agreement contracts with Department of Defense components, relative to the cybersecurity tools, applications, and capabilities that are currently deployed in, or required by, the Department to conduct— asset discovery; vulnerability scanning; conditional access (also known as comply-to-connect ); event correlation; patch management and remediation; endpoint query and control; endpoint detection and response; data rights management; data loss prevention; data tagging; data encryption; security information and event management; and security orchestration, automation, and response. The identity, credential, and access management
(ICAM)system, and associated capabilities to enforce the principle of least privilege access, offered as an existing option on an enterprise software agreement described in paragraph (1), relative to— the requirements of such system described in the Zero Trust Reference Architecture of the Department; and the requirements of such system under development by the Defense Information Systems Agency. The artificial intelligence and machine-learning capabilities associated with the tools, applications, and capabilities described in paragraphs
(1)and (2), and the ability to host Government or third-party artificial intelligence and machine-learning algorithms pursuant to contracts referred to in paragraph
(1)for such tools, applications, and capabilities. The network consolidation and segmentation capabilities offered on the enterprise software agreements described in paragraph
(1)relative to capabilities projected in the Zero Trust Reference Architecture. The automated orchestration and interoperability among the tools, applications, and capabilities described in paragraphs
(1)through (4). The comparative analysis conducted under subsection
(a)shall include an assessment of the following: Costs. Performance. Sustainment. Scalability. Training requirements. Maturity. Human effort requirements. Speed of integrated operations. Ability to operate on multiple operating systems and in multiple cloud environments. Such other matters as the Chief Information Officer and the Director of Cost Assessment and Program Evaluation consider appropriate. Not later than 30 days after the date on which the comparative analysis required under subsection
(a)is completed, the Chief Information Officer and the Director of Cost Assessment and Program Evaluation
(CAPE)of the Department of Defense shall jointly provide the congressional defense committees with a briefing on the findings of the Chief Information Officer and the Director with respect to such analysis, together with such recommendations for legislative or administrative action as the Chief Information Officer and the Director may have with respect to the matters covered by such analysis.
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.