Pub. L. 116-92, div. A, tit. XVI, subtit. C, sec. 1651
REORIENTATION OF BIG DATA PLATFORM PROGRAM.
SEC. 1651. REORIENTATION OF BIG DATA PLATFORM PROGRAM.(a) Reorientation of Program.—(1) In general.—Not later than January 1, 2021, the Secretary of Defense shall—(A) reorient the Big Data Platform program as specified in this section; and(B) align the reorientation effort under an existing line of effort of the Cyber Strategy of the Department of Defense.(2) Oversight of implementation.—The Secretary shall act through the Principal Cyber Advisor and the supporting Cross Functional Team in the oversight of the implementation of paragraph (1).(b) Common Baseline and Security Classification Scheme.—(1) In general.—Not later than January 1, 2021, the Secretary shall establish a common baseline and security classification scheme for the collection, storage, processing, querying, analysis, and accessibility of a common and comprehensive set of metadata from sensors, applications, appliances, products, and systems deployed across the Department of Defense Information Network (DODIN) to enable the discovery, tracking, and remediation of cybersecurity threats.(2) Requirements.—In carrying out paragraph (1), the Secretary shall—(A) take such actions as the Secretary considers necessary to standardize deployed infrastructure, including the Department of Defense’s perimeter capabilities at the Internet Access Points, the Joint Regional Security Stacks, or other approved solutions, and the routing of data laterally and vertically from Department of Defense Information Network segments and tiers, to enable standard and comprehensive metadata collection;(B) take such actions as the Secretary considers necessary to standardize deployed cybersecurity applications, products, and sensors and the routing of data laterally and vertically from Department of Defense Information Network segments and tiers, to enable standard and comprehensive metadata collection;(C) develop an enterprise-wide architecture and strategy for—(i) where to place sensors or extract data from network information technology, operational technology, and cybersecurity appliances, applications, products, and systems for cybersecurity purposes;(ii) which metadata data records should be universally sent to Big Data Platform instances and which metadata data records, if any, should be locally retained; and(iii) expeditiously and efficiently transmitting metadata records to the Big Data Platform instances, including the acquisition and installation of further data bandwidth;(D) determine the appropriate number, organization, and functions of separate Big Data Platform instances, and whether the Big Data Platform instances that are currently managed by Department of Defense components, 133 STAT. 1760 including the military services, should instead be jointly and regionally organized, or terminated;(E) determine the appropriate roles of the Defense Information Systems Agency’s Acropolis, United States Cyber Command’s Scarif, and any similar Big Data Platforms as enterprise-wide real-time cybersecurity situational awareness capabilities or as complements or replacements for component level Big Data Platform instances;(F) ensure that all Big Data Platform instances are engineered and approved to enable standard access and expeditious query capabilities by the Unified Platform, the network defense service providers, and the Cyber Mission Forces, with centrally managed authentication and authorization services;(G) prohibit and remove barriers to information sharing, distributed query, data analysis, and collaboration across Big Data Platform instances, such as incompatible interfaces, interconnection service agreements, and the imposition of accreditation boundaries;(H) transition all Big Data Platform instances to a cloud computing environment in alignment with the cloud strategy of the Chief Information Officer of the Department of Defense;(I) consider whether packet capture databases should continue to be maintained separately from the Big Data Platform instances, managed at the secret level of classification, and treated as malware-infected when the packet data are copies of packets extant in the Department of Defense Information Network;(J) in the case that the Secretary decides to sustain the status quo on packet capture databases, ensure that analysts operating on or from the Unified Platform, the Big Data Platform instances, the network defense services providers, and the Cyber Mission Forces can directly access packets and query the database; and(K) consider whether the Joint Artificial Intelligence Center’s cybersecurity artificial intelligence national mission initiative, and any other similar initiatives, should include an application for the metadata residing in the Big Data Platform instances.(c) Limit on Data and Data Indexing Schema.—The Secretary shall ensure that the Unified Platform and the Big Data Platform programs achieve data and data indexing schema standardization and integration to ensure interoperability, access, and sharing by and between Big Data Platform and other data sources and stores.(d) Analytics and Application Sourcing and Collaboration.—The Secretary shall ensure that the services, U.S. Cyber Command, and Defense Information Systems Agency—(1) seek advanced analytics and applications from Government and commercial sources that can be executed on the deployed Big Data Platform architecture; and(2) collaborate with vendors offering commercial analytics and applications, including support to refactoring commercial capabilities to the Government platform where industry can still own the intellectual property embedded in the analytics and applications.133 STAT. 1761(e) Briefing Required.—Not later than 180 days after the date of the enactment of this Act and not less frequently than once every 180 days thereafter until the activities required by subsection (a)(1) are completed, the Secretary shall brief the congressional defense committees on the activities of the Secretary in carrying out subsection (b).