Sec. 245. INDEPENDENT REVIEW AND ASSESSMENT OF CRYPTOGRAPHIC MODERNIZATION PROGRAM
342 words·~2 min read·
/statute-compilations/comps-10045/sec-245A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
## SEC. 245 INDEPENDENT REVIEW AND ASSESSMENT OF CRYPTOGRAPHIC MODERNIZATION PROGRAM ###
(a)Independent Review and Assessment Not later than 30 days after the date of the enactment of this Act, the Secretary of Defense shall select an appropriate entity outside the Department of Defense to conduct an independent review and assessment of the cryptographic modernization program of the Department of Defense. ###
(b)Elements The review and assessment required by subsection
(a)shall include the following: ####
(1)For each military department and appropriate defense agency, an analysis of the adequacy of the program management structure for executing the cryptographic modernization program, including resources, personnel, requirements generation, and business process metrics. ####
(2)A description of the acquisition model for each military department and appropriate defense agency, including how the acquisition strategies of programs of record are synchronized with the needs of the cryptographic modernization program. ####
(3)An analysis of the current funding mechanism, the Information System Security Program, to provide adequate and stable funding to meet cryptographic modernization needs. ####
(4)An analysis of the ability of the program to deliver capabilities to the user community while complying with the budget and schedule for the program, including the programmatic risks that negatively affect such compliance. ###
(c)Report ####
(1)Report required Not later than 120 days after the date of the enactment of this Act, the entity conducting the review and assessment under subsection
(a)shall submit to the Secretary and the congressional defense committees a report containing— #####
(A)the results of the review and assessment; and #####
(B)recommendations for improving the management of the cryptographic modernization program. ####
(2)Additional evaluation required Not later than 30 days after the date on which the congressional defense committees receive the report required by paragraph (1), the Secretary shall submit to such committees an evaluation by the Secretary of the findings and recommendations contained in such report. ####
(3)Form The report required by paragraph
(1)shall be submitted in unclassified form, but may include a classified annex.