Pub. L. 112-239, div. A, tit. IX, subtit. D, sec. 941
REPORTS TO DEPARTMENT OF DEFENSE ON PENETRATIONS OF NETWORKS AND INFORMATION SYSTEMS OF CERTAIN CONTRACTORS.
SEC. 941. REPORTS TO DEPARTMENT OF DEFENSE ON PENETRATIONS OF NETWORKS AND INFORMATION SYSTEMS OF CERTAIN CONTRACTORS.(a) Procedures for Reporting Penetrations.—The Secretary of Defense shall establish procedures that require each cleared defense contractor to report to a component of the Department of Defense designated by the Secretary for purposes of such procedures when a network or information system of such contractor that meets the criteria established pursuant to subsection (b) is successfully penetrated.(b) Networks and Information Systems Subject to Reporting.—126 STAT. 1890(1) Criteria.—The Secretary of Defense shall designate a senior official to, in consultation with the officials specified in paragraph (2), establish criteria for covered networks to be subject to the procedures for reporting system penetrations under subsection (a).(2) Officials.—The officials specified in this subsection are the following:(A) The Under Secretary of Defense for Policy.(B) The Under Secretary of Defense for Acquisition, Technology, and Logistics.(C) The Under Secretary of Defense for Intelligence.(D) The Chief Information Officer of the Department of Defense.(E) The Commander of the United States Cyber Command.(c) Procedure Requirements.—(1) Rapid reporting.—The procedures established pursuant to subsection (a) shall require each cleared defense contractor to rapidly report to a component of the Department of Defense designated pursuant to subsection (a) of each successful penetration of the network or information systems of such contractor that meet the criteria established pursuant to subsection (b). Each such report shall include the following:(A) A description of the technique or method used in such penetration.(B) A sample of the malicious software, if discovered and isolated by the contractor, involved in such penetration.(C) A summary of information created by or for the Department in connection with any Department program that has been potentially compromised due to such penetration.(2) Access to equipment and information by department of defense personnel.—The procedures established pursuant to subsection (a) shall—(A) include mechanisms for Department of Defense personnel to, upon request, obtain access to equipment or information of a cleared defense contractor necessary to conduct forensic analysis in addition to any analysis conducted by such contractor;(B) provide that a cleared defense contractor is only required to provide access to equipment or information as described in subparagraph (A) to determine whether information created by or for the Department in connection with any Department program was successfully exfiltrated from a network or information system of such contractor and, if so, what information was exfiltrated; and(C) provide for the reasonable protection of trade secrets, commercial or financial information, and information that can be used to identify a specific person.(3) Limitation on dissemination of certain information.—The procedures established pursuant to subsection (a) shall prohibit the dissemination outside the Department of Defense of information obtained or derived through such procedures that is not created by or for the Department except with the approval of the contractor providing such information.(d) Issuance of Procedures and Establishment of Criteria.—126 STAT. 1891(1) In general.—Not later than 90 days after the date of the enactment of this Act—(A) the Secretary of Defense shall establish the procedures required under subsection (a); and(B) the senior official designated under subsection (b)(1) shall establish the criteria required under such subsection.(2) Applicability date.—The requirements of this section shall apply on the date on which the Secretary of Defense establishes the procedures required under this section.(e) Definitions.—In this section:(1) Cleared defense contractor.—The term “cleared defense contractor” means a private entity granted clearance by the Department of Defense to access, receive, or store classified information for the purpose of bidding for a contract or conducting activities in support of any program of the Department of Defense.(2) Covered network.—The term “covered network” means a network or information system of a cleared defense contractor that contains or processes information created by or for the Department of Defense with respect to which such contractor is required to apply enhanced protection.