Pub. L. 116-92, div. A, tit. XVI, subtit. C, sec. 1657
CYBER GOVERNANCE STRUCTURES AND PRINCIPAL CYBER ADVISORS ON MILITARY CYBER FORCE MATTERS.
SEC. 1657. CYBER GOVERNANCE STRUCTURES AND PRINCIPAL CYBER ADVISORS ON MILITARY CYBER FORCE MATTERS.(a) Designation.—(1) In general.—Not later than 270 days after the date of the enactment of this Act, each of the secretaries of the military departments, in consultation with the service chiefs, shall appoint an independent Principal Cyber Advisor for each service to act as the principal advisor to the relevant secretary on all cyber matters affecting that military service.(2) Nature of position.—Each Principal Cyber Advisor position under paragraph (1) shall—(A) be a senior civilian leadership position, filled by a senior member of the Senior Executive Service, not lower than the equivalent of a 3-star general officer, or by exception a comparable military officer with extensive cyber experience;(B) exclusively occupy the Principal Cyber Advisor position and not assume any other position or responsibility in the relevant military department;(C) be independent of the relevant service’s chief information officer; and(D) report directly to and advise the secretary of the relevant military department and advise the relevant service’s senior uniformed officer.(3) Notification.—Each of the secretaries of the military departments shall notify the Committees on Armed Services of the Senate and House of Representatives of his or her Principal Cyber Advisor appointment. In the case that the appointee is a military officer, the notification shall include a justification for the selection and an explanation of the appointee’s ability to execute the responsibilities of the Principal Cyber Advisor.(b) Responsibilities of Principal Cyber Advisors.—Each Principal Cyber Advisor under subsection (a) shall be responsible for advising both the secretary of the relevant military department and the senior uniformed military officer of the relevant military service and implementing the Department of Defense Cyber Strategy within the service by coordinating and overseeing the execution of the service’s policies and programs relevant to the following:(1) The recruitment, resourcing, and training of military cyberspace operations forces, assessment of these forces against standardized readiness metrics, and maintenance of these forces at standardized readiness levels.133 STAT. 1768(2) Acquisition of offensive, defensive, and Department of Defense Information Networks cyber capabilities for military cyberspace operations.(3) Cybersecurity management and operations.(4) Acquisition of cybersecurity tools and capabilities, including those used by cybersecurity service providers.(5) Evaluating, improving, and enforcing a culture of cybersecurity warfighting and accountability for cybersecurity and cyberspace operations.(6) Cybersecurity and related supply chain risk management of the industrial base.(7) Cybersecurity of Department of Defense information systems, information technology services, and weapon systems, including the incorporation of cybersecurity threat information as part of secure development processes, cybersecurity testing, and the mitigation of cybersecurity risks.(c) Coordination.—To ensure service compliance with the Department of Defense Cyber Strategy, each Principal Cyber Advisor under subsection (a) shall work in close coordination with the following:(1) Service chief information officers.(2) Service cyber component commanders.(3) Principal Cyber Advisor to the Secretary of Defense.(4) Department of Defense Chief Information Officer.(5) Defense Digital Service.(d) Budget Certification Authority.—(1) In general.—Each of the secretaries of the military departments shall require service components with responsibilities associated with cyberspace operations forces, offensive or defensive cyberspace operations and capabilities, and cyberspace issues relevant to the duties specified in subsection (b) to transmit the proposed budget for such responsibilities for a fiscal year and for the period covered by the future-years defense program submitted to Congress under section 221 of title 10, United States Code, for that fiscal year to the relevant service’s Principal Cyber Advisor for review under subparagraph (B) before submitting the proposed budget to the department’s comptroller.(2) Review.—Each Principal Cyber Advisor under subsection (a)(1) shall review each proposed budget transmitted under paragraph (1) and submit to the secretary of the relevant military department a report containing the comments of the Principal Cyber Advisor with respect to all such proposed budgets, together with the certification of the Principal Cyber Advisor regarding whether each proposed budget is adequate.(3) Report.—Not later than March 31 of each year, each of the secretaries of the military departments shall submit to the congressional defense committees a report specifying each proposed budget for the subsequent fiscal year contained in the most-recent report submitted under paragraph (2) that the Principal Cyber Advisor did not certify to be adequate. The report of the secretary shall include a discussion of the actions that the secretary took or proposes to take, together with any additional comments that the Secretary considers appropriate regarding the adequacy or inadequacy of the proposed budgets.133 STAT. 1769(e) Principal Cyber Advisors’ Briefing to Congress.—Not later than February 1, 2021, and biannually thereafter, each Principal Cyber Advisor under subsection (a) shall brief the Committees on Armed Services of the Senate and House of Representatives on that Advisor’s activities and ability to perform the functions specified in subsection (b).(f) Review of Current Responsibilities.—(1) In general.—Not later than January 1, 2021, each of the secretaries of the military departments shall review the relevant military department’s current governance model for cybersecurity with respect to current authorities and responsibilities.(2) Elements.—Each review under paragraph (1) shall include the following:(A) An assessment of whether additional changes beyond the appointment of a Principal Cyber Advisor pursuant to subsection (a) are required.(B) Consideration of whether the current governance structure and assignment of authorities—(i) enable effective governance;(ii) enable effective Chief Information Officer and Chief Information Security Officer action;(iii) are adequately consolidated so that the authority and responsibility for cybersecurity risk management are clear and at an appropriate level of seniority;(iv) provide authority to a single individual to certify compliance of Department of Defense information systems and information technology services with all current cybersecurity standards; and(v) support efficient coordination across the military services, the Office of the Secretary of Defense, the Defense Information Systems Agency, and United States Cyber Command.(3) Briefing.—Not later than October 1, 2020, each of the secretaries of the military departments shall brief the Committees on Armed Services of the Senate and House of Representatives on the findings of the Secretary with respect to the review conducted by the Secretary pursuant to paragraph (1).