Pub. L. 107-217, tit. XIV, subtit. III, ch. 113, subch. III, sec. 11331

Responsibilities regarding efficiency, security, and privacy of federal computer systems

EnactedYear: 2002Length: 478 wordsOfficial source
§ 11331. Responsibilities regarding efficiency, security, and privacy of federal computer systems (a) Definitions.—In this section, the terms “federal computer system” and “operator of a federal computer system” have the meanings given those terms in section 20(d) of the National Institute of Standards and Technology Act (15 U.S.C. 278g-3(d)). (b) Standards and Guidelines.— (1) Authority to prescribe and disapprove or modify.— (A) Authority to prescribe.—On the basis of standards and guidelines developed by the National Institute of Standards and Technology pursuant to paragraphs (2) and (3) of section 20(a) of the Act (15 U.S.C. 278g-3(a)(2), (3)), the Secretary of Commerce shall prescribe standards and guidelines pertaining to federal computer systems. The Secretary shall make those standards compulsory and binding to the extent the Secretary determines necessary to improve the efficiency of operation or security and privacy of federal computer systems. (B) Authority to disapprove or modify.—The President may disapprove or modify those standards and guidelines if the President determines that action to be in the public interest. The President’s authority to disapprove or modify those standards and guidelines may not be delegated. Notice of disapproval or modification shall be published promptly in the Federal Register. On receiving notice of disapproval or modification, the Secretary shall immediately rescind or modify those standards or guidelines as directed by the President. (2) Exercise of authority.—To ensure fiscal and policy consistency, the Secretary shall exercise the authority conferred by this section subject to direction by the President and in coordination with the Director of the Office of Management and Budget. (c) Application of More Stringent Standards.—The head of a federal agency may employ standards for the cost-effective security and privacy of sensitive information in a federal computer system in or under the supervision of that agency that are more stringent than the standards the Secretary prescribes under this section if the more stringent standards contain at least the applicable standards the Secretary makes compulsory and binding. (d) Waiver of Standards.— (1) Authority of the secretary.—The Secretary may waive in writing compulsory and binding standards under subsection (b) if the Secretary determines that compliance would— (A) adversely affect the accomplishment of the mission of an operator of a federal computer system; or (B) cause a major adverse financial impact on the operator that is not offset by Federal Government-wide savings. (2) Delegation of waiver authority.—The Secretary may delegate to the head of one or more federal agencies authority 116 STAT. 1244 to waive those standards to the extent the Secretary determines that action to be necessary and desirable to allow for timely and effective implementation of federal computer system standards. The head of the agency may redelegate that authority only to a chief information officer designated pursuant to section 3506 of title 44. (3) Notice.—Notice of each waiver and delegation shall be transmitted promptly to Congress and published promptly in the Federal Register.