Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 117th Congress · S. 2902 (Introduced in Senate) — To modernize Federal information security management, and for other purposes. · Sec. 201

Sec. 201. Evaluation of effectiveness of standards

287 words·~1 min read·/bill/117/s/2902/is/section-201

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

As a component of the evaluation and report required under section 3555(h) of title 44, United States Code, and not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall perform a study that— assesses the standards promulgated under section 11331(b) of title 40, United States Code to determine the degree to which agencies use the authority under section 11331(c)(1) of title 40, United States Code to customize the standards relative to the risks facing each agency and agency system; assesses the effectiveness of the standards described in paragraph (1), including any standards customized by agencies under section 11331(c)(1) of title 40, United States Code, at improving agency cybersecurity; examines the quantification of cybersecurity risk in the private sector for any applicability for use by the Federal Government; examines cybersecurity metrics existing as of the date of enactment of this Act used by the Director, the Director of the Cybersecurity and Infrastructure Security Agency, and the heads of other agencies to evaluate the effectiveness of information security policies and practices; and with respect to the standards described in paragraph (1), provides recommendations for— the addition or removal of standards; or the customization of— the standards by agencies under section 11331(c)(1) of title 40, United States Code; or specific controls within the standards.
The Director shall incorporate the results of the study performed under subsection
(a)into the review of standards required under section 11331(e) of title 40, United States Code. Not later than 30 days after the date on which the study performed under subsection
(a)is completed, the Comptroller General of the United States shall provide to the appropriate congressional committees a briefing on the study.
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.