Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 117th Congress · S. 2902 (Introduced in Senate) — To modernize Federal information security management, and for other purposes. · Sec. 209

Sec. 209. Implementing presumption of compromise and zero trust architectures

229 words·~1 min read·/bill/117/s/2902/is/section-209·

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

Not later than 60 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director of the National Institute of Standards and Technology, shall develop recommendations to increase the internal defenses of agency systems to— limit the ability of entities that cause incidents to move laterally through or between agency systems; identify incidents more quickly; isolate and remove unauthorized entities from agency systems more quickly; implement zero trust architecture; and otherwise increase the resource costs for entities that cause incidents; and Not later than 180 days after the date on which the recommendations under subsection
(a)are completed, the Director shall issue guidance to agencies that requires the implementation of the recommendations. Not later than 60 days after the date on which the Director issues guidance under subsection (b), the head of each agency shall submit to the Director a plan to implement zero trust architecture that includes— a description of any steps the agency has completed; an identification of activities that will have the most immediate security impact; and a schedule to implement the plan. Not later than 90 days after the date on which the Director issues guidance required under subsection (b), the Director shall provide a briefing to the appropriate congressional committees on the guidance and the agency implementation plans submitted under subsection (c).
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.