Pub. L. 111-84, div. A, tit. IX, subtit. D, sec. 931
IMPLEMENTATION STRATEGY FOR DEVELOPING LEAP-AHEAD CYBER OPERATIONS CAPABILITIES.
SEC. 931. IMPLEMENTATION STRATEGY FOR DEVELOPING LEAP-AHEAD CYBER OPERATIONS CAPABILITIES.(a) Strategy Report Required.—Not later than March 1, 2010, the Under Secretary of Defense for Acquisition, Technology, and Logistics shall submit to the congressional defense committees a report on a strategy for organizing the research and development bodies of the Department of Defense to develop leap-ahead cyber operations capabilities.123 STAT. 2433(b) Elements.—The report required by subsection (a) shall address the following:(1) A description of the management structure and investment review process for coordinating the technology development of advanced offensive and defensive cyber operations capabilities—(A) among the military departments, the Defense Agencies, the combatant commands, and the intelligence community;(B) across all levels of classification, including relevant special access programs; and(C) based on the identification and prioritization of joint cyber operations capabilities gaps.(2) Actions taken and recommendations for further improving the coordination of research and development of offensive and defensive cyber operations capabilities among private sector, interagency, non-governmental, and international partners.(3) Assessment of the feasibility and utility of regular national level, joint, interagency cyber exercises that would include, to the extent possible, participants from industry, international militaries, and non-governmental organizations to assess technologies, policies, and capabilities.(c) Coordination.—The report required by subsection (a) shall be developed in coordination and concurrence with the Vice Chairman of the Joint Chiefs of Staff, the Under Secretary of Defense for Intelligence, the Under Secretary of Defense for Policy, the Assistant Secretary of Defense for Networks and Information Integration, the Director of the National Security Agency, and the commander of the United States Cyber Command.(d) Form.—The report required by subsection (a) shall be submitted in unclassified form, but may include a classified annex.(e) Cyber Operations Capabilities Defined.—The term “cyber operations capabilities” means the range of capabilities needed for computer network defense, computer network attack, and computer network exploitations. Such term includes technical as well as non-materiel solutions.