Sec. 104. Amendments to subtitle III of title 40
782 words·~4 min read·
/bill/117/s/3600/es/section-104A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Subtitle G of title X of Division A of the National Defense Authorization Act for Fiscal Year 2018 ( 40 U.S.C. 11301 note) is amended in section 1078— by striking subsection
(a)and inserting the following: In this section: The term agency has the meaning given the term in section 551 of title 5, United States Code. The term high value asset has the meaning given the term in section 3552 of title 44, United States Code. ; in subsection (b), by adding at the end the following: The Director shall— give consideration for the use of amounts in the Fund to improve the security of high value assets; and require that any proposal for the use of amounts in the Fund includes a cybersecurity plan, including a supply chain risk management plan, to be reviewed by the member of the Technology Modernization Board described in subsection (c)(5)(C). ; and in subsection (c)— in paragraph (2)(A)(i), by inserting , including a consideration of the impact on high value assets after operational risks ; in paragraph (5)— in subparagraph (A), by striking and at the end; in subparagraph (B), by striking the period at the end and inserting and ; and by adding at the end the following: a senior official from the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, appointed by the Director. ; and in paragraph (6)(A), by striking shall be— and all that follows through 4 employees and inserting shall be 4 employees . Subchapter I of chapter 113 of subtitle III of title 40, United States Code, is amended— in section 11302— in subsection (b), by striking use, security, and disposal of and inserting use, and disposal of, and, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director, promote and improve the security of, ; in subsection (c)— in paragraph (3)— in subparagraph (A)— by striking including data and inserting which shall— include data ; and by adding at the end the following: specifically denote cybersecurity funding under the risk-based cyber budget model developed pursuant to section 3553(a)(7) of title 44. ; and in subparagraph (B), by adding at the end the following: The Director shall provide to the National Cyber Director any cybersecurity funding information described in subparagraph (A)(ii) that is provided to the Director under clause
(ii)of this subparagraph. ; in subsection (f)— by striking heads of executive agencies to develop and inserting “heads of executive agencies to— develop ; in paragraph (1), as so designated, by striking the period at the end and inserting ; and ; and by adding at the end the following: consult with the Director of the Cybersecurity and Infrastructure Security Agency for the development and use of supply chain security best practices. ; and in subsection (h), by inserting , including cybersecurity performances, after the performances ; and in section 11303(b)— in paragraph (2)(B)— in clause (i), by striking or at the end; in clause (ii), by adding or at the end; and by adding at the end the following: whether the function should be performed by a shared service offered by another executive agency; ; and in paragraph (5)(B)(i), by inserting , while taking into account the risk-based cyber budget model developed pursuant to section 3553(a)(7) of title 44 after title 31 . Subchapter II of chapter 113 of subtitle III of title 40, United States Code, is amended— in section 11312(a), by inserting , including security risks after managing the risks ; in section 11313(1), by striking efficiency and effectiveness and inserting efficiency, security, and effectiveness ; in section 11315, by adding at the end the following: The Chief Information Officer or an equivalent official of a component agency shall report to— the Chief Information Officer designated under section 3506(a)(2) of title 44 or an equivalent official of the agency of which the component agency is a component; and the head of the component agency. On annual basis, the Director may exempt any agency from the reporting structure requirements under subsection (d). On an annual basis, the Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives a report that includes a list of each exemption granted under paragraph
(1)and the associated rationale for each exemption. The report required under paragraph
(2)may be incorporated into any other annual report required under chapter 35 of title 44, United States Code. ; in section 11317, by inserting security, before or schedule ; and in section 11319(b)(1), in the paragraph heading, by striking and inserting CIOS . Chief Information Officers
Connectionstraces to 1
Traces to 1 document
U.S. Code
Citation graph
cites case law
Sec. 104
Amendments to subtitle III of title 40
Cites 1Cited by 0 across 0 sources