Sec. 1504. Support for cyber threat tabletop exercise program with the defense industrial base
515 words·~2 min read·
/bill/118/hr/5009/eah/section-1504·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than one year after the date of the enactment of this Act, the Secretary of Defense, acting through the Assistant Secretary of Defense for Cyber Policy, shall establish a program (to be known as the Cyber Threat Tabletop Exercise Program ) to prepare the Department of Defense and the defense industrial base for cyber attacks preceding or during times of conflict or wars through the use of tabletop exercises. In carrying out the program, the Secretary of Defense, acting through the Assistant Secretary of Defense for Cyber Policy, shall consult and coordinate with the following:
The Chief Information Officer of the Department of Defense. The Under Secretary of Defense for Acquisition and Sustainment. The Commander of the United States Cyber Command. The Commander of the United States Northern Command. The Commander of the Army Interagency Training and Education Center. The Director of the Defense Cyber Crime Center. Such other individuals and entities as the Assistant Secretary of Defense for Cyber Policy determines appropriate. The Assistant Secretary of Defense for Cyber Policy may solicit such individuals and entities in the Department of Defense and the defense industrial base as the Assistant Secretary determines appropriate to participate in the program. — The program shall consist of the following:
A series of tabletop exercises that simulate cyber attack scenarios affecting the defense industrial base, which the Assistant Secretary of Defense for Cyber Policy shall carry out on a biannual basis beginning not later than one year after the date of the enactment of this Act until December 30, 2030, and in which the Department of Defense and entities in the defense industrial base shall participate. A series of tabletop exercises for use by individual entities or collections of entities in the defense industrial base that simulate cyber attack scenarios affecting the defense industrial base and which are designed to test and improve the responses and plans of such entities to such scenarios.
The Assistant Secretary of Defense for Cyber Policy shall develop and update the tabletop exercises described in subparagraph (A). The Assistant Secretary of Defense for Cyber Policy shall ensure that the cyber attacks simulated by the tabletop exercises described in subparagraph
(A)are based on the cyber attack capabilities and activities of current and potential adversaries of the United States. Not later than one year after the date of the enactment of this Act, the Assistant Secretary of Defense for Cyber Policy shall establish procedures to— identify vulnerabilities in the cybersecurity of the Department of Defense and the defense industrial base pursuant to the tabletop exercises carried out under the program; and identify other lessons learned that can improve national security or the quality of such tabletop exercises. Not later than September 30, 2025, and annually thereafter until the October 1, 2029, the Secretary of Defense, acting through the Assistant Secretary of Defense for Cyber Policy, shall submit to the congressional defense committees a report describing the activities of the Department of Defense pursuant to this section during the preceding year. In this section, the term program means the program established under subsection (a).