Sec. 1734. ASSESSMENT OF EFFECT OF INCONSISTENT TIMING AND USE OF NETWORK ADDRESS TRANSLATION IN DEPARTMENT OF DEFENSE NETWORKS
319 words·~1 min read·
/statute-compilations/comps-16736/sec-1734A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
## SEC. 1734 ASSESSMENT OF EFFECT OF INCONSISTENT TIMING AND USE OF NETWORK ADDRESS TRANSLATION IN DEPARTMENT OF DEFENSE NETWORKS ###
(a)In General Not later than March 1, 2021, the Chief Information Officer of the Department of Defense shall conduct comprehensive assessments as follows: ####
(1)Timing variability in department networks The Chief Information Officer shall characterize— #####
(A)timing variability across Department information technology and operational technology networks, appliances, devices, applications, and sensors that generate time-stamped data and metadata used for cybersecurity purposes; #####
(B)how timing variability affects current, planned, and potential capabilities for detecting network intrusions that rely on correlating events and the sequence of events; and #####
(C)how to harmonize standard of timing across Department networks. ####
(2)Use of network address translation The Chief Information Officer shall characterize— #####
(A)why and how the Department is using Network Address Translation
(NAT)and multiple layers and nesting of Network Address Translation; #####
(B)how using Network Address Translation affects the ability to link malicious communications detected at various network tiers to specific endpoints or hosts to enable prompt additional investigations, quarantine decisions, and remediation activities; and #####
(C)what steps and associated cost and schedule are necessary to eliminate the use of Network Address Translation or to otherwise provide transparency to network defenders, including options to accelerate the transition from Internet Protocol version 4 to Internet Protocol version 6. ###
(b)Recommendation The Chief Information Officer and the Principal Cyber Advisor shall submit to the Secretary of Defense a recommendation to address the assessments conducted under subsection (a), including whether and how to revise the cyber strategy of the Department. ###
(c)Briefing Not later than April 1, 2021, the Chief Information Officer shall brief the congressional defense committees on the findings of the Chief Information Officer with respect to the assessments conducted under subsection
(a)and the recommendation submitted under subsection (b).